Enterprise security solutions for the new frontier of AI
Attackers now send phishing with perfect grammar in the right thread, and clone a voice from a sample scraped off a voicemail greeting. Defenders get AI-driven detection, and a new attack surface with it: staff pasting records into public chatbots, and AI agents acting inside business systems with real credentials. We run security programs that treat both as the same job.
Express IT Solutions, offices in Fayetteville and downtown Syracuse, running Central New York networks since 2005.
Enterprise security solutions in the age of AI are one layered program that covers both sides of what AI changed: attackers now send phishing with perfect grammar and clone voices from short public samples, while staff pasting records into public chatbots and AI agents acting inside business systems with real credentials open a new attack surface. The program is not a product and not a single AI detection box: it is the same layered discipline run since 2005, identity, endpoints, email, backup and recovery, monitoring, policies and people, and vendor access, with a new AI-era line item inside each layer, run from Syracuse by the team that builds and secures AI agents.
Four things that are different now, from people who clean up after all four.
None of this is theoretical and none of it needs a nation state. The tools that write clean email, mimic a voice, and act inside a browser are cheap, public, and indifferent to who is using them. Here is what that does to a working business, stripped of the conference-keynote framing.
Phishing that reads perfectly
The tell you trained your staff on is gone. For twenty years the giveaway was the language: the odd greeting, the broken English, the wrong name. AI writes a payment request in your supplier’s tone, with the right project reference, inside the real thread. It can hold the follow-up conversation too, politely, for days.
What has not changed is the plumbing. The expensive version of this attack still runs through a compromised mailbox and a hidden inbox rule that quietly buries the real correspondence while the fraud plays out. We wrote up exactly how to check your own tenant for that in our walkthrough of Microsoft 365 inbox rule invoice fraud. Read it, run the check, it costs nothing.
The defensive consequence: you can no longer train people to spot bad writing, because there is no bad writing. You train them to verify the request, and you put controls in places where the quality of the prose is irrelevant: enforced multi-factor, identity threat detection, email authentication records that are actually configured, and filtering that looks at behavior rather than spelling.
The voice on the phone
A voice is no longer identification. Cloning one takes a short public sample, a webinar, a voicemail greeting, a video on the company site. The call that follows sounds like your CFO, knows the context, and asks for something urgent.
The fix is procedural and it is boring, which is why it works. Payment instructions and bank-detail changes get verified out of band, on a number you already had on file, never on the number or the thread the request arrived through. Transfers above a threshold you choose take two named approvers. And the rule that matters most: urgency is itself the red flag. Any request engineered so there is no time to verify is a request that must be verified.
Write this down before you need it. Nobody improvises well with a convincing voice on the line, and a procedure only protects you if the person following it knows they will be backed for slowing down.
Shadow AI, and agents with real credentials
Shadow AI, or data leaving through a chat window
Your staff are already using AI tools. The only open question is whether you issued them or they brought their own. A contract pasted into a public chatbot to “summarize it”, a patient list pasted in to “clean up the formatting”, source code pasted in to find a bug: each one is business data leaving through port 443, looking exactly like normal web traffic.
Blocking one chatbot does not solve this, and we cover why in the FAQ below. What works is the combination: a written AI-use policy that says what may go where, approved tools that are good enough that nobody needs to sneak, and visibility at the network and software layer so you know what is actually in use. The published MSP plans already include firewall, DNS and software management at the middle tier, which is the visibility part of that sentence.
Software that holds your credentials
An AI agent reads your records and acts inside your systems. That is the entire point of one, and it is the entire risk. Every hard question in security gets asked again the moment software starts acting on its own with a login.
We get to say this as builders, not bystanders: AI projects in production for Central New York businesses, from the same firm that has run networks since 2005. Our own product is the reference implementation of the posture we recommend. PlowzBox, built for field-service operators, runs its AI models on hardware the customer owns, accepts no inbound connections from the internet, and holds every outbound message for owner approval. We did not do that because it was easy. We did it because an agent without a boundary is an incident with a start date.
