Managed IT & cybersecurity for professional firms
You run the firm.We watch your six.
CY6 keeps the technology behind law firms, accounting practices, clinics and professional offices secure, current and quietly out of the way — with people who answer the phone, and evidence you can hand to a client.
Two minutes, six questions, no email address required.
Position 1
Endpoints
Every laptop, desktop and server, monitored for failure and for attack.
The gap
Most firms are not careless. They are uncovered.
Nobody sets out to run a firm without cover. The business grew, the person who handled it left, and there was never an obvious moment to fix it.
- Now
Backups run. Nobody has restored one.
With CY6Restores are tested on a schedule, with a date you can quote.
- Now
IT is whoever is free, or whoever is least afraid of it.
With CY6One number, one team, and someone already watching before you call.
- Now
Security means antivirus, and hoping.
With CY6Layered controls, monitored around the clock, with a written plan for the bad day.
- Now
A client sends a security questionnaire and the office stops.
With CY6You send a current document the same afternoon.
- Now
Technology spending arrives as emergencies.
With CY6A three-year budget, reviewed quarterly, that you own.
We have deliberately not put a breach statistic on this page. You do not need frightening; you need covering.
Coverage / 01—06
Six services. One team. No stale tickets.
Same people, one agreement, one number to call. Take all six, or start with the ones you need most.
- 01
Managed IT and helpdesk
Someone to call, and someone already watching
Day-to-day support for your people plus continuous care for the machines they use. Your team gets a real human on a known number instead of asking whoever is nearest the server closet.
- Unlimited helpdesk for covered users, by phone, email or portal
- 24/7 remote monitoring with automated remediation for common faults
- Patching on a published schedule, tested before it reaches your machines
- Asset and warranty tracking so nothing quietly ages out
- Documented onboarding and offboarding for staff changes
- Vendor wrangling — we talk to your line-of-business software people
- 02
Cybersecurity and response
Layered protection, plus a plan for the day it matters
Modern detection and response across endpoints, identity and email, backed by people who investigate alerts instead of forwarding them to you. Prevention is most of the work; the rest is knowing exactly what to do at 6am on a Sunday.
- Managed endpoint detection and response on every covered device
- Identity protection: enforced multi-factor, conditional access, session review
- Email security tuned for impersonation and payment-redirection fraud
- Dark-web credential monitoring for your domains
- Written incident response plan, with named contacts and first-hour actions
- Security awareness training and simulated phishing on a light, non-punitive cadence
- 03
Backup and continuity
Backups that have actually been restored
Backup is not a product, it is a promise about time. We define how much work you can afford to lose and how long you can afford to be down, then build to those numbers and prove them by restoring on a schedule.
- Image-level backup of servers and covered workstations
- Separate backup of Microsoft 365 or Google Workspace data
- Off-site, immutable copies designed to survive ransomware
- Documented recovery targets: how much data, how much downtime
- Recovery testing with a timed result you can show an auditor or insurer
- Continuity plan covering loss of premises, internet or a key system
- 04
Cloud, email and identity
Microsoft 365 and Google Workspace, properly configured
Most firms buy a solid cloud platform and use a fraction of it, with default settings that were never meant to be final. We configure, secure and maintain the platform you already pay for.
- Tenant hardening against a published baseline, reviewed quarterly
- SPF, DKIM and DMARC set up so your mail is trusted and hard to spoof
- File structure and permissions that match how the firm actually works
- Single sign-on and password vaulting for the apps that support it
- Licence review — we tell you when you are over-buying
- Guest and external sharing controls appropriate to confidential work
- 05
Compliance-ready IT
Evidence, not just intentions
Regulated professions are increasingly asked to prove their controls, not describe them. We map what you run to the framework you answer to, close the gaps, and keep the evidence current so questionnaires stop being a fire drill.
