Skip to content
Person working on a computer at their desk

Small Business IT Services

The primary focus of ETS is helping small and midsize businesses level up their security and prove it.

We start with security and work backward. The focus is two things: a managed security program built on the CIS Critical Security Controls, the same framework security teams and cyber insurers use to define what “secure” actually means, and fractional security leadership to steer it. The bigger technology work that keeps a business moving (device lifecycle, migrations, network changes) is delivered as scoped, quoted project engagements driven by your roadmap, and it’s work we do exceptionally well.

The ETS Standard

Every ETS client is managed to CIS Implementation Group 1 plus the majority of Implementation Group 2, with hardened configuration baselines on every device and tenant. That’s not marketing language; it’s a published framework you can read, and it’s what the evidence in your quarterly review is measured against.

Why it matters: per the CIS Community Defense Model v2.0, implementing the IG1 safeguards defends against 77% of the ATT&CK (sub-)techniques used across the top five attack types: malware, ransomware, web application hacking, insider privilege misuse, and targeted intrusions. For ransomware specifically, that’s 78% at IG1, rising to 92% with full implementation. ETS clients operate between those bounds, and your scorecard shows exactly where.

What the evidence looks like: a quarterly conformance report and coverage scorecard, restore tests that actually run, access reviews that actually happen, and an exception register for anything deliberately out of scope. When your cyber insurance renewal asks hard questions, the answers already exist.

What a Partnership Includes

Managed Security. A flat per-user program covering the person and their device: 24/7 managed detection and response, default-deny application control on every endpoint, advanced email protection, security awareness training, identity threat detection, managed backup, secure network access, and continuous CIS baseline enforcement. Windows and Mac at parity. Servers, additional devices, and iPads covered as simple add-ons.

Fractional Security Leadership (vCISO / vCIO). A deliverable-defined advisory program: quarterly technology roadmap, annual budget forecast, a maintained risk scorecard, and a standing seat at your leadership table for security and IT strategy. Also available standalone for organizations with internal IT or another provider, which is the natural fit for midsize teams: your people run IT, ETS runs security and the evidence.

Assessments & Projects. Fixed-fee security and network assessments, data classification and DLP foundations, and the larger technology projects that keep a business moving: device lifecycle, migrations, and network changes, all scoped in writing before anything starts. Penetration testing available through a vetted partner.

Is This Your Business?

  • Agile team of between 15 to 300 people
  • Have internal IT? Co-managed is our natural mode: ETS runs the security layer and the evidence while your team keeps running IT
  • Windows or Mac environments; Microsoft 365 or Google Workspace (we’ll align your licensing so it carries real security weight)
  • In a regulated or trust-sensitive space or simply done gambling on your cybersecurity posture being “probably fine”
  • Growing, and ready for proactive, evidenced IT management instead of reactive fixes

“I recently hired Chad as an IT consultant for my small but growing business and I have to say I am extremely impressed with the level of service and expertise he has provided. Chad was able to quickly identify and resolve any issues we were having and secure the business as well as create an IT-positive culture. He consistently provides valuable insights and recommendations for improving our overall IT infrastructure. One of the things I appreciate most about working with Chad is his ability to clearly communicate technical information in a way that is easy for me to understand. Overall, I highly recommend Chad if you are looking to implement IT policies and procedures to secure your current business and as you scale.”

MICHAEL, CEO

 

THE PROCESS

Here’s what you can expect when you reach out:

1. Right-Fit Call

We want to learn about your business, what you do, and if we can help. You're interviewing us too, so we'll happily answer any questions you may have to make sure we're a good fit for each other.

2. Baseline Assessment

If we're a good fit, we measure. Users, applications, accounts, devices, network, and tenant configuration, all assessed against the CIS Controls. You get a baseline scorecard showing where you stand before we change anything.

3. Create Plan

Your plan is the gap between your baseline and the standard, in plain terms and priority order. Every recommendation traces to a specific CIS safeguard, so you can see the justification for each step and each dollar.

4. Get to Work!

Time to put the plan into action! This is where you start to get results, and see how partnering with ETS is a breath of fresh air.

Ready to level up your tech?

Contact Edstrand Technology Services to Get Started

(262) 228-8799