HomeServicesCyber Security

Managed Cybersecurity Services

Attackers keep coming through the same three doors: a stolen password, a convincing email, an unpatched machine nobody was watching. NetSys closes those paths and watches everything else, 24/7 monitoring, endpoint detection and response, immutable backups, and training that changes what your staff clicks. Every NetSys client hit by ransomware has fully recovered. Engineers work on-site from our Brooklyn office across New York City, Westchester, the Hudson Valley, and Fairfield County.

Review Assessment Options

The short answer

Managed cybersecurity services put an outside team in charge of your security every day: endpoint detection and response, 24/7 monitoring, email and identity protection, patching, tested backups and staff training. NetSys runs that stack from its Brooklyn office, alongside your IT or inside a managed IT agreement, month to month. Every NetSys client hit by ransomware has fully recovered.

Cybersecurity support matched to your business risks

NetSys has been defending business networks from the Brooklyn office at 1 Prospect Park SW since 1998, and most of that work is now identity work. Microsoft Defender for Endpoint runs on every workstation and server with its policies pushed from Intune. Entra ID Conditional Access decides which sign-ins are allowed and blocks the legacy authentication paths a default Microsoft 365 tenant leaves open. Purview data loss prevention watches the files that would hurt to lose. Privileged access is handled through PAM and PIM, so nobody carries standing administrator rights for something they need twice a year. Backups are offline and immutable, and we restore from them on a scheduled date and record what came back and how long it took.

The free assessment is a remote external penetration test, limited to the information available to NetSys and the external scope we agree with you. The report is yours whether or not you hire us. Tier 2, which reads your source code inside an isolated sandbox, is quoted separately. Joel Baum leads the security and compliance side of the practice, every client gets a named account manager with a real cell number, and agreements run month to month.

A Comprehensive, Proactive Approach to Security

Attackers rarely break anything. They log in. The paths we see against small businesses in New York are business email compromise after a mailbox is taken over, OAuth consent phishing where a user approves a malicious app against their own Microsoft 365 tenant, Direct Send abuse that lets an outsider drop mail into your domain without authenticating, callback phishing that carries a phone number instead of a link so the mail filter has nothing to score, MFA fatigue push spam, and unpatched edge devices such as SonicWall VPN firmware. Each one has a specific control behind it: Conditional Access policies in Entra ID, app consent policies with admin review of third-party apps, Direct Send turned off so submission has to be authenticated, Defender for Office 365 plus training on the phone-number pattern, number matching on approvals, and a firewall and VPN patch cadence that is tracked rather than assumed. Monitoring runs 24/7 behind all of it, and offline immutable backups with dated restore tests sit behind that.

Our Cybersecurity Services

Network Security

A firewall is only as current as its last firmware update, which is how unpatched SonicWall VPN appliances turned into a ransomware entry point for businesses that thought the edge was handled. We keep edge devices on a tracked patch schedule, segment the flat networks that let one infected laptop reach the file server, and put remote access behind Entra ID Conditional Access rather than a shared VPN password.

  • Next-generation firewall deployment and management
  • Secure VPN and remote access configurations
  • Network segmentation and traffic control
  • Secure Wi-Fi implementation and authentication
  • Regular firmware and security updates

Endpoint & Server Protection

The endpoint is where a phishing click stops being an email and becomes a foothold. Every workstation and server runs Microsoft Defender for Endpoint with its policies and compliance rules pushed from Intune, patching follows a schedule we track instead of a reminder the user dismisses, and local administrator rights come off the day-to-day account so malware inherits a limited user instead of the whole machine.

  • Managed antivirus and advanced endpoint detection & response (EDR)
  • Patch and update management
  • Application control and device restrictions
  • System hardening for servers and critical infrastructure

24/7 Monitoring & Threat Response

Monitoring runs around the clock against signals that mean something: a Defender for Endpoint alert on a machine, an Entra ID sign-in from a country your staff does not work in or over legacy authentication, a new inbox rule quietly forwarding mail outside the company, an OAuth app consent nobody asked for. When one trips we isolate the device and kill the session rather than sending you an email about it, and your named account manager gives you a cell number that works at 2am.

