CySecWall

Someone should be watching your network at 3 a.m.We already are.

CySecWall is a cybersecurity-first managed service provider for small and mid-sized businesses across the United States and Canada. We monitor your people, endpoints, and cloud accounts around the clock, fix what we find, and hand you the evidence your insurer and auditors ask for.

No long discovery project. The review is a call plus a read-only assessment, and you keep the findings whether or not you hire us.

Watch floor, overnight shift 24/7/365

    Illustrative example of the events our analysts handle. Not live customer data.

    We build and report against the frameworks your clients ask about:

    • CIS Controls v8.1
    • NIST CSF 2.0
    • SOC 2 readiness
    • HIPAA Security Rule
    • PCI DSS 4.0
    • CMMC Level 1 and 2
    • PIPEDA

    Who this is for

    You have 40 employees. Whoever is attacking you has automation.

    Most businesses your size are not targeted by name. They are found by a scanner, phished with a template, and hit on a long weekend. The defence does not need to be exotic, but it does need to be running, monitored, and provable. That is usually the part that falls off the plate of a busy office manager or a two-person IT team.

    Nobody owns security

    Your IT person keeps the business running. Security is the thing that gets pushed to next quarter, every quarter.

    Tools are bought, not watched

    Licences for antivirus, backup, and email filtering exist. Nobody reads the alerts they generate at 2 a.m. on a Saturday.

    The questions are getting harder

    Insurers, enterprise clients, and lenders now ask for MFA coverage, tested restores, and an incident response plan in writing.

    A bad week costs real money

    Downtime, forensics, legal notification, and lost trust land on the owner. Prevention is the cheapest line item in that story.

    What we do

    One team for watching, hardening, and proving it.

    Everything below is included in a managed agreement and delivered by our own staff. Pick the whole programme or the parts your current IT team does not cover.

    Watch and respondAround the clock, with a human who can act, not just email you a ticket.

    24/7 managed detection and response

    Analysts monitor endpoints, servers, and cloud sign-ins continuously and contain threats under an agreed response window.

    Endpoint and server protection

    Next-generation antivirus and EDR deployed, tuned, and watched on every laptop, desktop, and server, Windows and macOS.

    Cloud and identity monitoring

    Sign-in anomalies, new forwarding rules, consent grants, and admin changes in Microsoft 365 and Google Workspace, flagged as they happen.

    Incident response

    A named team, a rehearsed plan, and a retainer, so the clock does not start with a sales call and a credit check.

    Harden and preventThe unglamorous work that removes most of the risk before an alert ever fires.

    Microsoft 365 and Google Workspace hardening

    Baselines for identity, mail flow, sharing, and admin roles, rechecked monthly so configuration drift does not undo the work.

    Identity, MFA, and access

    Phishing-resistant MFA rollout, conditional access, removal of standing admin rights, and clean-up of accounts nobody has used in a year.

    Email and phishing defence

    Filtering, impersonation controls, and SPF, DKIM, and DMARC configured to actually reject rather than politely observe.

    Patch and vulnerability management

    Scheduled scanning and patch windows for operating systems, browsers, and the third-party applications that usually get missed.

    Backup and tested recovery

    Immutable backups for servers, endpoints, and Microsoft 365, with restores tested on a schedule instead of during an outage.

    Security awareness training

    Short monthly lessons and phishing simulations, with reporting that shows who is improving and who needs a hand.

    Prove and planTurning the work into something you can hand to an insurer, a client, or your board.

    Virtual CISO

    Quarterly planning, budget guidance, vendor review, and a risk register written in language your leadership team will read.

    Compliance readiness

    Controls and evidence mapped to CIS, NIST CSF, SOC 2, HIPAA, PCI DSS, or CMMC, so audits stop being a fire drill.

    Cyber insurance support

    We complete the technical sections of your renewal questionnaire and close the gaps that drive premiums or void coverage.

    Monthly reporting

    One page you can actually use: what we saw, what we did, what changed, and what needs a decision from you.

    How an engagement runs

    Four stages, starting with a fixed price and no surprises.

    1. Stage 1

      Security review

      A 30-minute call, then a read-only assessment of identity, endpoints, email, and backups. You get a findings report, a prioritised list, and a fixed monthly price.

      Week 1
    2. Stage 2

      Stabilise

      We close the gaps that matter first: MFA everywhere, admin rights trimmed, EDR on every device, backups running and restoring.

      Weeks 2 to 6
    3. Stage 3

      Operate

      Monitoring and response 24/7, patching, training, and a monthly report. Your team gets one number to call when something looks wrong.

