Cybersecurity

Security Built In — Not Bolted On.

Layered protection for Dallas–Fort Worth businesses that closes the gaps most MSPs leave open: endpoint, email, identity, and network — designed to work together, not as a checkbox pile.

Prevention-firstNot just detection
Enterprise pedigreeEx-Lehman, ex-Nomura
Insurance-readyMFA, EDR, backups, IR
SB 2610 alignedTexas safe-harbor ready
The real problem

"We Have Antivirus and a Firewall" Isn't a Strategy.

Most DFW small businesses have a firewall from 2018, endpoint antivirus that came with the laptop, and email running on default Microsoft 365 settings. That's not a security posture — that's a hope.

Attackers don't attack one layer. They chain them: a phishing email lands, a password gets typed into a fake login page, MFA isn't enforced, they log in as your CFO, and by the time your antivirus notices, the wire has already gone out.

Real security is layered. Every layer catches what the last one missed. That's what we build.

Antivirus + firewall

  • One layer, one point of failure
  • Tools that don't talk to each other
  • Reactive alerts, after the damage
  • Gaps attackers know how to find

Layered security (48 Technologies)

  • Endpoint + email + identity + network
  • Tools designed to work together
  • Continuous monitoring and hardening
  • Fewer incidents — not just faster response
What's included

Four Layers, Working Together.

Cybersecurity isn't a product you buy — it's a set of controls that overlap. Every one of these runs on every client environment we manage. No à la carte gaps.

Endpoint

  • Managed EDR — not consumer antivirus
  • Every workstation, laptop, and server
  • USB and script-execution controls
  • Weekly patch cycles with proof

Email

  • Advanced threat protection & sandboxing
  • DMARC, SPF, DKIM enforced
  • Business email compromise (BEC) rules
  • Phishing simulations for your team

Identity

  • Microsoft Entra MFA on every login
  • Conditional access & risk-based rules
  • Least-privilege on admin accounts
  • Automated onboarding/offboarding

Network & monitoring

  • Managed firewall with active rules
  • 24/7 alerting on unusual activity
  • Segmented guest and IoT networks
  • Monthly posture summary
How we harden a business

From "Exposed" to "Insurance-Ready" in 60 Days.

Cybersecurity is not a one-week project. But it is a bounded one. Here's the sequence we run for every new client.

Week 1–2 — Assess

We find out what's actually there.

A vendor-neutral review of your current controls, aligned to CIS Controls / NIST CSF — so we can prioritize by real risk, not vendor upsell.

  • Endpoint & M365 tenant review
  • MFA & admin-rights audit
  • Firewall rules & external attack surface
  • Prioritized risk register
Week 3–6 — Deploy

We close the highest-risk gaps first.

MFA everywhere, EDR on every endpoint, DMARC in enforcement mode, backups verified. The controls insurers now require — actually working.

  • EDR rolled out to every endpoint
  • MFA + conditional access enforced
  • DMARC / SPF / DKIM in enforcement
  • Backup restore tested end-to-end
Week 7–8 — Operationalize

We turn it into a running program.

Security only works if someone owns it every day. Steady-state monitoring, monthly reports, quarterly reviews — and an incident response playbook you can actually use.

  • Monthly cybersecurity report
  • Incident response playbook delivered
  • Simulated phishing baseline
  • Cyber-insurance evidence pack
How we scope

Priced Per User, With the Real Numbers on the Table.

Cybersecurity is bundled into our managed IT service on a per-user basis — the same flat rate that covers monitoring, help desk, and patching. If you already have an IT provider and just want the security layer, we quote it as a standalone bolt-on.

Where your quote lands depends on your risk floor. A healthcare-adjacent business, a defense contractor, and a 20-person marketing firm have very different threat models and insurance requirements — and different price points.
  • 1. Regulatory floorHIPAA, PCI, CMMC, or Texas SB 2610 safe-harbor shift the controls you need — and the effort to run them.
  • 2. Endpoint & user countHow many users and endpoints we're licensing and monitoring. Volume brings the per-user rate down.
  • 3. Existing debtA tenant with no MFA and no EDR takes more setup than one already partway there. We quote the runway separately.
The alternatives

Layered Security vs. "AV + Firewall" vs. In-House SOC

Three ways to run cybersecurity at a 25–75 employee DFW business. Only one of them is defensible when the insurance carrier asks for evidence.

AV + Firewall Only

The "we're covered" trap
  • One-layer defense
  • No MFA enforcement
  • No email authentication (DMARC)
  • No monitoring between incidents
  • Insurance may deny at claim time
  • Nobody owns it day-to-day
Cheapest — until the claim gets denied

Layered Security — 48 Technologies

Endpoint + email + identity + network
  • Managed EDR on every endpoint
  • MFA + conditional access enforced
  • DMARC / SPF / DKIM in enforcement
  • 24/7 monitoring & incident response
  • Cyber-insurance evidence pack
  • Monthly report, quarterly review
Defensible — and actually operated

In-House SOC

Full-time security team
  • $250K+ fully loaded, minimum
  • Requires 3+ specialists for coverage
  • 24/7 requires shift rotation
  • Tooling stack is a separate budget
  • Hard to hire and retain in DFW
  • Great — once you're 500+ people
Right for enterprise — overkill for SMB
Tom Cloud, founder of 48 Technologies
At Lehman and Nomura I watched what real attackers can do. I built this for the DFW businesses that can't afford to learn that lesson the hard way.
Tom Cloud · Founder, 48 Technologies · More about Tom →
What's next

Find Out How Exposed You Really Are — Free.

Start with a 15-minute Cyber Insurance Audit. We'll show you exactly what your policy expects, what you actually have, and where the gap is. No sales pitch.