  • Continuous system and security log monitoring
  • Real-time alerts for suspicious activity
  • Incident investigation and triage
  • Rapid response and remediation recommendations

Cloud Security & Secure Remote Work

A default Microsoft 365 tenant is not a secured one. Hardening it means Conditional Access in Entra ID that blocks legacy authentication and unmanaged devices, Intune compliance policies on the laptops that reach SharePoint and OneDrive, Purview data loss prevention so a client file cannot walk out through a personal account, and a review of which third-party apps your users have already consented to inside the tenant.

  • Secure configuration of cloud services
  • Identity and access management (MFA, role-based access)
  • Hardened remote access solutions (VPN, Zero-Trust principles)
  • Protection for remote devices and home networks

Ransomware Defense & Data Protection

NetSys has worked more than 30 ransomware incidents in the last three years and recovered every one. The clients who had a disaster recovery plan already written and tested were running again inside 24 hours. Without one, the same decisions get made during the incident instead of before it, and that is where the days go. The defense that matters here is a backup you have proven: offline and immutable copies, restores run on a scheduled date, and the restore time written down so nobody is estimating it while the office is down.

  • Anti-phishing and email threat protection
  • Behavioral ransomware detection
  • Industry-standard backup and disaster recovery solutions
  • Offline and immutable backup options
  • Tested recovery procedures

Security Policies, Compliance & Employee Training

Training is about what is being sent to your staff this month: callback phishing that asks them to call a number about a renewal they never bought, an OAuth consent screen dressed as a Microsoft sign-in, a wire-change request from a mailbox that really does belong to your CFO. Policy work follows the rule you are graded on, whether that is HIPAA for a medical practice, the FTC Safeguards Rule for a firm holding consumer financial data, NYDFS 23 NYCRR 500 for a licensed New York business, or CMMC 2.0 for a defense supplier. Karla Gilvergara leads the AI tools and AI fraud awareness training.

  • Creation and refinement of security policies
  • Compliance guidance based on your industry
  • Employee cybersecurity awareness training
  • Best practices for safe remote work and data handling

How a Security Engagement Starts

No two environments are the same, so we look before we prescribe.

  • Free remote external test with available-information and scope limitations stated
  • Review of identity, email, endpoints, network, and backups as they exist today
  • A prioritized fix list separating quick wins from projects that need budget
  • A written split of what we run and what stays with your team
  • Month-to-month terms — nothing long-term to sign before you see the work

Where We Defend Businesses

Monitoring runs remotely around the clock; engineers come to you across our on-site regions.

  • Headquarters: 1 Prospect Park SW, Suite 6E, Brooklyn, NY 11215
  • On-site: New York City, Long Island and Westchester County
  • On-site: the Hudson Valley, North Jersey and Fairfield County, CT
  • Remote-first everywhere else: visits arranged in advance and scoped in the proposal
  • 24/7 remote monitoring and response wherever your systems run
Why NetSys

Why Businesses Choose The NetSys Group

Fifteen minutes with a NetSys engineer, not a salesperson, and you will know where your cyber security stands and what it would take to fix it. Call 845-203-3914 or request a call to discuss the scope and next steps.

