Cybersecurity
Security you can evidence, not security you can only claim.
Endpoint protection, a 24 hour security operations centre, phishing simulations and dark web monitoring, run for Houston companies that will eventually be asked to prove all of it.
30 minutes. We tell you what we would change first, and you keep the notes.
What actually goes wrong
Three failures we see repeatedly
None of these are exotic. They are the ordinary ways companies of your size get hurt, which is also why they are preventable.
Credentials, not malware
Most intrusions at this size begin with a working password rather than a virus. Phishing simulations and dark web monitoring exist because the credential is the front door, and it is usually opened rather than forced.
The gap between alert and human
A tool that flags something at 2am is worth very little if the first person to read it arrives at 8am. That gap is what the 24/7 SOC and the 15 minutes response commitment are for.
Backups nobody has restored
A backup that has never been restored is an assumption, not a safeguard. Ransomware is the moment you discover which one you had. Tested recovery is in every plan for that reason.
What is running
The security stack, in full
Everything below is included from the entry plan up, at $72 per user per month. Compliance work is part of the service rather than a separate engagement.
- 24/7 RMM monitoring with NOC alerting
- XDR endpoint protection and 24/7 SOC
- Server backup with tested recovery
- Patch management and software standardisation
- Microsoft 365 or Google Workspace backup
- Phishing simulations and security training
- Dark web monitoring
- vCISO consulting
The part people skip
Controls are easy. Evidence is the hard part.
Buying security software is a purchase decision and takes an afternoon. Being able to demonstrate, eleven months later, that the software was configured correctly the whole time, that the alerts were reviewed, that the training was completed and that a restore was actually tested, is an operational discipline. That second thing is what an audit examines and what a client security questionnaire is really asking about.
It is also the thing companies discover late. The typical sequence is a large customer sending a security questionnaire, or an insurer asking for attestations at renewal, and the answers turning out to be unavailable rather than unfavourable. Nobody had been keeping the records because nobody had been asked for them yet.
On our own position, we hold to the same standard we ask of clients: EzziTrust LLC operates to SOC 2 aligned controls and its own Type II audit is in progress. Stating that plainly is more useful to you than a badge would be.
Questions before you buy security
Straight answers
How is this different from the antivirus we already have?
Antivirus recognises files it has seen before. That was adequate when attacks arrived as attachments and stayed on one machine. Modern intrusions use valid credentials, legitimate tools already installed on your systems, and move sideways between machines, so there is often no malicious file to detect at all. XDR watches behaviour rather than files, and a 24/7 SOC means a human looks at the alert at three in the morning instead of it sitting in a queue until Monday. The gap is not detection quality. It is that nobody is watching your antivirus.
We are a small company. Why would anyone target us?
Because almost nobody is targeted personally. The overwhelming majority of intrusions at this size are opportunistic: automated scanning finds an exposed service or a reused password, and the attack proceeds because it can. Being uninteresting is not a defence against a process that never looked at who you are. The practical consequence is that the controls that stop this are unglamorous and cheap, which is why they sit in the Cybersecurity & Compliance plan at $72 per user per month rather than in an enterprise product.
What actually happens in the first hour of a suspected breach?
The alert reaches the 24/7 SOC before it reaches you, because that is what the monitoring is for. An emergency is responded to inside 15 minutes at any hour. The first moves are containment rather than investigation: isolate the affected endpoints, cut the credential being used, and confirm the backups are intact and untouched. Understanding exactly what happened comes after the bleeding stops, and it comes from logs that were being collected before the incident rather than reconstructed after it.
Can you produce the evidence our auditor or client asks for?
That is the reason security awareness training, phishing simulations and tested backups sit inside the plan rather than being sold separately. An auditor rarely asks whether you have a policy. They ask you to show that training happened, that a restore was tested and worked, that patches were applied within a window, and that access was reviewed. Those are records, and records only exist if something was collecting them all year.
Is EzziTrust SOC 2 certified?
EzziTrust LLC operates to SOC 2 aligned controls and its own Type II audit is in progress. We would rather state that plainly than let a badge imply otherwise, because a certification claim is the first thing a serious buyer verifies. What we can evidence today is the control set itself, and how it is operated for clients.
Do we have to take the full IT plan to get the security?
No. Cybersecurity & Compliance exists for companies that already have IT covered and need the security and compliance side handled. At 20 users that is $1,440 a month. When a client already has an IT person we run co-managed. They keep supporting your people while we take cybersecurity and compliance, and our team covers nights, weekends and anything they cannot get to.
Book a 30 minute security review
We look at what you are running, tell you the two things we would fix first, and you keep the notes whether or not you hire us.