Every Silver Reef plan ships with a working security baseline: the controls that stop most real-world attacks, deployed and monitored — not a product catalog, not a scare pitch. And when the questionnaire lands on your desk, you forward it to us.
| Control | What it actually is | What it stops |
|---|---|---|
| Multi-factor authentication (MFA) | A second proof of identity at sign-in | A stolen password becoming a stolen account |
| Managed endpoint protection | Antivirus's modern successor — watches for behavior, monitored by humans | Ransomware detonating quietly on a Tuesday night |
| Patch management | Software updates applied on a schedule, verified | Attacks on holes that were fixed months ago |
| Email security | Filtering plus impersonation protection | The fake-invoice wire transfer; the "CEO" gift-card text's email cousin |
| Tested backups | Copies that can't be encrypted or deleted, restore-tested on schedule | Paying a ransom to get your own files back |
| Security awareness training | Short, regular, non-condescending | The click that starts almost every incident |
| Access control | People can reach what their job needs — nothing more | One compromised login owning the whole company |
None of this is exotic. It's the standard of care — the security equivalent of locking the yard gate. What's rare is having it actually deployed, monitored, and documented. That part is our job: the core controls ship with every plan, and the full stack — 24/7-monitored detection and response, advanced email security, training with phishing simulations, an annual risk assessment — is our Secure plan, at a price published on the website, not a mystery quote.
Some businesses need more than the baseline: you hold patient or client records, you're a supplier to defense or aerospace primes, you process serious payment volume, or your insurer wants continuous monitoring in writing. That's the Secure plan — $185 per user per month, published — plus scoped programs on top.
We complete insurance and customer security questionnaires for our clients — accurately, because we run the controls we're attesting to. That matters more than it sounds: a wrong answer on an insurance attestation is a denied claim waiting to happen. Ours come with evidence attached.
Attackers don't pick you; their software does. Phishing and password-stuffing are automated and indiscriminate — most small-business incidents start with an email anyone could have received. The size that matters isn't your headcount; it's your wire-transfer limit.
For about a week, mildly — if it's rolled out carelessly, longer. We stage rollouts, we train in plain English, and we've yet to meet the annoyance that costs more than one wire-fraud incident.
Insurance is the thing that pays some costs after. It doesn't restore your data, your customer's trust, or the week you lose — and increasingly it doesn't pay at all if the questionnaire answers weren't true. The controls are the plan; insurance is the backstop.
HIPAA: yes — dental and medical practices are our home turf. Risk analysis, policies, BAAs, and the controls behind them, built into how your systems actually run rather than sold as a seal on a website. CMMC: if you supply defense or aerospace primes, flow-down requirements are coming to you, and we'll get you honestly ready.
A free, written security baseline review. No fear-mongering, no product catalog — just what's open, what it means, and what closing it costs.
Prefer to talk first? Call (435) 525-2998 — an engineer answers.
Prefer email? jeff@silverreefsystems.org