  • One month-to-month agreement covers the whole stack: managed help desk, cybersecurity, PAM, PIM, disaster recovery planning, and AI adoption. Security is not a higher tier you get upsold into later.
  • Named controls, deployed by default: Microsoft Defender for Endpoint on every workstation and server, Entra ID Conditional Access on every sign-in, Purview data loss prevention on the files that matter, and offline immutable backups with restores tested on a date we can show you.
  • Joel Baum leads the security and compliance practice and Latoya Reed handles the Microsoft 365 and Entra ID work. Every client also gets a named account manager who hands over a real cell number for escalation.
  • Controls mapped to whichever rule you are audited against: HIPAA, PCI DSS, SOC 2, CMMC 2.0, NIST CSF, NYDFS 23 NYCRR 500, the NY SHIELD Act, the FTC Safeguards Rule, GLBA, or SEC Reg S-P.
  • Email and identity get the attention the attacks do: Defender for Office 365 in front of the mailbox, Microsoft 365 Direct Send switched off, an alert on any new rule that forwards mail outside the company, and admin review before a user can consent to a third-party app in your tenant.
  • Privileged access is treated as its own job: PAM to strip standing local administrator rights, PIM so an Entra ID admin role is granted for a set window and then taken back, and a documented break-glass account that gets tested rather than assumed.
  • A 100% ransomware recovery record — every NetSys client hit has fully recovered
  • 98% client retention across 28+ years in business
  • Engineers on-site across NYC, Long Island, Westchester, the Hudson Valley, North Jersey and Fairfield County, CT
  • Month to month, like every NetSys agreement — no long-term contract
  • See the work before you buy it: the external penetration test is free and the findings are yours to keep
From our client work

Cyber Security in practice

Client names are withheld. Each card is the scope of a real NetSys engagement, as delivered.

When something is wrong, this is the clock

Security incidents are response-time problems. The same written commitments that cover our managed IT clients apply when the call is a security call:

SeverityPhone responseRemote responseOn-site response
Critical — you're down, or actively at risk10 minutes30 minutesAs fast as 1 hour, per agreement
Standard — something's broken, work continues30 minutes1 hourUp to 6 hours, per agreement

On-site times depend on where you are and the on-site tier written into your agreement — we put the numbers in writing instead of implying them. And there is no ticket queue in front of any of this: you call, a NetSys engineer answers. The help desk is staffed seven days a week from 4 a.m. to 11 p.m. Eastern time, and emergency service is available 24/7.

The managed security stack, layer by layer

What runs in a NetSys security agreement, and the attack each layer is there to stop:

LayerWhat we runWhat it stops
Endpoint detection (EDR)ThreatDown EDR or Microsoft Defender on every covered workstation and serverMalware and ransomware that antivirus alone misses
Managed detection and response (MDR)NetSys engineers triage each Defender alert and can isolate a compromised machineAn alert nobody reads until Monday
SOC monitoringSign-in, email, firewall and server logs collected and correlated, scoped per businessAn attack that shows only across several systems at once
Email securityDefender for Office 365, Direct Send switched off, and alerts on rules forwarding mail outside the companyPhishing, spoofed internal mail and a quietly hijacked mailbox
IdentityMFA and Conditional Access on every sign-in, with PAM and PIM for admin rightsA stolen password turning into admin control
Backup and recoveryOffline, immutable backups restored on a dated scheduleRansomware becoming a permanent loss
Security awareness trainingMonthly phishing simulations, with a short lesson for anyone who clicksThe lure that gets past every filter

Response commitments for security calls are the severity table on this page. SOC log monitoring is scoped separately from endpoint MDR.

Cyber Security by market

NYC Metro: New York City · Brooklyn, NY · Manhattan

Long Island: Nassau County, NY · Suffolk County, NY · Long Island

Hudson Valley: Westchester County, NY

Connecticut: Stamford, CT · Connecticut

New Jersey: New Jersey

Pennsylvania: Philadelphia

New England: Boston · Massachusetts

National metro: Palo Alto · Chicago · Houston · Atlanta · Los Angeles · Dallas · Charlotte · Denver · San Diego · Austin · San Antonio

Florida (other): Tampa · Florida

Mid-Atlantic: Maryland · Virginia

Statewide: California

Common Questions

Cyber Security FAQs

How fast do you respond to a security incident?

Monitoring runs around the clock. Response depends on the incident, the affected systems and the authority agreed in your service scope. Before onboarding, establish who can isolate a device, disable an account and approve recovery, plus the escalation contacts for an after-hours incident. Your named account manager provides a direct escalation route.

What happens if we're hit with ransomware?

Every NetSys client hit by ransomware has fully recovered — a 100% record. We restore from offline, immutable backups using recovery procedures we test on a schedule, then close the entry point that let the attack in.

