Security is not a product you install. It is a set of things that have to stay true every day, on every machine, whether or not anyone is looking.
Most small businesses in Bradenton and Lakewood Ranch have some of it. Antivirus is running. There is a firewall in the closet. Someone set up Microsoft 365 a few years ago. What is usually missing is anyone whose job it is to check that all of it still works.
What usually goes wrong
The first belief that gets people hurt is that they are too small to be worth attacking. Nobody is picking your business out of a list. Attacks are automated, they sweep everything with an open door, and a five-person office with an unpatched machine is easier than a company with a security team. Being small is the reason you get hit, not the reason you do not.
The second is that having a tool means being protected. Antivirus that nobody has opened in a year, alerts going to an inbox nobody reads, a backup that has never once been restored to check it works. Tools without someone watching them are theatre. They generate a feeling of safety and nothing else.
The third is email. Almost every incident I have seen at this size starts with a mailbox — a password reused from somewhere that got breached, no multi-factor authentication, and a forwarding rule quietly added that nobody notices for weeks.
What I actually do
Security at your scale is layers, each one cheap on its own, and each one covering a gap the others leave.
- Managed endpoint protection. Every machine running current protection, reporting to one console, with someone actually reading what it reports. That someone is me.
- Patching. Windows and third-party applications kept current on a schedule. Unpatched software is the most common way in and the easiest to close.
- Ransomware defence. Behaviour-based detection rather than signature matching alone, because ransomware does not look like a known virus until it is already running.
- Backup you can prove. A backup that has never been tested is a hope. I test restores, because the day you need one is a bad day to find out.
- Microsoft 365 hardening. Multi-factor authentication enforced, legacy authentication disabled, mail forwarding rules audited, admin accounts separated from daily-use accounts.
- System hardening. Turning off what is not needed, closing what is open by default, and removing the local administrator rights that let one bad click become a whole-network problem.
- Alert response. When something fires, a person looks at it and decides what it means.
What “managed” means day to day
It means the work continues when nothing is happening. Machines check in. Patches go out. Alerts arrive and get triaged. When a laptop drops off the console for a week, I notice and ask why.
Most of it you will never see, which is the point. What you should see is a clear answer whenever you ask what state your systems are in.
Finding the gaps before someone else does
You cannot secure what you have not looked at. Alongside ongoing management I run point-in-time testing:
- Internal network testing — what someone could reach and do from inside your office, on your Wi-Fi, or from one compromised machine.
- Web application testing — for businesses running a site that takes bookings, payments or customer data.
- Phishing simulation — a controlled campaign against your own staff to find out who clicks, followed by training rather than blame.
The point of testing is not a certificate. It is a list of specific things to fix, in the order they matter.
Microsoft 365 is where I would start
If you do one thing this month, make it this. Enforce multi-factor authentication on every mailbox, turn off legacy authentication, and audit your forwarding rules.
It costs nothing beyond the licence you already pay for, and it closes the door that most attacks at your size walk through. I will do it in an afternoon whether or not you buy anything else from me.
Who this is for
Businesses in Bradenton, Lakewood Ranch, Sarasota and the wider Manatee and Sarasota county area with somewhere between three and fifty machines. Offices holding customer records, payment details or anything covered by a contract with a larger company. Anyone who has been asked by a client or an insurer what their security posture is and did not have an answer.
Who this is not for
If you need a formal compliance certification — SOC 2, HIPAA attestation, PCI-DSS validation — that is an audit, and an auditor has to do it. I can get your systems into a defensible state and work alongside whoever runs the audit, but I do not issue the certificate and I will not pretend otherwise.
If you want a box ticked so an insurance form can be filled in, and no intention of changing anything, we will both be disappointed.
Common Questions
We are only a few people. Are we really a target?
You are not being singled out, and that is the problem. Attacks scan indiscriminately for open doors. A small office with an unpatched machine and no multi-factor authentication is a softer target than a large company, not a less interesting one.
We already have antivirus. Is that not enough?
It is one layer, and it only works if someone reads what it reports. Antivirus running quietly on a machine nobody monitors will detect something eventually and tell nobody. The gap is rarely the software. It is that no one is watching it.
What happens if we get hit anyway?
We isolate the affected machines, work out what was reached, and restore from backup — which is why I test restores in advance rather than discovering their state under pressure. Nobody can promise an incident will not happen. What is worth paying for is being able to recover from one.
Do you have to replace everything we already have?
Usually not. Most businesses already own more capability than they use — Microsoft 365 in particular includes security features most people never switch on. I would rather configure what you have properly than sell you something new.
How do we start?
With a look at what is actually running: which machines, what is patched, how email is configured, whether backups work. That produces a list of gaps in priority order. You decide what to fix and whether you want me to keep watching afterwards.
Tell me what you are worried about
If you are not sure where you stand, that is the normal starting point, and it is a better position than assuming you are fine.