Cyber Security
Attackers keep coming through the same three doors: a stolen password, a convincing email, an unpatched machine nobody was watching. NetSys closes those paths and watches everything else, 24/7 monitoring, endpoint detection and response, immutable backups, and training that changes what your staff clicks. Every NetSys client hit by ransomware has fully recovered. Engineers work on-site from our Brooklyn office across New York City, Westchester, the Hudson Valley, and Fairfield County.
The short answer
Managed cybersecurity is a layered defense that somebody runs for you every day: 24/7 monitoring of your systems and logs, endpoint detection and response on every device, multi-factor authentication and email threat protection, offline and immutable backups with tested restores, and security awareness training for your staff. NetSys has been defending business networks since 1998, and delivers today's version of that stack from our Brooklyn headquarters, with engineers on-site across New York City, Westchester County, the lower Hudson Valley, New Jersey, Connecticut, and Pennsylvania. Every NetSys client hit by ransomware has fully recovered — a 100% record — and every agreement runs month to month.
NetSys has been defending business networks from the Brooklyn office at 1 Prospect Park SW since 1998, and most of that work is now identity work. Microsoft Defender for Endpoint runs on every workstation and server with its policies pushed from Intune. Entra ID Conditional Access decides which sign-ins are allowed and blocks the legacy authentication paths a default Microsoft 365 tenant leaves open. Purview data loss prevention watches the files that would hurt to lose. Privileged access is handled through PAM and PIM, so nobody carries standing administrator rights for something they need twice a year. Backups are offline and immutable, and we restore from them on a scheduled date and record what came back and how long it took.
Most engagements start with the free Tier 1 external penetration test: your website, the systems you have exposed to the internet, what public records hand an attacker about your staff, and how likely a phishing email is to get a click. The report is yours whether or not you hire us. Tier 2, which reads your source code inside an isolated sandbox, is quoted separately. Joel Baum leads the security and compliance side of the practice, every client gets a named account manager with a real cell number, and agreements run month to month, so the work has to be worth renewing every month.
A Comprehensive, Proactive Approach to Security
Attackers rarely break anything. They log in. The paths we see against small businesses in New York are business email compromise after a mailbox is taken over, OAuth consent phishing where a user approves a malicious app against their own Microsoft 365 tenant, Direct Send abuse that lets an outsider drop mail into your domain without authenticating, callback phishing that carries a phone number instead of a link so the mail filter has nothing to score, MFA fatigue push spam, and unpatched edge devices such as SonicWall VPN firmware. Each one has a specific control behind it: Conditional Access policies in Entra ID, app consent policies with admin review of third-party apps, Direct Send turned off so submission has to be authenticated, Defender for Office 365 plus training on the phone-number pattern, number matching on approvals, and a firewall and VPN patch cadence that is tracked rather than assumed. Monitoring runs 24/7 behind all of it, and offline immutable backups with dated restore tests sit behind that.
Our Cybersecurity Services
Network Security
A firewall is only as current as its last firmware update, which is how unpatched SonicWall VPN appliances turned into a ransomware entry point for businesses that thought the edge was handled. We keep edge devices on a tracked patch schedule, segment the flat networks that let one infected laptop reach the file server, and put remote access behind Entra ID Conditional Access rather than a shared VPN password.
- Next-generation firewall deployment and management
- Secure VPN and remote access configurations
- Network segmentation and traffic control
- Secure Wi-Fi implementation and authentication
- Regular firmware and security updates
Endpoint & Server Protection
The endpoint is where a phishing click stops being an email and becomes a foothold. Every workstation and server runs Microsoft Defender for Endpoint with its policies and compliance rules pushed from Intune, patching follows a schedule we track instead of a reminder the user dismisses, and local administrator rights come off the day-to-day account so malware inherits a limited user instead of the whole machine.
- Managed antivirus and advanced endpoint detection & response (EDR)
- Patch and update management
- Application control and device restrictions
- System hardening for servers and critical infrastructure
24/7 Monitoring & Threat Response
Monitoring runs around the clock against signals that mean something: a Defender for Endpoint alert on a machine, an Entra ID sign-in from a country your staff does not work in or over legacy authentication, a new inbox rule quietly forwarding mail outside the company, an OAuth app consent nobody asked for. When one trips we isolate the device and kill the session rather than sending you an email about it, and your named account manager gives you a cell number that works at 2am.
- Continuous system and security log monitoring
- Real-time alerts for suspicious activity
- Incident investigation and triage
- Rapid response and remediation recommendations
Cloud Security & Secure Remote Work
A default Microsoft 365 tenant is not a secured one. Hardening it means Conditional Access in Entra ID that blocks legacy authentication and unmanaged devices, Intune compliance policies on the laptops that reach SharePoint and OneDrive, Purview data loss prevention so a client file cannot walk out through a personal account, and a review of which third-party apps your users have already consented to inside the tenant.
