Cybersecurity for Boston Businesses
Backup that restores, MFA everywhere, phishing training and Massachusetts 201 CMR 17.00 compliance for small and mid-sized Greater Boston businesses.
Security for a ten-person office is not a smaller version of enterprise security. It is a short list of controls that stop nearly everything, done properly and kept working.
We are not going to sell you a platform. We are going to make sure the basics are actually in place, because in every incident we have been called into, the failure was a basic control that was missing or had quietly stopped working.
The controls that matter, in order
1. Multi-factor authentication on email. Business email compromise is the incident we see most, and it is usually the most expensive — an attacker sits in a mailbox, watches invoicing, and redirects a payment. MFA stops nearly all of it. It is included in the Microsoft 365 or Google plan you already pay for.
2. Backup that has been restored. Not “we have backup”. Backup that someone restored from, recently, and confirmed. With one copy offline or immutable, because ransomware deliberately targets backups it can reach.
3. Patching on a schedule. Most compromises of small businesses use a vulnerability that had a fix available. The gap is not knowledge, it is that nobody owns the task.
4. Least privilege. Not everyone is an administrator. When a workstation is compromised, the difference between an incident and a disaster is what that account could reach.
5. Segmentation. Guest Wi-Fi separated from workstations, payment systems separated from general traffic. See network support.
6. Staff who recognise phishing. Short, regular, non-patronising training. Your people are the control that catches what the software misses.
7. Offboarding that works. Accounts disabled the day someone leaves. We routinely find accounts active for people gone a year or more.
Massachusetts 201 CMR 17.00
This one deserves its own section because so many small Boston businesses are subject to it without knowing.
It applies to anyone holding personal information about a Massachusetts resident. If you have Massachusetts employees, you hold their Social Security numbers — you are covered. It requires a Written Information Security Program: a real document naming who is responsible, what data you hold, how it is protected, how you vet vendors and what happens in a breach.
We help you build one that reflects what you actually do. A WISP downloaded from a template and never implemented is worse than none — in an investigation it documents the gap between what you said and what you did.
Accounting firms have a second layer
If you prepare tax returns, the FTC Safeguards Rule and IRS Publication 4557 apply on top, and the IRS requires a written security plan to maintain your PTIN. See IT support for accounting firms.
Where we start
A security review, typically two to three hours, that produces a plain list: what is exposed, ranked by how likely it is to hurt you and how much it costs to fix. Most items on a first review are free or nearly free — they were simply never turned on.
No scare tactics and no product pitch. If your basics are in good shape, we will tell you that too.
Related
Frequently asked questions
- What is 201 CMR 17.00 and does it apply to us?
- It is the Massachusetts data protection regulation, and it applies to any business that holds personal information about a Massachusetts resident — not just companies based here. Personal information means a name combined with a Social Security number, driver’s licence number, or financial account number. If you have employees in Massachusetts, you already hold that. The regulation requires a Written Information Security Program, and most small businesses subject to it do not have one.
- We are small. Is anyone really targeting us?
- Almost nothing that hits small businesses is targeted. It is automated, scanning for exposed services and unpatched systems, and it does not check your revenue first. Being small is not protection — it usually just means less capacity to recover.
- Is cyber insurance enough?
- No, and increasingly it depends on controls you must already have. Policies now ask whether you enforce MFA, keep offline backups and maintain a security program. Answering yes on the application and no in reality is how claims get denied.
- What is the single most valuable thing we could do?
- Multi-factor authentication on email. Business email compromise is the most common and most expensive incident we see in offices this size, and MFA stops the overwhelming majority of it. It is free with the Microsoft 365 and Google plans you already pay for.
- How do we know our backups actually work?
- By restoring from them, on a schedule, and documenting that it worked. Any other answer is a hope. We test restores as a routine matter — most businesses discover a broken backup at the exact moment they need it.
Tell us what stopped working
Text or email is usually faster than a call. We serve Boston and everything within 20 miles — and remote support has no radius.