Security that fits a small business — not a Fortune 500.
Layered defense built around the CIS Controls v8 baseline. Endpoint, email, identity, and incident response — sized for SMBs and run by humans, not a portal.
Stop incidents before they become headlines.
Most breaches at small businesses come through the front door: a misconfigured account, a missed patch, a credential nobody remembered to revoke. We close those doors with a baseline that's repeatable, measurable, and proportional to the threat.
- MFA on every administrative account, including ours
- Endpoint detection-and-response across every workstation
- Email security with anti-phishing and DMARC enforcement
- Quarterly access reviews and credential rotation
6 capabilities. One SLA.
Endpoint Protection
EDR-grade detection on every workstation and server.
Email Security
Anti-phishing, anti-spoofing, DMARC, and quarantine review.
Identity & Access
MFA, conditional access, and least-privilege role design.
Phishing Simulation
Quarterly campaigns with follow-up training that actually works.
Incident Response
Documented playbook + retainer for after-hours containment.
Compliance Mapping
CIS v8, HIPAA-aware, and SOC-2-friendly evidence packs.
The ones owners ask before signing.
If yours isn't here, ask on the discovery call — we'll give a real answer.
Do we need a SOC?
Almost no SMB does. A baseline of EDR + MFA + email defense covers >95% of what a SOC would catch, at a fraction of the cost.
What about cyber insurance?
We provide an evidence pack mapped to the questions most insurers ask. Several clients have used it to lower premiums.
Are you HIPAA / SOC-2 / PCI experts?
We're HIPAA-aware and align to CIS v8. For formal audits we work alongside specialist auditors — we provide the evidence; they make the call.
What happens when something does break in?
Incident-response retainer covers it. Documented playbook, defined escalation, after-hours coverage. No scrambling to find the contract.
Other services
View all →See if Cybersecurity from PHT fits your business.
30 minutes with the founder. We'll look at your environment, your support load, and tell you honestly whether this service is the right fit — even if the answer is "not yet."