The rules we apply to every agent, ours or anyone’s: it gets its own identity, never a shared human login. It gets the narrowest permissions that let it do the one job. Its boundary is written down: what it may read, what it may change, what it may send. It keeps a record a human can audit. And it has an off switch that does not take a person’s account down with it.
How we build and lock these down: AI agents and workflow automation and secure AI agents.
Cheap, public, and indifferent to who is using them.
Scoped, monitored, and offboarded like staff.
One layered program, with the AI-era job added to every layer.
Enterprise security is not a product and it is not a single AI detection box. It is the same layered discipline we have run since 2005, with a new line item inside each layer. The foundation is explained in full, layer by layer, on our cybersecurity page for Central New York business. Here is the enterprise version, and what AI adds to each row.
-
Identity, vendors and access
Multi-factor on every account, no exceptions for seniority. Identity threat detection and response (ITDR) watching for the logins that pass the password check but fail the smell test. Who can reach your systems from outside, through what, reviewed and recorded, with offboarding that actually closes accounts. What AI added to it: agent and automation accounts are identities too, scoped, monitored, and offboarded like staff, and every AI vendor and connected automation is a third party with access, on the same register.
-
Endpoints
Managed EDR on every machine, with MDR and 24/7 security operations monitoring behind it, centrally visible. What AI added to it: detection tuned for tooling that behaves like a user, because some of your software now does.
-
Email
Spam and phishing filtering, spoof protection, authentication records configured rather than left at default. Advanced email security at the top tier. What AI added to it: filters judged on behavior and authentication, not prose quality, because the prose is now perfect.
-
Backup and recovery
Microsoft 365 backup across Email, OneDrive and SharePoint. Device backup. Restores proven on a schedule, not assumed. What AI added to it: recovery paths that do not depend on any AI tool being trustworthy on the day you need them.
-
Monitoring
24/7 security operation center monitoring with a human escalation path. What AI added to it: watching what the automations did overnight, not only what the people did.
-
Policies and people
Security awareness training built around the attacks that actually land. What AI added to it: a written AI-use policy: approved tools, what may be pasted where, and the out-of-band verification rule for payments.


What enterprise security costs
The mapping to published pricing is direct, and you can check it yourself on the managed IT packages page. The $80 per seat Secure plan already carries EDR and MDR, ITDR, email spam filtering, firewall, DNS and software management, 24/7 security operation center monitoring, and Microsoft 365 backup. The $99 Total plan adds advanced email security, security awareness training, unlimited device backup, and compliance and reporting support. The $65 Standard plan is the floor: patching, device management, endpoint antivirus. Program work beyond the packages, the AI-use policy, the payment verification procedures, the agent reviews, is scoped with you and confirmed in writing before anything starts.
Tell us where you stand. The first conversation is free and specific.
Three kinds of business this page was written for.
Operating companies
Businesses that run physical operations, where the IT network sits next to equipment that must not stop. We serve many power plant and peaker plant clients across the country, from Upstate New York to California, and at those sites we apply this discipline on the business side of the IT/OT boundary. The habits that come from that work, change control, access registers, the assumption that downtime is measured in more than annoyance, carry into every program we run.
Multi-site businesses
One security program, enforced identically at every location, is worth more than a good program at headquarters and hope everywhere else. We support multi-site clients at every location they run, including the ones we fly to, and the multi-site IT support page covers how that is structured. Within 50 miles of Syracuse, no questions asked. All of Upstate New York, covered.
Firms with compliance programs
If your sector carries a framework, the framework is yours and your auditor’s. Our job is inside it: run the controls it requires, keep the records it expects, and answer the operational questions, from your auditor or your insurer, with evidence instead of recollection. We do not hold certifications, we are not auditors, and we will not imply otherwise. What we will do is make the honest answers to the questionnaire better every quarter.
Word for word from public Google reviews. Names as the reviewers published them.
“Express provides excellent service, we’ve been with them for years. They are always responsive to whatever issues we might have. Great work, always totally pleased.”
“I have always had good experiences with this team. They listen to the problem and take the time to go over it with you if you need or want them to. Very good experience and reasonable.”
Straight answers on enterprise security
The questions we actually get asked.
