Cybersecurity for Syracuse and Central New York businesses.
Most attacks on a small business are not clever. They arrive as an email that looks like a supplier, a laptop that missed three months of updates, or a password reused from a website that got breached. We have run security for businesses across Central New York since 2005, on site across all of Upstate New York, and at every location our multi site clients run. Call (315) 682-6372.
Not ready to talk? Run the nine-point check yourself and see where you stand.
The stack we actually run
Cybersecurity for a small business is seven jobs done consistently: protecting the machines, filtering the email, controlling the network edge, backing up and actually test-restoring the data, patching everything, teaching the people, and having a written plan for the day something gets through. Express IT Solutions has run those seven for Central New York businesses since 2005, from an office at 511 East Genesee St in Fayetteville. We are not auditors and we do not sell certifications. Call (315) 682-6372.
What does cybersecurity actually cover for a small business?
Seven layers, and no single product is more than one of them. Anyone selling you cybersecurity as one purchase is selling you a layer and calling it a roof.
- An invoice from a supplier address that is one letter off
- A laptop that has been off the network for three weeks
- A login attempt from a password reused on a breached site
Nothing here depends on the person at the desk making the right call under pressure. That is the point of layers.
- Quarantined before it reaches the inbox
- Patched the moment it reconnects
- Blocked at the second factor, and you get told
- 01
Endpoint protection
Every laptop, desktop and server runs managed protection that we can see from here, not a free tool somebody installed once and never opened again. When one machine trips an alert, we know which machine, whose it is, and where it sits.
We run: Bitdefender and Webroot, centrally managed by us.
- 02
Email security
Filtering, spoof protection and the sending rules that stop someone forging your own domain at your own staff. Email is where the expensive attacks land, because a fake invoice does not need to break anything to work.
We run: Microsoft 365 with the anti-spoof and authentication records configured, not left at default.
- 03
Network and firewall
A managed edge, a separated guest network, and cameras, tablets and point-of-sale kept off the same network as the machine that touches your bank. Most small offices are one flat network, which means one compromised device reaches everything.
We run: Ubiquiti UniFi and Cisco Meraki, configured and monitored, not shipped and forgotten.
- 04
Backup and recovery
Backed up on site and off site, and restored on a schedule to prove the restore works. A backup nobody has ever restored from is a belief, not a backup. This is the layer that decides whether ransomware is a bad week or the end of the business.
We run: Synology on site with Microsoft Azure off site, with test restores as part of the service.
- 05
Patching and updates
Windows, macOS, the software on top, and the firmware in the firewall and the switches. The firmware is the one everybody forgets, and it is the one sitting directly on the internet. We patch on a cycle, in a reboot window you pick.
We run: a monthly patch cycle across every managed machine, with out-of-band pushes when something is being actively exploited.
- 06
Security awareness
Short, specific training for the people who actually get targeted, which is usually whoever pays the invoices and whoever answers the phone. Not an annual video nobody watches. The useful version teaches one rule: verify a payment change out of band, by voice, on a number you already had.
We run: practical sessions built around the attacks we see landing locally, plus phishing simulations where a client wants them.
- 07
Incident response
One page that says what happens in the first hour: who to call, who can shut things off, who talks to customers, and where the backups are. Written while everyone is calm, because nobody writes a good plan at 6pm on a Friday with the phones ringing.
We run: a written response plan agreed with you, and we are the number on it.
Product names are the property of their owners. We name these because they are what we run on Central New York networks, not because of any partner arrangement, and not as a claim of certification. If you already own something that works, we would rather manage that than sell you a replacement.
What a Central New York business is actually up against.
Nobody is writing custom malware for a nine-person firm in Fayetteville. What happens instead is duller and more effective: automated scanning finds an unpatched box, or a person gets an email that looks exactly like the one they were expecting.
- The invoice that is one letter off. A supplier’s email gets compromised, the thread is real, and the bank details on the last message are not. Nothing on your network has to break for this to cost you money.
- The machine nobody updated. Scanning for known holes is automated and constant. Being small does not make you invisible, it makes you cheap to try.
- The password that was already spent. Reused on a site that got breached years ago, still working on your email today, unless a second factor stops it.
- The flat network. One compromised laptop, and the camera recorder, the point-of-sale and the accounting PC are all one hop away.
Reported to the FBI as lost to internet crime in New York State in 2025, across 45,255 complaints. Fourth highest of any state on both counts.
Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report, state tables. Industry figure. Not an Express IT Solutions result.
Reported lost nationally to business email compromise in 2025, the second largest loss category. This is the fake-invoice attack, and it is the one aimed at small firms.
Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report, crime types by loss. Industry figure. Not an Express IT Solutions result.
Of breaches now start with a software vulnerability, which Verizon reports has overtaken stolen passwords as the top way attackers get in. That is layer five, patching.
Source: Verizon, 2026 Data Breach Investigations Report. Industry figure. Not an Express IT Solutions result.
