Secure · Cybersecurity

Cybersecurity for businesses without an IT department.

Practical protection for a small business in Fairfield County: the website, the domain, the email, the accounts and the people who can log into them. Reviewed, fixed and explained in plain language by a CompTIA Security+ certified practitioner — in person or remote.

Review from $250, creditedSecurity+ certifiedPlain-language reportEnglish & Spanish

What this covers: the handful of things that actually get small businesses hurt — an unpatched website, weak or shared logins, DNS nobody understands, email that can be spoofed, a former employee or agency that still has access, and backups that have never been restored. I find them, fix what can be fixed, and write down the rest.

Who this is for

Businesses that are too small for a managed IT contract but too exposed to keep ignoring it: a medical or dental practice, a law or accounting office, a contractor whose invoices are being spoofed, a shop whose website was hacked once already. If you have a website, a domain and a Google or Microsoft account, you have an attack surface — this is the service that shrinks it.

Secure

What a security engagement includes

Site and account review

Website platform and plugins, hosting and domain registrar, DNS, certificates, email provider, cloud accounts and who has access to what. Findings in writing, credited toward the work.

Website hardening

Updates, firewall and rate limits, admin access locked down, two-factor on every account that supports it, backups scheduled and restored once to prove they work.

DNS, SSL and Cloudflare

Records cleaned up, certificates renewed automatically and monitored, the site behind Cloudflare with sensible security headers.

Email authentication

SPF, DKIM and DMARC configured so your mail reaches inboxes and nobody can send as you. Explained in the SPF, DKIM and DMARC guide.

Access review

Old logins closed: the former employee, the former agency, the plugin nobody uses, the shared password on a sticky note.

Compromise cleanup

If the site is already hacked or you are locked out: a paid assessment first, then a written scope and a flat quote within 48 hours, then the cleanup, then the hardening so it does not recur.

Monitoring

Uptime, certificate expiry and file changes watched, with alerts to me. Included in the monthly care plan.

A report you can read

What was exposed, what it would have cost you, what was fixed, and what is left for you to decide. No scores out of a hundred.

How it runs

How it runs

  1. Review

    A paid review of the site, domain, email and accounts. You get the findings in writing even if you stop there.

  2. Plan

    A written scope and flat quote for the fixes, with the review fee credited in full.

  3. Fix

    Hardening, authentication, access cleanup and monitoring, done with you — you keep every password and account.

  4. Explain

    A plain-language report and a short walkthrough of what changed and what to watch.

  5. Keep watching

    Optional monthly care: updates, tested backups and monitoring by the same person.

Questions

Questions about security work

Start with a conversation.

Free estimate, no commitment. Tell me what the business needs and I will tell you what I would do, what it would cost, and whether you need me at all.