01

Remote monitoring and management

The layer everything else runs on. Your machines, watched and maintained.

An agent on every workstation and server reports health, patch state and configuration continuously, and we act on it. Operating system and third-party patching runs on a schedule instead of whenever somebody remembers. Support is remote, so a problem is looked at in minutes rather than at the end of a drive. Most of what would have become a call gets handled before anyone notices it happened.

  • Continuous monitoring and alerting
  • Operating system and application patching
  • Remote helpdesk for staff
  • Asset and warranty inventory
  • Onboarding and offboarding for users
  • Monthly reporting on what changed and what needs attention
02

Endpoint detection and response

Not antivirus. Detection that watches behaviour and can stop a machine mid-attack.

Traditional antivirus matches files against a list of known bad ones, which is useless against anything new. EDR watches what processes actually do: the encryption pattern, the credential dump, the tool that should never have run. When it sees an attack in progress it can isolate the machine from the network before the damage spreads, and it keeps the forensic trail your insurer will ask for.

  • Behavioural detection, not signature matching
  • Automatic isolation of a compromised device
  • Ransomware rollback where the platform supports it
  • Alerts triaged by us, not forwarded to you
  • Retained detection history for insurance and audit
  • Coverage for servers as well as workstations
03

Email security, powered by Ironscales

The attack path that actually gets used, closed off.

Microsoft 365 and Google Workspace filtering stops the obvious. It does not reliably stop a convincing invoice from a supplier whose account was taken over, which is the attack that costs practices real money. Ironscales sits inside the mailbox rather than only at the gateway, so it catches impersonation and account-takeover patterns that pass every perimeter check, and it pulls a bad message out of every inbox it reached once one person reports it.

  • Mailbox-level phishing and impersonation detection
  • Automatic removal of a reported message from every inbox
  • Business email compromise and supplier-invoice fraud detection
  • One-click reporting built into Outlook for staff
  • Phishing simulation and training
  • Works with Microsoft 365 and Google Workspace
04

Identity threat detection and response

Watching the accounts themselves, because a valid login raises no alarms.

Once an attacker has a working password and a session token, they are not breaking in any more, they are signing in. Nothing on the endpoint objects. ITDR watches the identity layer for what that actually looks like: impossible travel, a new mail-forwarding rule quietly created, multi-factor suddenly registered on an unfamiliar device, a mailbox granted to someone who should not have it.

  • Detection of account takeover in Microsoft 365 and Entra
  • Alerting on suspicious mailbox rules and forwarding
  • Multi-factor enrolment and configuration monitoring
  • Privilege and access review
  • Conditional access policy design and upkeep
  • Response when an account is compromised, not just an alert
05

Offsite backup and recovery

Copies ransomware cannot reach, and restores somebody has actually run.

Backup only matters at the moment you need it back, and that is the worst possible time to discover a job has been failing silently since March. Data goes offsite to storage that cannot be altered or deleted within its retention window, which is what defeats the part of a ransomware attack that hunts down your backups first. Restores are tested on a schedule and the results are written down, so recovery time is a number you know rather than a number you find out.

  • Encrypted offsite backup
  • Immutable copies ransomware cannot encrypt or delete
  • Scheduled restore testing with written results
  • Documented recovery time and recovery point targets
  • Microsoft 365 data covered, which Microsoft does not do for you
  • Practice management and imaging data covered explicitly

Also covered

The rest of what lives inside a managed agreement.

These are not add-ons with separate prices. They fall inside the five controls above, and they come up often enough as their own question that they are worth naming.

  • Microsoft 365 administration and hardening

    Tenant configuration, conditional access policies, licence tidy-up, shared mailboxes and delegation reviewed rather than accumulated.

  • Security awareness training and phishing simulation

    Simulated campaigns and short training assigned to whoever needs it, with reporting you can hand to an insurer.

  • Multi-factor rollout across every account

    Including the shared front-desk login and the administrator account nobody has touched since it was created, which are the two that always get missed.

  • Documentation and compliance evidence

    Written record of what is implemented, who has access and when it was last reviewed. This is what a HIPAA risk analysis and a cyber insurance questionnaire both ask for.

  • Quarterly technology review

    What we caught, what changed, what is approaching end of life, and what needs budget in the next twelve months.

  • Onboarding and offboarding

    A new hire gets the right access on day one. Someone leaving loses all of it the same day, including the accounts nobody remembers.

Questions

The things people ask before they call.

You are in Minnesota. We are not. Does that matter?

No. Everything we run is delivered by an agent on your machines or inside your Microsoft 365 tenant, so coverage does not depend on geography. We work with clients across the country and the service is identical in every state.

What happens when something physically needs a person?

It is rare, because almost nothing in a modern practice is fixed by standing next to it. When it genuinely is, for example a failed switch or a cable run, we schedule and brief a vetted technician local to you and manage the work ourselves. You deal with us, and you get one invoice.

Do you take clients outside dentistry?

Yes. Dental is the deepest specialism because the clinical software and imaging demand it, and that rigour carries over to every other client. Plenty of our work is small business outside healthcare.

What does it cost?

Managed protection is a flat monthly fee based on how many users and devices you have, so it is predictable and it does not rise when you have a bad month. The assessment is free, and you keep its documentation regardless of whether you go further.

We already have someone. Is this worth a conversation?

It is worth an assessment. You will get an independent picture of what you have and where the risk sits, and plenty of practices take that back to their existing provider and fix things there. That is a fine outcome.

Is this not just antivirus with a nicer name?

No. Antivirus matches files against a list of known bad ones. EDR watches what software actually does and can isolate a machine mid-attack, email security works inside the mailbox rather than only at the gateway, and ITDR watches the accounts themselves, because a stolen password produces a login that looks completely legitimate.

How fast do you respond?

Managed clients reach a real person during business hours, with emergency coverage outside them. Response targets are written into the agreement rather than implied. Security alerts are triaged by us around the clock rather than emailed to you.

What happens to our data if we leave?

You get all of it, plus the documentation, in a usable format. No hostage-taking of credentials or configuration. Everything we build is documented so that another provider could pick it up.

Start with the assessment.

It is free, it is done remotely in about an hour, and it ends with a written picture of your environment and its risks that is yours to keep. No obligation and no contract attached.