- Secure configuration of cloud services
- Identity and access management (MFA, role-based access)
- Hardened remote access solutions (VPN, Zero-Trust principles)
- Protection for remote devices and home networks
Ransomware Defense & Data Protection
NetSys has worked more than 30 ransomware incidents in the last three years and recovered every one. The clients who had a disaster recovery plan already written and tested were running again inside 24 hours. Without one, the same decisions get made during the incident instead of before it, and that is where the days go. The defense that matters here is a backup you have proven: offline and immutable copies, restores run on a scheduled date, and the restore time written down so nobody is estimating it while the office is down.
- Anti-phishing and email threat protection
- Behavioral ransomware detection
- Industry-standard backup and disaster recovery solutions
- Offline and immutable backup options
- Tested recovery procedures
Security Policies, Compliance & Employee Training
Training is about what is being sent to your staff this month: callback phishing that asks them to call a number about a renewal they never bought, an OAuth consent screen dressed as a Microsoft sign-in, a wire-change request from a mailbox that really does belong to your CFO. Policy work follows the rule you are graded on, whether that is HIPAA for a medical practice, the FTC Safeguards Rule for a firm holding consumer financial data, NYDFS 23 NYCRR 500 for a licensed New York business, or CMMC 2.0 for a defense supplier. Karla Gilvergara leads the AI tools and AI fraud awareness training.
- Creation and refinement of security policies
- Compliance guidance based on your industry
- Employee cybersecurity awareness training
- Best practices for safe remote work and data handling
How a Security Engagement Starts
No two environments are the same, so we look before we prescribe.
- Free external penetration test: your real exposure shown, not described
- Review of identity, email, endpoints, network, and backups as they exist today
- A prioritized fix list separating quick wins from projects that need budget
- A written split of what we run and what stays with your team
- Month-to-month terms — nothing long-term to sign before you see the work
Where We Defend Businesses
Monitoring runs remotely around the clock; engineers come to you across our on-site regions.
- Headquarters: 1 Prospect Park SW, Suite 6E, Brooklyn, NY 11215
- On-site: New York City, Westchester County, and the lower Hudson Valley
- On-site: New Jersey, Connecticut, and Pennsylvania
- On-site: Southwest Florida and Palo Alto, California
- 24/7 remote monitoring and response wherever your systems run
Why Businesses Choose The NetSys Group
Fifteen minutes with a NetSys engineer, not a salesperson, and you will know where your cyber security stands and what it would take to fix it. Call 845-203-3914 or book the call and we will come back with it in writing.
- One month-to-month agreement covers the whole stack: managed help desk, cybersecurity, PAM, PIM, disaster recovery planning, and AI adoption. Security is not a higher tier you get upsold into later.
- Named controls, deployed by default: Microsoft Defender for Endpoint on every workstation and server, Entra ID Conditional Access on every sign-in, Purview data loss prevention on the files that matter, and offline immutable backups with restores tested on a date we can show you.
- Joel Baum leads the security and compliance practice and Latoya Reed handles the Microsoft 365 and Entra ID work. Every client also gets a named account manager who hands over a real cell number for escalation.
- Controls mapped to whichever rule you are audited against: HIPAA, PCI DSS, SOC 2, CMMC 2.0, NIST CSF, NYDFS 23 NYCRR 500, the NY SHIELD Act, the FTC Safeguards Rule, GLBA, or SEC Reg S-P.
- Email and identity get the attention the attacks do: Defender for Office 365 in front of the mailbox, Microsoft 365 Direct Send switched off, an alert on any new rule that forwards mail outside the company, and admin review before a user can consent to a third-party app in your tenant.
- Privileged access is treated as its own job: PAM to strip standing local administrator rights, PIM so an Entra ID admin role is granted for a set window and then taken back, and a documented break-glass account that gets tested rather than assumed.
- A 100% ransomware recovery record — every NetSys client hit has fully recovered
- 98% client retention across 28+ years in business
- Engineers on-site across NYC, Westchester, the Hudson Valley, New Jersey, Connecticut, and Pennsylvania
- Month to month, like every NetSys agreement — no long-term contract
- See the work before you buy it: the external penetration test is free and the findings are yours to keep
When something is wrong, this is the clock
Security incidents are response-time problems. The same written commitments that cover our managed IT clients apply when the call is a security call:
| Severity | Phone response | Remote response | On-site response |
|---|---|---|---|
| Critical — you're down, or actively at risk | 10 minutes | 30 minutes | As fast as 1 hour, per agreement |
| Standard — something's broken, work continues | 30 minutes | 1 hour | Up to 6 hours, per agreement |
On-site times depend on where you are and the on-site tier written into your agreement — we put the numbers in writing instead of implying them. And there is no ticket queue in front of any of this: you call, a NetSys engineer answers.
