Irvine, California · Mon–Fri, 8 a.m.–5 p.m. Pacific

Call (833) 901-6649info@demakistech.com

Security

Security as the starting point of every plan

Most cyber-insurance applications now ask the same questions. Is multi-factor sign-in on for everyone? Is every computer protected? Are backups tested? Is your email domain protected against spoofing? We set these controls up, keep them running and write them down, so you can answer honestly.

The baseline every managed plan starts from

  1. Multi-factor sign-in for every user and every admin account
  2. Endpoint detection and response (EDR) on every computer
  3. Backups with an offline or immutable copy, restore-tested every quarter
  4. Patching on a written schedule, with critical updates handled quickly
  5. Email authentication: SPF, DKIM and DMARC, moved to enforcement
  6. Admin rights kept narrow and reviewed regularly
  7. A written incident-response plan that says who does what if something goes wrong

The Complete plan includes all seven. On the Essentials plan, any control the plan does not include, such as backup, is quoted as an add-on or declined in writing.

The baseline draws on key safeguards in the CIS Critical Security Controls (v8.1, Implementation Group 1), a widely used set of essential safeguards for smaller organizations.

If you decide to skip a control, we record that decision in writing. Nobody has to guess later.

Why email comes first

Business email compromise is when someone impersonates you or a supplier to redirect a payment. It is one of the most common and expensive attacks on small businesses.

$27,000

In Coalition's 2026 Cyber Claims Report, the average loss per business email compromise claim in 2025 was $27,000.

Email authentication (SPF, DKIM and DMARC) makes it much harder for someone to send mail that looks like it came from your domain. It is usually the fastest security win for a small office.

Fixed-scope security projects

These are available whether or not you are on a managed plan.

  • Email authentication fix

    We set up SPF, DKIM and DMARC for your domain, watch the reports, and move DMARC to enforcement once your legitimate mail is accounted for.

  • Cyber-insurance readiness check

    We compare your setup with your insurer's questionnaire. You get a written gap report and a plan to close each gap.

  • Microsoft 365 security review

    We check multi-factor sign-in, sign-in policies, admin roles, external sharing, mailbox forwarding rules and audit settings. You get a report of what we found and what we recommend.

Add-ons, on request

  • Security awareness training and phishing tests for your staff
  • A password manager (included in the Complete plan)
  • DNS filtering to block known-bad websites
  • Email security filtering (included in the Complete plan)
  • Backup for computers and Microsoft 365 on the Essentials plan (included in the Complete plan)
  • Backup for servers

What we won't tell you

No one can promise you will never be attacked, and we won't either. What we can do is put the controls in place, keep them working, and show you in writing where you stand.

Find out where you stand

Ask for a security check, or call us. We reply during business hours.