Straight answers to fair questions.
These are the questions careful owners ask before handing anyone the keys to their infrastructure. They deserve real answers, in writing, before a contract ever appears.
Is this only about security and backups?
No, though they get the most ink because they're where a bad month hurts worst. The retainer covers the whole layer your business stands on: the domain and directory that sign everyone in each morning, DNS and DHCP, file shares and their permissions, storage capacity, the hypervisors underneath, and the certificates that always seem to expire on a Friday. If it lives in the server room or the rack in the closet, keeping it healthy is my job.
Can you guarantee we won't get hacked?
No, and nobody honest can. Even companies spending millions a year on security get breached. What I do is make a breach as hard and as unrewarding as possible: a small attack surface, defenses tuned against real attack traffic, and backups proven by actually restoring them. If the worst day comes anyway, your business comes back from a verified backup in hours, not from a ransom negotiation. The monthly report is your standing proof that all of it keeps working.
Will this help with our cyber liability insurance?
Almost certainly, though not the way people expect. Carriers rarely discount premiums for good controls anymore; they require them. Applications now demand proof of tested backups, patch schedules, and perimeter defenses, and a claim can be denied when the answers on the application turn out to be wrong. I provide the documentation and logging your broker needs, and the monthly reports become a running record that the controls you attested to actually exist and actually run.
What happens if you're unavailable?
Maintenance is scheduled around availability, so the routine work never depends on catching me on a random Tuesday. More importantly, you always hold your own keys: every account is in your name, and you keep a living runbook and environment map that any competent engineer could pick up. You are never locked out of your own network, and you lose nothing if I vanish tomorrow. Few IT providers can honestly say that.
Why don't you do helpdesk or break-fix?
Because my focus has to stay entirely on the layer that can put you out of business: servers, backups, and the network perimeter. Traditional IT shops miss critical server alerts because their techs are buried in password resets and printer jams. Saying no to helpdesk is how I make sure your firewall audit never gets bumped for somebody's slow laptop.
Do we have to replace our current IT person or shop?
No, and you usually shouldn't. They keep the day-to-day: users, workstations, the printer only they understand. I take the layer underneath, the one that needs senior attention and rarely gets it. They gain a deep bench to call on, you get senior infrastructure care without a full-time senior salary, and nobody's job is threatened.
Do you resell software, hardware, or cloud services?
No. I'm an engineer, not a reseller. Anything your environment needs is bought in your name, on your card, at the vendor's price. No markup, no commission, no bundle. That means no conflict of interest behind any recommendation I make, and nothing you lose access to if we ever part ways.
Who plugs in hardware?
Someone on your side, with my support and instruction. The setups are designed so the physical part is genuinely simple: slot the drive, plug in the box, connect two cables, setup initial access (if required). I walk your contact through it step by step in writing and do everything else remotely. If you'd rather nobody on your team ever touch equipment, I can arrange a vetted local technician for a flat coordination fee.
Why is there no phone number?
Written communication is a feature, not a cost saving. Every request, answer, and promise ends up documented, which protects both of us and builds the paper trail your auditors and insurers love. Every inquiry gets a considered, written reply, usually within two business days.
What if we cancel?
You keep everything. The accounts were always yours, and so are the documentation, the runbook, the environment map, and every report I ever sent you. Offboarding is a clean handshake, not a hostage negotiation. I will even provide the exact VPN and firewall rules to close. The service is built this way on purpose: a vendor you can leave easily is a vendor you can trust.