      Ongoing
    4. Stage 4

      Improve

      A quarterly working session on risk, roadmap, and budget, plus a tabletop exercise once a year so the plan is not theoretical.

      Every quarter

    Insurance and audits

    Answer your renewal questionnaire honestly.

    Cyber insurers and enterprise clients now ask for specifics, and a wrong answer can cost you a claim. These are the controls they ask about most. We implement them, keep them running, and give you the documentation that shows it.

    Check your gaps in 30 minutes

    • MFA on email, VPN, and remote access
    • EDR deployed on every endpoint and server
    • Offline or immutable backups with tested restores
    • Separate accounts for administrative work
    • Documented patching timelines for critical fixes
    • Security awareness training with records
    • Email filtering and impersonation controls
    • A written and rehearsed incident response plan
    • An inventory of devices, users, and vendors
    • Logging retained long enough to investigate

    Businesses we know well

    Regulated data, tight margins, and no room for a week of downtime. We work most often with organisations between 20 and 500 people in:

    • Medical and dental clinics
    • Law firms
    • Accounting and wealth management
    • Insurance brokerages
    • Manufacturing and distribution
    • Construction and trades
    • Engineering and architecture
    • Property management
    • Non-profits and associations
    • Defence and aerospace suppliers

    Plans

    Flat monthly pricing, per user, with no hourly surprises.

    Every plan includes onboarding, tooling licences, and unlimited security support for covered users. Final pricing is confirmed after the security review.

    Essentials

    $49 per user, per month

    For teams with capable IT who need the security layer covered.

    • EDR on every endpoint and server
    • 24/7 detection and response
    • Email filtering and DMARC enforcement
    • Monthly security report
    Get a quote

    Most companies start here

    Managed

    $89 per user, per month

    The full programme for a business without a dedicated security person.

    • Everything in Essentials
    • Microsoft 365 hardening and drift checks
    • Patch and vulnerability management
    • Backup with scheduled restore tests
    • Awareness training and phishing simulations
    • Incident response included
    Get a quote

    Managed plus compliance

    $129 per user, per month

    For regulated work, enterprise clients, or an audit on the calendar.

    • Everything in Managed
    • Virtual CISO and quarterly planning
    • Framework mapping and evidence collection
    • Client security questionnaires handled
    • Annual tabletop exercise
    Get a quote

    Minimum 15 users. Servers, network devices, and site coverage are quoted separately. Co-managed arrangements with an existing IT provider are welcome.

    Why businesses choose us

    Security is the whole job

    We are not a help desk that added a security package. Every engagement is built around detection, response, and evidence.

    North American coverage

    Analysts on shift across U.S. and Canadian time zones, with data residency options for organisations that need them.

    We work with your IT

    Co-managed by default. Your internal team or existing MSP keeps the business running while we cover the security layer.

    Plain reporting

    One monthly page in language an owner can read, plus the technical detail underneath when someone asks for it.

    Questions we get

    Before you book the call.

    Do we have to fire our current IT provider?
    No. Most of our clients keep their internal team or MSP for day-to-day support and bring us in for the security layer. We document the split so nothing falls between us, and we are happy to run the joint monthly call.
    How quickly do you respond to something serious?
    Critical alerts are triaged by a human within 15 minutes, 24 hours a day. Containment actions such as isolating a device or revoking sessions are pre-authorised in your service agreement so we do not wait for someone to wake up.
    What size of business do you work with?
    Typically 20 to 500 employees, across the United States and Canada. Below about 15 users a managed programme rarely makes financial sense, and we will tell you that on the first call.
    Do you support Macs and remote staff?
    Yes. Windows and macOS are covered equally, and everything we deploy works for people who never touch an office network. Mobile device management is available as an add-on.
    What actually happens if we get breached?
    We contain first, then run the incident response plan we wrote with you: scope, evidence, eradication, recovery, and a written report. We coordinate with your insurer's panel and legal counsel, and we do not bill an emergency rate to clients on a managed agreement.
    How long is the agreement?
    Twelve months to start, because the first two months are mostly our work. After that it continues month to month with 30 days' notice. Your data and configuration are yours, and we document the handover if you leave.
    What does the security review cost?
    Nothing, and there is no obligation. It is a 30-minute conversation followed by a read-only assessment of identity, endpoints, email, and backups. You keep the findings report either way.

    Start here

    Book your security review.

    Tell us a little about your business and we will come back within one business day with a time. If it turns out you do not need us, we will say so.

    Not ready to talk? Take the checklist instead.

    The ten controls insurers ask about, with how to check each one yourself. No form required.

    Read the checklist