Family owned in San Diego, CA · Since 2004
Ocean Computers

Crew Guard

Security that an insurer will accept

Layered defense across identity, endpoint and email, deployed and configured rather than installed and forgotten. Documented to the standard your auditor or cyber insurance underwriter will actually ask for.

Remote Delivered nationwide US-Based Technicians only Flat Monthly pricing Named Crew assigned

Crew Guard

Most breaches are ordinary, which is good news

The controls that stop the common attacks are well understood. The problem is almost never knowledge. It is that nobody has been made responsible for deploying them.

Small businesses are not targeted less than large ones. They are targeted more, because the attacks are automated and the defenses are usually thinner. The typical incident we are called about is not sophisticated. It is a credential harvested through a convincing email, used on an account without multi-factor authentication, followed by weeks of quiet mailbox access before anyone notices the forwarding rule.

The defenses against that are well understood and largely unglamorous. Multi-factor authentication everywhere. Endpoint detection that actually reports somewhere staffed. Email filtering and authentication records configured correctly. Backups that have been restored from. Staff who have seen a phishing simulation recently enough to hesitate. None of this is exotic, and most environments we assess are missing at least three of them.

Identity is the perimeter now

With business software living in the cloud, the meaningful boundary is no longer your firewall. It is who can authenticate as whom. We harden Microsoft Entra ID with enforced multi-factor authentication, conditional access rules that account for location and device state, and a review of the standing privileges that accumulate quietly in every tenant. Most environments we inherit have several accounts with administrative rights that nobody can justify.

Endpoint and email

Modern endpoint detection and response replaces signature-based antivirus, watching for behavior rather than matching known files, and it reports to somewhere a person actually looks. On the email side we configure filtering, plus the SPF, DKIM and DMARC records that determine whether someone can trivially send mail that appears to originate from your domain. That last one is missing or misconfigured in a striking number of the environments we assess.

Documentation, because it will be requested

Cyber insurance applications now ask specific technical questions, and answering them inaccurately can void a claim at the worst possible moment. We document what is deployed, when it was implemented, and how it is configured, in language an underwriter or auditor can use. For regulated businesses we map that documentation to the technical safeguards behind HIPAA, PCI or CMMC.

What we do not do is certify you compliant. No IT provider legitimately can. We implement and evidence the technical controls; certification is an auditor's function, and any provider blurring that distinction is telling you something about how they handle other boundaries.

Scope

What is included

Everything below is part of the service rather than an upsell discovered later.

Multi-factor authentication everywhere

Enforced across Microsoft 365, VPN and any system that supports it, with conditional access rules rather than a blanket policy.

Endpoint detection and response

Behavior-based protection that reports to somewhere staffed, replacing signature antivirus that only catches what is already known.

Email security and authentication

Filtering plus correctly configured SPF, DKIM and DMARC so your domain cannot be trivially impersonated.

Phishing simulation and training

Short, regular, non-punitive exercises. The goal is a workforce that hesitates, not one that resents the exercise.

Privilege and access review

A recurring audit of who can do what. Standing administrative rights accumulate quietly in every environment we inherit.

Documented safeguards

Written evidence of what is deployed and when, mapped to HIPAA, PCI or CMMC technical requirements where relevant.

Common questions

We are small. Are we really a target?

You are targeted by automation that does not check your revenue first. Credential-stuffing and phishing campaigns are indiscriminate by design. In practice smaller businesses are compromised more often because the controls are thinner, not because anyone chose them specifically.

Will MFA slow our staff down?

Slightly, and considerably less than people expect once conditional access is configured properly. A trusted device on a known network can be exempted from repeated prompts while an unrecognized login from elsewhere is challenged. The friction lands where the risk is.

Can you help with our cyber insurance application?

Yes. We answer the technical questions accurately and document the evidence behind each answer. This matters more than it sounds, because an inaccurate application can void a claim at the moment you need it.

What happens if we are breached?

Crew Guard includes an incident response runbook prepared in advance: who is contacted, what is isolated, how communication is handled, what is preserved for investigators. Writing that during an incident is how small incidents become large ones.

Talk to Us

Talk to a technician, not a salesperson

Describe what is happening. We will tell you whether it is a quick fix, a project, or a sign of something larger.

(858) 429-1311

Family owned in San Diego, California since 2004 · remote support in all 50 states · US-based technicians · never outsourced

Same-day response No long contracts Flat monthly pricing Free assessment

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in San Diego. We only use your details to help with your request. Never sold, never shared.