We already have antivirus and a firewall. Is that not enough?
Those are two layers of seven, and they are the two that stop the attacks least likely to reach you. Antivirus does not stop a real supplier’s compromised email asking for new bank details. A firewall does not stop a reused password on a webmail login. The gaps we find most often in Central New York offices are the unglamorous ones: multi-factor missing on somebody senior, backups nobody has ever restored, and firmware three years behind.
| What people already have | What it does not cover | Which layer does |
|---|---|---|
| Antivirus | A convincing email asking for a payment change | Email security and awareness |
| A firewall | A stolen password used from a normal-looking browser | Multi-factor on every account |
| Cloud storage sync | Encrypted files syncing over the good copies | Backup with real restore testing |
| Windows Update on auto | Firewall, switch and camera firmware | Patching, including the network kit |
What actually happens in the first hour after a breach?
The first hour decides how much of the rest of the week you get back. In practice it is: isolate the affected machines from the network, confirm whether accounts or just devices are involved, force password and session resets on anything exposed, and check that a clean backup exists before anything gets rebuilt. Then, and only then, the conversation about what to tell customers. Guessing in public is how a bad day becomes a bad year.
- Isolate first, investigate second. Pulling a machine off the network costs nothing and buys everything.
- Assume the account, not just the device. If a password was typed into something fake, the device was never the problem.
- Verify the backup before you rebuild. Restoring onto a box that is still compromised repeats the whole thing.
- One person talks. Decide that in advance, in writing, while everybody is calm.
We are not a forensics firm and we do not present ourselves as one. For a serious incident we handle containment and recovery and we will tell you plainly at what point you want a specialist investigator, your insurer’s panel, or law enforcement involved.
Our insurer is asking security questions we cannot answer. Can you help?
Yes, and this is the most common reason a business calls us about security rather than about a computer being slow. Cyber insurance applications now ask specific operational questions: is multi-factor enforced on email, are backups tested, how fast do you patch, who has administrator rights. We can answer those with a record rather than a guess, and where the honest answer today is no, we will tell you what it takes to make it yes.
To be explicit: we are not auditors, we do not issue certifications, and we cannot make anyone compliant with a framework. What we can do is run the controls your insurer is asking about and produce evidence of it. Whether that satisfies your policy is between you and your insurer.
Managed security, doing it in-house, or doing nothing in particular.
Almost every small business is in one of these three columns right now. This is the structural difference between them, not a claim about any specific provider or any specific in-house person.
| In practice | Nothing formal | One person in-house | Managed security |
|---|---|---|---|
| Who is watching at 2am | Nobody | Nobody, they are asleep | A monitored queue and a rota |
| When patches get applied | When something breaks | When they get a free afternoon | On a monthly cycle you agreed |
| Last time a backup was restored | Never | Usually unknown | On a schedule, with a date |
| What happens when that person leaves | Nothing changes | Every password and login goes with them | Documented handover, accounts stay yours |
| Answering an insurer’s questionnaire | Guesswork | Best recollection | A record of what is actually enforced |
| What it costs you | Nothing until it costs everything | A salary, plus the work they stop doing | A flat monthly fee, scoped in writing |
| Best when | Honestly, never | You have enough scale to keep them busy and backed up | Security matters but it is nobody’s actual job |
Scroll the table sideways to see all three columns.
Co-managed is a real fourth option and often the right one: your in-house person keeps the work they are good at, and we cover the overnight monitoring, the patch cycle and the restore testing. See our managed IT services in Syracuse and Central New York for how that is structured.
Nine things to check before you call anyone, including us.
Answer these out loud. Every one is a yes or a no, and every no is a specific piece of work rather than a vague worry. You do not need us to run this, and you may not need us afterwards.
- 01
Can you name every machine that touches your data?
Including the laptop the bookkeeper uses from home, the old PC running one piece of software nobody will replace, and anything a contractor brought in. You cannot protect a device you do not know exists.
- 02
Is multi-factor on for every email account, including the owner’s?
The exception is almost always the person with the most authority and the least patience for being interrupted, which is exactly the account an attacker wants.
- 03
When did somebody last restore a real file from backup?
Not check that the backup ran. Restore something and open it. If nobody can give you a date, treat the answer as never.
- 04
Are your machines patched within a month of a fix being released?
And does that include the firewall, the switches and the wireless access points, not just Windows. Firmware is the layer that sits directly on the internet and it is the one that gets skipped.
- 05
Would a payment-details change from a real supplier get paid?
If the email came from the right address, in the right thread, in the right tone. If the answer is yes, that is the single most expensive gap on this list, and the fix is a rule rather than a product.
- 06
Does anyone still have access who no longer works there?
Email, the file share, the accounting system, the wifi password nobody has changed, the shared login for the supplier portal. Check the last one honestly.
- 07
Are the cameras and guest wifi on the same network as accounting?
In most small offices, everything is one flat network because that is what came out of the box. Separating them is a configuration change, not a purchase.