Can AI write phishing that gets past filters?
Yes, AI routinely writes phishing that passes both spam filters and a careful human read, because the language is fluent and the context is correct. Filters that score on broken grammar or known templates miss it, which is why the working defenses sit elsewhere: enforced multi-factor, identity threat detection, properly configured email authentication, and a verification procedure for any request that moves money. The follow-on mechanics have not changed, and our write-up on Microsoft 365 inbox rule invoice fraud shows you how to check your own tenant for the hidden rules these attacks leave behind.
Should we block ChatGPT at work?
A blanket ban on AI chatbots usually fails, because the work moves to personal phones where you have no visibility at all. The approach that holds up is a short written AI-use policy, approved tools good enough that nobody needs to work around them, and network-level visibility so you know what is actually in use. Block specific tools where a real reason exists, by all means. But policy plus approved tools beats prohibition, because prohibition only relocates the risk.
How do we secure AI agents that act for us?
Treat every AI agent as an account, because that is what it is. It gets its own identity rather than a shared human login, the narrowest permissions that cover its one job, a written boundary saying what it may read, change and send, a log a human can audit, and an off switch that does not disrupt a person’s access. We build agents ourselves, with AI projects in production for Central New York businesses, and our own product holds every outbound message for owner approval and accepts no inbound connections. We secure agents the way we ship them: secure AI agents covers the full checklist.
How do we stop voice-clone payment fraud?
You stop it with procedure, not with ear training, because a cloned voice is built to survive ear training. Every payment instruction or bank-detail change gets verified out of band, on a number already on file, never through the channel the request arrived on. Set a threshold above which two named people approve, and make it policy that urgency triggers more verification, not less. Then put it in writing, so the person who slows down a convincing caller knows the business will back them.
What does enterprise security cost?
The baseline has published pricing: the managed packages run $65, $80 and $99 per user per month, flat, and the security stack described on this page starts at the $80 Secure tier. The full inclusions are on the managed IT packages page. One-off work bills hourly from the pay-as-you-go rate card. Program work beyond the packages, policies, verification procedures, agent reviews, is scoped on a call and confirmed in writing before you commit to anything, because a number quoted without your details is a guess.
Do you replace our compliance program?
No, and nobody honest will offer to. Your compliance program belongs to you and your auditor; we work inside it. That means running the controls it requires, producing the records it expects, and answering your auditor’s and insurer’s operational questions with evidence. We hold no certifications and we are not an audit firm. If part of your framework needs a specialist or an accredited assessor, we will say so plainly and keep running the controls while they do their part.
What is shadow AI, and how do we find it?
Shadow AI is the set of AI tools your staff use for work without approval or oversight, usually public chatbots on company or personal devices. You find it with network and software visibility rather than interrogation: DNS and software management shows which tools are actually in use, and the pattern is usually wider than anyone guessed. The response is not punishment. It is an AI-use policy, approved alternatives, and a clear statement of what must never be pasted into a public model.
We already have an IT provider or an internal team. Can you run just the security and AI side?
Yes, co-managed is normal here and often the right structure. Your existing provider or internal team keeps the day-to-day they are good at, and we carry the security layers, the monitoring, and the AI-specific work: agent reviews, the AI-use policy, the verification procedures. We will also tell you honestly if your current setup is fine, because taking work that does not need doing is how trust gets spent.
Book a security review
A few fields now, a straight recommendation on the call.
Bring us the question you actually have.
Maybe it is an invoice that nearly got paid. Maybe someone found a chatbot transcript with client data in it. Maybe you want an agent doing real work and nobody can tell you what it would be allowed to touch. Bring the real question. We will tell you which gaps matter for a business your size, what each one takes to close, and which ones you can close yourself without paying anybody.
It goes to our offices in Fayetteville and downtown Syracuse, not a call centre.
We will tell you straight if the network is not ready for AI, or if your current setup is fine.
No revenue question, no budget question, no qualification hoops.
If the honest answer is that you do not need us yet, that is the answer you will get.
Fayetteville, NY 13066
Syracuse, NY 13202
help@expresssupport.com