intwin tech
Cybersecurity

Security that is in the plan, not in the proposal.

Endpoint, identity, email and round-the-clock detection, included in the monthly rate rather than sold as the upgrade you buy after something happens.

What is included

What is running from day one

Most breaches at companies your size do not involve anything exotic. They involve a password that worked, an inbox that was trusted, and a machine nobody had patched. The controls below are aimed squarely at that.

Managed endpoint detection and response

Every laptop and server

Behavioural detection rather than signature matching alone, with an analyst on the other end. Isolation of a compromised machine happens in minutes, not after someone reads an email about it.

Identity protection

The most attacked surface you have

Multi-factor authentication everywhere it can be enforced, conditional access rules that fit how your people actually work, and monitoring for the sign-in that should not have been geographically possible.

Email security

Ahead of the inbox

Filtering for the obvious, and detection for the impersonation attempt that carries no attachment and no link, because that is the one that gets paid.

Round-the-clock detection and response

Alerts actioned, not forwarded

A security operations centre watching what got through everything else. The difference that matters is whether someone acts at three in the morning or simply logs it for the morning.

Patch and vulnerability management

The unglamorous majority

Most successful intrusions use something that had a fix available. Patching on a schedule, with exceptions written down, closes more risk than any product you can buy.

Backup as a security control

Because ransomware is a data problem

The modern breach encrypts rather than steals. Immutable, tested backups are what turns a catastrophe into an expensive week.

Awareness training

Short and regular

A few minutes often, rather than the annual hour everybody clicks through while doing something else. Simulated phishing that teaches instead of humiliating.

Evidence and reporting

For the auditor and the insurer

SOC 2, HIPAA and cyber-insurance questionnaires answered with logs and configuration exports rather than assurances.

Worth knowing

What this is not

It is not a penetration test. A test tells you what a motivated attacker could do on the day it was run; it is worth doing, we will help you arrange one, and it is a separate piece of work with its own price. Anyone bundling it into a monthly rate is either not doing it properly or not doing it often.

It is not a compliance certification. We run the controls a SOC 2 or HIPAA programme depends on and we keep the evidence in a state an auditor can read, but the audit itself is performed by someone independent, and it should be.

It is not a guarantee, and we would be careful with anyone who offers one. What we will tell you plainly is which risks these controls address, which they reduce without removing, and which are still open because you have decided the fix costs more than the exposure. That last list should exist and should be short.

Fit

Whether this is the right service for you

A good fit

This is usually the right shape when

  • A cyber-insurance renewal asking questions you cannot currently answer
  • Client contracts starting to carry security requirements
  • Regulatory obligations such as 23 NYCRR 500 or a written IRS security plan
  • A near miss, or a competitor who has just had a bad month
Probably not

We would point you elsewhere if

  • Looking for a certificate rather than the controls behind one
  • Wanting security as a project that finishes, rather than something that runs
  • Environments with industrial control systems, which need a different specialist

Questions about cybersecurity

Our insurer sent a fifteen-page questionnaire. Can you help?
Yes, and this is one of the more common reasons companies call us. We answer it from the actual configuration rather than from optimism, and where an answer would have to be no, we tell you what it would take to make it yes and roughly what that costs. Insurers have become considerably better at checking, and a questionnaire answered hopefully is a claim denied later.
Do you need to replace our antivirus?
Usually yes, and not because the one you have is bad. Consumer-grade and unmanaged products cannot be seen centrally, which means nobody knows when one machine has been switched off for a month. The value is as much in the visibility as in the detection.
What happens if something does get through?
We isolate the affected machines, work out what was reached, and tell you what we know and what we do not yet know, in that order. You get a written account afterwards, including anything we would do differently. Incident response is written into the agreement rather than quoted after the fact.
Is training really necessary if the filtering is good?
Yes, because the attacks that succeed at your size are increasingly the ones with nothing for a filter to catch: a plausible message from a real address asking a finance person to change bank details. Nothing technical stops that. A person who has seen the pattern before does.

Start with a free IT assessment

Thirty minutes on a call, then a written picture of what you are running, where you are exposed, and what supporting it properly should cost per month. No obligation, and the document is yours to keep either way.