- 08
Do you know who to call at 6pm on a Friday, by name?
A support portal is not an answer. A person you have met, whose number is in your phone, is an answer.
- 09
Is there one page that says what happens in the first hour?
Who isolates the machines, who resets the passwords, who calls the insurer, who talks to customers, and where the backups live. One page. If it does not exist, that is the cheapest item on this list to fix.
The next thing asking for access to your data will not be a person.
An AI agent reads your records and acts inside your systems. That is the entire point of one, and it is the entire risk. Every question on this page gets asked again, harder, the moment software starts acting on its own with your credentials.
- It is an account, so it needs account rules. Its own identity, the narrowest permissions that let it work, and an off switch that does not disrupt a person’s login.
- It needs a boundary, in writing. Which systems it may read, what happens to that data, and where it is kept afterwards.
- It needs a record. If you cannot go back and read what it did and why, you are guessing.
- Security first, then the agent. If the network is not patched, backed up and separated, we will say so before we quote anything.
We would rather tell you the network is not ready than sell you an agent that sits on it.
Upstate NY
On site anywhere in Upstate New York
- Syracuse
- Fayetteville
- Manlius
- Liverpool
- Baldwinsville
- Cazenovia
- Chittenango
- Lafayette
- Jamesville
- Minoa
- Tully
All of it covered on site from one office at 511 East Genesee St, Fayetteville. The towns above are the ones we are in constantly. Clients with more than one office get us at every location, including the ones we fly to.
A security team down the road, not a portal in another time zone.
Security work is mostly unglamorous and continuous, and it goes wrong when nobody local owns it. We are one team: the people who set the firewall rules are the people who answer the phone.
- We come to you. On site anywhere in Upstate New York, including every town named in this section, out of one office in Fayetteville. If you run offices further out, we come to those too, including the ones we fly to.
- One number, real techs. (315) 682-6372, answered by people who know your setup.
- We will tell you no. If the work is not worth doing, or the honest fix is something you can do yourself, you will hear that.
The stuff people ask before they change anything.
Are you a certified or accredited security firm?
No, and we will not imply otherwise. We are not auditors, we do not issue certifications, and we do not hold a framework attestation. We are a Central New York IT firm that has run security for local businesses since 2005. What we can show you is what we actually do and what is actually enforced on your systems.
Can you make us HIPAA or PCI compliant?
No provider can make you compliant, including us, and anyone who says they can is selling something. Compliance is your obligation and it covers how your whole business operates, not just the technology. Bring your specific requirements to the scoping call and we will tell you plainly which controls we can run and which parts you will need an auditor or a specialist for.
How much does cybersecurity cost for a small business?
It depends on how many people and machines you have, what you already run, and how much you need documented for an insurer. We do not publish a figure because a number without your details is a guess. We scope it on a short call and confirm the monthly figure in writing before you commit to anything.
Do we have to leave our current IT provider?
No. Some clients keep their existing provider for day-to-day support and bring us in for the security layers specifically, or for a second opinion. We will tell you honestly if we think your current setup is fine, and we would rather do that than take work we do not need to do.
What do you do first if we sign up?
We look before we change anything. That means an inventory of machines and accounts, a check on multi-factor and administrator rights, a look at how backups run and whether anyone has restored from them, and the patch state of everything including the firewall. Then you get a plain list of what we found, ordered by what matters most.
Do you handle it if we get hit?
Yes, for containment and recovery: isolating machines, resetting accounts and sessions, and restoring from a verified clean backup. We are not a forensics firm and we will not pretend to be. For a serious incident we will tell you at what point you want a specialist investigator, your insurer’s panel, or law enforcement involved.
Is security included in your managed IT, or is it extra?
The baseline is built in, because we will not run a network we have not secured. Endpoint protection, patching, backup and account control come with managed IT. Deeper work like awareness training, tighter email controls and documented evidence for an insurer is scoped on top, and we tell you which bucket something falls into before we do it.
TELL US WHERE YOU STAND
Bring us the nine questions and your honest answers.
We will tell you which gaps matter for a business your size, which ones to close first, and which ones you can close yourself without paying anybody.
- It goes to our office in Fayetteville, not a call centre.
- We will tell you straight if there is a cheaper way to fix it.
- No revenue question, no budget question, no qualification hoops.
Or just call
That line reaches a person who knows the work. If you want an answer now instead of later today, calling is faster, and we would rather say that than pretend the form is.
The form is the better route if you would rather write it down than say it out loud, or you are somewhere you cannot take a call.
(315) 682-6372Find out where you actually stand.
Bring us the nine questions and your honest answers. We will tell you which gaps matter for a business your size, what each one takes to close, and which ones you can close yourself without paying anybody. Free, no obligation, no hard sell.
If the honest answer is that you are fine and do not need us, that is what you will hear.
Express IT Solutions · Cybersecurity for Central New York business · Last updated August 13, 2026