Skip to main content
Cybersecurity

Practical cybersecurity for real businesses.

You cannot eliminate every technology risk. You can make your business harder to compromise, catch suspicious activity sooner, limit the damage when something happens, and have a plan for what comes next.
RPMC helps businesses put sensible security measures in place across their computers, accounts, email, cloud services, networks, and wider technology environment.
Technician helping a colleague at a computer
Colleagues discussing something on a laptop
Team reviewing work together around a table
IT professional reviewing information on a monitor

Prevention and preparation

Hope for the best. Plan for the worst.

A common security promise is some version of, "We will keep the bad guys out." Real security is more complicated than that.

Known weaknesses can be patched. Accounts can be protected. Computers can be monitored. Security policies can be improved. Then tomorrow a new vulnerability can be discovered that nobody knew about today. That does not make security pointless. It is the reason security needs more than one layer. RPMC takes the view that sooner or later every business will deal with something suspicious. That does not mean every incident becomes a disaster.

Early action keeps incidents smaller

A malicious email can be identified before someone acts on it. Suspicious software can be detected before it spreads. A compromised account can be locked down before more damage is done. An unhealthy system can be corrected before it becomes tomorrow's emergency. The goal is to reduce the chances of something happening, catch problems as early as practical, limit their impact, and know what to do next. You cannot plan on preventing every security incident. You can plan to keep an incident from becoming a disaster.

Small team in a meeting around a laptop
Layered protection

Security is not one product

Installing security software is important. It is not the whole job. Modern business security has several layers because there are several ways technology can be attacked or misused. Good security comes from putting sensible controls around the whole environment and keeping them working over time.
A secure computer with a compromised Microsoft 365 account is still a problem. A strong password does not help if an employee unknowingly approves a malicious sign-in. A fully patched workstation does not protect an old network device with vulnerable firmware. A backup can help you recover from an attack, but it does not stop the attack from happening in the first place.
Identity and access
Employees should have their own accounts, strong authentication, and appropriate access to the systems they actually need. Multi-factor authentication is now a normal part of doing business online. It is not always convenient, especially when personal mobile devices become part of the process, but passwords alone should not carry the entire responsibility for protecting an important business account. As businesses grow, centralized account and identity management becomes increasingly important. Shared passwords, shared computer accounts, and informal access that worked when the company was very small can become real security problems later.
Computers and devices
Business computers need appropriate endpoint protection, monitoring, maintenance, and security updates. Security is not just about detecting known viruses. Modern endpoint protection can also help identify suspicious behaviour and activity that may require investigation. The important part is not simply that an alert exists. Someone needs to work out what the alert means.
Email and cloud services
Email remains one of the easiest ways for something suspicious to reach an employee. Microsoft 365 and other cloud services also mean that a business account may be reachable from almost anywhere. Protecting the computer in the office is only one part of protecting the account. Account configuration, authentication, email security, access, and cloud settings all contribute to the security of the business.
Networks and infrastructure
Firewalls, wireless networks, switches, VPNs, servers, storage, firmware, and other infrastructure can all affect security. Cybersecurity does not stop at the workstation. The wider environment matters too.

A common assumption

"Why would anyone care about my computer?"

This is one of the most dangerous assumptions a small business can make. An attacker does not have to know your company. They do not have to dislike your company. They may not care what your business does at all. They only need to find something they can use.

Your systems have value because you need them.

Being a small business does not make your technology unimportant. It usually means the opposite. You depend on it.

Your email has value because people trust messages that come from your account.

Your data has value because your business depends on it.

Your credentials may provide access to something else.

Your computer may provide another route into the business.

And if losing access would stop you from working, that interruption itself has value to someone trying to extort money from the business.

When something is flagged

An alert is the start of the investigation

Security tools generate information. RPMC still needs to determine what that information means. A detection might represent a real infection. It might be suspicious activity that needs more investigation. It might also turn out to be legitimate activity or a false positive. RPMC approaches security incidents the same way we approach other difficult technical problems: follow the evidence.
01
Determine what was detected
Understand the alert, behaviour, account, device, or event that caused concern.
Person working at a laptop with notes nearby
02
Reduce immediate risk
Restrict an account, revoke access, isolate activity, or remove a device from the network when the situation warrants it.
Technician helping a colleague at a computer
03
Investigate and understand the scope
Run deeper scans, review the affected environment, examine account activity, and determine what else may be involved. One affected computer is different from an issue that has reached multiple accounts, devices, or systems.
Small team in a meeting around a laptop
04
Remediate and recover
Remove the threat, correct the weakness, reset credentials, repair affected systems, or take other appropriate action. If systems or data have been damaged, the situation may move from cybersecurity response into backup and business continuity.
People working on laptops in an office
There are standard procedures, but security incidents still require judgment. The right response depends on what actually happened.

Security reviews look beyond the obvious

Technology environments change. New employees arrive. Old employees leave. Computers are replaced. Software is installed. Cloud services are added. Firmware gets old. Accounts and permissions accumulate. Settings that made sense several years ago may no longer make sense today. RPMC security reviews look across the environment for things that deserve attention. Depending on the environment, that can include:
Operating system versions
Patch status
Endpoint protection
Device health
Accounts and authentication
Microsoft 365 and cloud security
Infrastructure
Network equipment
Firmware
Peripheral devices
Aging technology
Security configuration
Other avoidable exposure
This is particularly important when RPMC begins working with an existing environment. Before improving security, it helps to understand what is actually there.
Person writing an email on a laptop
A practical place to start

If it looks suspicious, send it.

