Serving the Loop, West Loop, River North & Fulton Market · (708) 296-3646

The practical controls, not a product stack

Small businesses are found, not targeted.

Nobody is choosing you specifically. Automated scanning finds unpatched systems and exposed services indiscriminately, and a twelve-person firm in a Loop tower looks identical to a scanner as a twelve-person firm anywhere — except it often holds client money or client data.

What it costs

Security reviews and remediation at $185/hr scheduled or $145/hr remote. Segmentation and firewall work is usually quoted as a fixed-price project.

Full price list →

The unglamorous things that stop most of it

Multi-factor authentication everywhere, especially email. The overwhelming majority of small-business breaches start with a stolen or guessed password on an account without it. It is free with Microsoft 365 and it is the highest-value hour of security work available to you.

Patching on a schedule. Automated attacks target vulnerabilities fixed months ago. Being current removes you from most of that traffic entirely.

A segmented network. This is the part network specialists actually change. Cameras, door controllers, thermostats and payment terminals have no business reaching your file server, and separating them is cheap when somebody competent does it.

Backups a compromised machine cannot reach. Covered on the backup page, and it decides how bad the worst day gets.

Email is the front door

Nearly everything arrives by email. Filtering that catches the obvious, external-sender banners so a spoofed internal address is visible, and SPF, DKIM and DMARC configured so other people’s servers reject mail pretending to be from you.

That last one protects your customers and your name as much as it protects you. Being the firm whose domain sent a fraudulent invoice is a reputational problem long after the technical one is fixed.

The scam that actually takes the money

Not ransomware — invoice fraud. Somebody compromises a mailbox, reads quietly for a few weeks, then sends a plausible message changing the bank details on a genuine outstanding invoice. It clears your process because it is not fake enough to trip anything.

The control is procedural rather than technical: any change to payment details is verified by phone, on a number you already held, before anything moves. Write it down, tell the finance people it is a rule and not a suggestion, and it stops working.

Been asked for a penetration test?

It almost always comes from somewhere specific — a PCI obligation, a SOC 2 audit, a cyber-insurance renewal, or a client’s security questionnaire. What you actually need differs a lot depending on which one is driving it, and it is frequently not what the form implies.

Ring and say what you have been asked for. You will get a straight answer about what it really means before you spend anything on it.

What we will not do

Frighten you into a stack of overlapping tools. Most small businesses in Chicago get the great majority of their risk reduction from MFA, patching, decent endpoint protection, email filtering, a segmented network and unreachable backups — largely things you already pay for or can simply enable.

If you need a compliance framework — HIPAA, CMMC, PCI, or an insurance questionnaire you cannot honestly answer — that is real work with real cost, and it gets scoped rather than covered by pretending a product handles it.

FAQ

Questions we get asked

Are small businesses really targeted?

Not targeted — found. Automated scanning does not care about your size, and smaller businesses generally have weaker protection, which makes them a better return for the same effort.

What is the single most valuable thing we can do?

Turn on multi-factor authentication for email and any remote access. Free with Microsoft 365, an afternoon including telling everyone, and it blocks the attack that starts most small-business breaches.

Do you do penetration testing?

Worth a conversation rather than a yes or no, because what you need depends entirely on what is driving the request. A PCI obligation, a SOC 2 audit, an insurance renewal and a client security questionnaire all point at different work, and a fair number of businesses asking for a pen test need something simpler and cheaper first.

Tell us what you have been asked to produce and you will get a straight answer about what it actually requires.

Is antivirus enough on its own?

No. Modern endpoint protection is necessary and not sufficient — it does not help against a valid stolen password, and it does not stop somebody being talked into a bank transfer.

Our cyber-insurance form asks about MFA, backups, EDR and segmentation. Can you help?

Yes, and this is a good reason to get in touch. Those forms are increasingly binding — answering optimistically can void a claim. You will get a straight read on where you actually stand and what it costs to answer honestly.

How do we stop invoice fraud?

A written rule that any change to payment details is verified by phone on a number you already held, never one from the email. Plus MFA on mailboxes so they cannot be read in the first place.

Tell us what is going on

You will speak to an engineer, not a salesperson.

We reply by the next business day, if not sooner. No sales sequence, no drip emails — one human, one call.

Ready when you are.

Ring and describe it in plain English. You will get a number before anyone drives anywhere.