Do you work with our existing IT staff?

Yes. We can act as your complete security team or layer 24/7 monitoring, endpoint detection, and incident response on top of your internal IT — whichever split fits your organization.

Is the external penetration test really free?

Yes. The free assessment is a remote external penetration test, limited to the information available to NetSys and the external scope we agree with you. Internal reviews, onsite work and any broader assessment are scoped separately.

Do you provide cybersecurity services in New York City?

Yes. Our office is at 1 Prospect Park SW in Brooklyn, so on-site work across the five boroughs is routine scheduling rather than a special trip. Monitoring and response run 24/7 remotely; engineers come to you for remediation and network work, and the free external penetration test runs remotely before you hire us.

Do you cover Westchester County and Fairfield County, Connecticut?

Yes. Both sit inside our on-site coverage, which is New York City, Long Island, Westchester, the Hudson Valley, North Jersey and Fairfield County, CT. Our main line, 845-203-3914, is a Hudson Valley number. To be plain about it: we have one office, in Brooklyn. The rest of that list is coverage territory we actually drive, and we don't claim satellites we don't have.

What's the difference between managed IT and managed cybersecurity?

Managed IT keeps things working — helpdesk, patching, hardware, email, backups. Managed cybersecurity keeps things defended — 24/7 monitoring, endpoint detection and response, identity and access controls, email threat protection, and incident response. We build security into every managed IT agreement rather than selling it back to you as an upgrade. You can also buy the security layer on its own if another provider handles your day-to-day IT.

We're on Microsoft 365 and it has security built in. Isn't that enough?

Microsoft 365 includes security capabilities, but their availability and protection depend on licensing, configuration and ongoing administration. We review MFA, sign-in policies, privileged access, email protection and device compliance against your actual tenant. Retention and recovery settings also need review: a written backup and restore plan should specify what is protected, for how long and who can restore it.

What should we do first if we think we've already been breached?

Call 845-203-3914 and stop using the affected accounts. Don't delete anything, don't wipe the machine, and don't pay anyone. We isolate affected devices, establish how the attacker got in and what they could reach, restore from offline immutable backups using recovery procedures we test on a schedule, and close the entry point before anything comes back online. Every NetSys client hit by ransomware has fully recovered.

What are cybersecurity services?

Cybersecurity services are the work of protecting a business's accounts, devices, email and data. They include assessments and penetration tests that find weaknesses, the controls and monitoring that close and watch them, and a plan for incidents. Managed cybersecurity runs those controls every day instead of handing over a one-time report.

Does NetSys provide managed security, or only IT support?

Both. NetSys is a managed IT and cybersecurity company, and its managed security runs under the same month-to-month agreement: ThreatDown MDR, Microsoft Defender, email filtering, MFA and Conditional Access, and backups with tested restores. The 24/7 security operations center (SOC) is part of the ThreatDown MDR service. Log-based SOC monitoring across sign-ins, firewalls and servers is scoped separately, and businesses that keep their own IT provider can buy the security layer alone through our MSSP service.

What should a small business look for in a cybersecurity company?

A small business should look for a cybersecurity company that watches alerts around the clock and has agreed authority to isolate a compromised device. Then check, in writing: whether EDR, MFA, email filtering and backups are in the base price or sold as add-ons; dated restore-test results; a named contact with response commitments by severity; contract length and exit terms; and whether they will test your defenses before you sign, as our free external penetration test does.

How much do managed cybersecurity services cost?

It depends on how many layers you need, priced per user or per device each month. The number moves with headcount, compliance obligations, the licenses you already own (Microsoft 365 Business Premium includes Defender for Business) and whether we also run your IT. NetSys publishes no rate card; our cost guide cites published market ranges.

Keep Reading

Guides on this topic

Cybersecurity services

Agree what needs protecting and who owns the response.

Bring your current security tools, your main concern and any insurer or client deadline. We will use those to define the review, responsibilities and next steps before proposing ongoing coverage.

Review Assessment Options 845-203-3914