Your employees should not have to become cybersecurity analysts before they are allowed to ask for help. If someone receives an email that does not look right, RPMC can examine it. That may include looking at the sender, message details, links, attachments, and other indicators that help determine whether the message is legitimate. Potentially dangerous files or links can also be examined away from the employee's normal business computer. The answer is not always simply yes or no.
Sometimes It appears safe.
Sometimes There are things here that do not look right. Treat it cautiously.
And sometimes This is not safe. Delete it and do not interact with it.
What matters is that the employee had somewhere to ask before guessing. Stopping to question something suspicious is not an employee causing a security problem. It is good security behaviour.
Get Support
People doing their jobs

Security should make it easier to ask for help

Employees are often described as the weakest link in cybersecurity. RPMC does not think that is a particularly useful way to treat people. Most employees are trying to do their jobs. They receive email, open documents, sign in to systems, work remotely, answer customers, and move information around because the business requires them to. Security should support that work.
Technician helping a colleague at a computer
Employees need somewhere to ask
Employees need sensible protections, clear guidance, and somewhere to ask when they are uncertain.
Practical guidance
RPMC can provide practical security guidance and knowledge-base information as part of supporting the environment.
Formal training where needed
More formal security-awareness training can also be added where the business needs it.
The goal is not to make employees afraid to touch the computer. It is to make safer decisions easier.
Monitored security

Someone should be watching

Security software that quietly installs and is never looked at does not provide the same value as monitored security. Where managed monitoring is in place, security activity can be reviewed around the clock so that potentially important events are assessed rather than simply left in an alert queue.

An alert

Information has arrived.

Some alerts require action. Some require more investigation. Some turn out to be harmless.

A response

Someone decides what it means.

The value comes from having a process for deciding which is which.

An investigation

The evidence gets checked.

If something looks suspicious or unclear, RPMC can look deeper into the device, account, activity, or surrounding environment to understand what actually happened.

An action

The right next step is taken.

Harmless alerts can be closed. Real concerns may need containment, remediation, credential changes, recovery, or another appropriate response based on what the investigation found.

Receiving an alert is not the same as responding to an incident.
Foundational controls

What practical business security looks like

Not every business needs the same security architecture. But there are fundamentals that most businesses should be thinking about.
Strong endpoint protection
Business computers should use appropriate security protection and monitoring. Consumer-style antivirus alone should not be the entire security strategy for an organization that depends on its computers to operate.
Multi-factor authentication
Important cloud accounts should use more than a password. MFA may add an extra step, but that extra step can make a stolen password considerably less useful to an attacker.
Better password habits
Passwords should be strong enough to protect what they provide access to. Employees should have their own accounts rather than casually sharing credentials. Your account represents you. If another employee needs access, the better answer is usually to give them appropriate access rather than give them your password.
Centralized identity where appropriate
As the number of computers and employees grows, managing each workstation as an independent island becomes harder to control. Centralized identity and access management helps give employees consistent accounts, permissions, and security across the business environment.
Backups
Security reduces risk. Backup prepares for the possibility that prevention was not enough. Important business systems and data should have an appropriate recovery strategy. Cybersecurity and backup work together, but they solve different parts of the problem.
Security updates and maintenance
Known security weaknesses should not stay open indefinitely. RPMC manages patching with both security and business impact in mind. A critical security update may need to move quickly. A normal update may be allowed a short period for widespread problems to appear before deployment. Where practical, maintenance is scheduled during lower-impact periods so that if an update creates an issue, there is a better opportunity to deal with it before the workweek begins. Security matters. So does keeping the business running.
Related, not the same

Cybersecurity and business continuity are different jobs

Security asks how we reduce the chance of something happening, detect it, contain it, and respond. Business continuity asks how we get the business working again if systems or data are damaged or unavailable anyway. A business needs both conversations. You can have excellent security and still experience hardware failure, accidental deletion, a cloud problem, or a new threat that existing protection did not stop. You can also have excellent backups and still suffer unnecessary disruption because preventable security weaknesses were ignored. Good security tries to keep the incident small. Good business continuity prepares for the possibility that it was not.
Not a one-time project

Cybersecurity works best as an ongoing responsibility

Some security work is a project. A business may need help improving Microsoft 365 security, correcting weak account practices, replacing outdated equipment, reviewing an environment, or dealing with a specific concern. But security does not stay finished. New vulnerabilities appear. Businesses change. Employees change. Devices change. Software changes. Attack methods change.
An ongoing managed relationship gives RPMC the ability to understand the environment, maintain the security baseline, monitor what is happening, and take more responsibility over time. For businesses that want RPMC involved across the wider technology environment, Managed IT Services is usually the next conversation. The difference is not simply adding more security products. It is having someone responsible for keeping the technology environment moving in the right direction.
Team reviewing work together around a tableColleagues discussing something on a laptop
Barrie, Toronto and the GTA

Not sure whether your business is properly protected?

RPMC is based in Barrie and works with businesses across Barrie, Toronto and the Greater Toronto Area. Whether you are trying to improve an existing security environment, dealing with an active concern, or simply trying to understand what your business should be doing differently, start with the situation you have. You do not need to know the name of the security service before talking to us. Tell us what you have today, what concerns you, and what you are trying to protect. We will help you work out what deserves attention.
Book a Free Discovery Call Get Support