Where we deliver Cyber Security
Cyber Security in Brooklyn, NY · Cyber Security in Stamford, CT · Cyber Security in Greenwich, CT · Cyber Security in White Plains, NY · Cyber Security in Palo Alto, CA · Cyber Security in Tampa Bay · Cyber Security in Westport, CT — and remotely wherever your systems run. See all locations and service areas.
Cyber Security FAQs
How fast do you respond to a security incident?
Immediately — our team monitors around the clock and isolates affected devices in real time. Every client also has their dedicated account manager's cell number for direct escalation, day or night.
What happens if we're hit with ransomware?
Every NetSys client hit by ransomware has fully recovered — a 100% record. We restore from offline, immutable backups using recovery procedures we test on a schedule, then close the entry point that let the attack in.
Do you work with our existing IT staff?
Yes. We can act as your complete security team or layer 24/7 monitoring, endpoint detection, and incident response on top of your internal IT — whichever split fits your organization.
Is the external penetration test really free?
Yes. A NetSys engineer visits your office, safely demonstrates how an attacker would get in, and hands you a prioritized fix list. You keep the findings whether or not you hire us.
Do you provide cybersecurity services in New York City?
Yes. Our office is at 1 Prospect Park SW in Brooklyn, so on-site work across the five boroughs is routine scheduling rather than a special trip. Monitoring and response run 24/7 remotely; engineers come to you for remediation and network work, and the free external penetration test runs remotely before you hire us.
Do you cover Westchester County and Fairfield County, Connecticut?
Yes. Both sit inside our on-site coverage area, which runs from the Brooklyn office up through Westchester and the lower Hudson Valley and east into Connecticut, plus New Jersey and Pennsylvania. Our main line, 845-203-3914, is a Hudson Valley number. To be plain about it: we have one office, in Brooklyn. Everywhere else is coverage territory we actually drive — we don't claim satellites we don't have.
What's the difference between managed IT and managed cybersecurity?
Managed IT keeps things working — helpdesk, patching, hardware, email, backups. Managed cybersecurity keeps things defended — 24/7 monitoring, endpoint detection and response, identity and access controls, email threat protection, and incident response. We build security into every managed IT agreement rather than selling it back to you as an upgrade. You can also buy the security layer on its own if another provider handles your day-to-day IT.
We're on Microsoft 365 and it has security built in. Isn't that enough?
It's a start, not a program. A default tenant leaves legacy authentication paths open, gives most staff more access than their job needs, and retains deleted data only for a window. We harden the tenant, enforce multi-factor authentication and conditional access, layer email threat protection and endpoint detection on top, and keep an independent backup — because Microsoft's retention protects against Microsoft's failures, not yours.
What should we do first if we think we've already been breached?
Call 845-203-3914 and stop using the affected accounts. Don't delete anything, don't wipe the machine, and don't pay anyone. We isolate affected devices, establish how the attacker got in and what they could reach, restore from offline immutable backups using recovery procedures we test on a schedule, and close the entry point before anything comes back online. Every NetSys client hit by ransomware has fully recovered.
Guides on this topic
- Case Study: 7-BTC Ransomware Demand, 4.5-Hour Recovery, $0 Paid
- Stamford cybersecurity — our dedicated Stamford, CT page
- Monthly Cyber Threat Report — What's Hitting Small Businesses Right Now
- Callback Phishing: The Scam That Skips Your Email Filter
- Passkeys vs MFA: Logins Phishing Can't Beat
- Small Business Cybersecurity: The Controls That Actually Stop Attacks
- MDR vs. Antivirus: What Small Businesses Need in 2026
- The 2026 SMB Cybersecurity Checklist
- Free External Penetration Test
- IT & Cybersecurity in Brooklyn & New York City
- IT & Cybersecurity in Westchester County
- IT & Cybersecurity in Greenwich, Stamford & Fairfield County
- Security Assessment Services — Where Do We Actually Stand?
- Privileged Access Management — Locking Down the Admin Accounts
Related services
Security inside the agreement, not a tier above it.
Most engagements open with the free Tier 1 external test, run remotely against what your business shows the internet. The findings are yours whether or not you hire us. What follows is mostly identity work: the legacy sign-in paths a default Microsoft 365 tenant leaves open, and who still holds standing admin rights.