- Gap assessment against HIPAA, the FTC Safeguards Rule, IRS Pub. 4557, PCI DSS or NIST CSF
- A written information security plan you can hand over
- Technical controls implemented to match the policy, not the other way round
- Access reviews, log retention and change records kept as evidence
- Annual risk assessment and remediation tracking
- Support answering client and insurer security questionnaires
- 06
Strategy and projects
A technology plan that fits the business plan
Quarterly time with someone who understands both your books and your network. Budgets, renewals, growth plans and the occasional office move, handled as projects with dates rather than emergencies with invoices.
- Quarterly business review, if you want one: what changed, what is ageing, what is next
- Three-year budget for hardware, licensing and lifecycle replacement
- Project delivery: office moves, server retirement, cloud migration, new sites
- Vendor selection and contract review for line-of-business software
- Growth modelling — what your setup costs at double the headcount
- A single roadmap document, kept current, that you own
Who we help
Firms where a bad computer day is a bad client day
We are most useful where confidentiality, deadlines and professional obligations meet a team too small to employ its own technology department.
Law firms
Confidentiality obligations that outlast any single matter
- ABA Model Rules 1.1 & 1.6
- Outside counsel guidelines
- Trust and escrow wire controls
- Practice management support
Accounting and CPA firms
A written security plan is no longer optional
- IRS Pub. 4557
- FTC Safeguards Rule
- Written information security plan
- Busy-season capacity planning
Medical and dental clinics
HIPAA controls without a hospital-sized budget
- HIPAA Security Rule
- Business associate agreement
- Clinical device segmentation
- Imaging and PACS support
Professional offices
For firms whose product is judgement and whose asset is trust
- NIST Cybersecurity Framework
- Client contract security terms
- Cyber insurance questionnaires
- Advisory firm evidence and retention
Real estate, title and escrow
The industry criminals target most, because the money is already moving
- ALTA Best Practices
- Wire verification procedure
- Lookalike domain monitoring
- Underwriter requirements
Non-profits and associations
Donor trust, restricted budgets, and a lot of volunteers
- Donor data protection
- Volunteer access control
- Grant conditions
- PCI DSS for donations
First fifteen days
What actually happens after you say yes
No six-week discovery phase billed by the hour. Two weeks from kickoff you have a documented, monitored, backed-up environment.
Day 1
Kickoff
We agree what success looks like, who we call for what, and how your people reach us. You leave the call knowing the support number, the escalation path and the next three dates.
You getSupport channels live, named contacts on both sides, dates set
Days 2-5
Discovery
We inventory what you actually run — devices, servers, cloud tenants, line-of-business software, licences, network gear and the things nobody remembered. We look for risk and for money being wasted, and we usually find both.
You getFull asset inventory and a prioritised findings list
Days 6-7
Documentation
Findings become a plan. You get a written roadmap, the policies your obligations require, and a clear split of what we own versus what stays with you. No surprises later about who was supposed to do what.
You getRoadmap, security plan and a responsibility matrix you keep
Days 8-14
Deployment
Agents, protection, backup and identity controls are rolled out in a deliberate order, mostly outside working hours. We fix the urgent findings from discovery as we go and tell you when something needs a decision.
You getEvery covered device monitored, protected and backed up
Day 15+
Steady state
Routine takes over: monitoring, patching, tickets, tested restores and a review each quarter. The roadmap stays current, so the next twelve months are planned rather than reactive.
You getMonthly summary, roadmap kept current, quarterly review if you want one
In their words
What clients say
“CY6 has completely transformed our IT setup. Their team is always responsive, easy to reach out to and very professional. They have become an essential part of our business.”
“Their IT support and cybersecurity are spot-on and tailored to what we need. Since working with them we have seen less downtime and a real boost in system speed. What stands out is how much they care about our success.”
“In addition to being an extremely knowledgeable and talented team, they have excellent customer support skills.”
Seven days to change your mind
If you are unhappy in your first week as a managed client, we tear up the agreement and refund everything we have not already spent on your licences. We would rather lose a client early than keep an unhappy one.
A $100,000 cybersecurity warranty
Covered clients running our security stack as designed are backed by a $100,000 warranty, subject to its terms. It is a backstop, not a replacement for cyber insurance, and we will always tell you the difference.
Obligations
We work to the standards your profession answers to
Controls are half of it. The other half is being able to show a client, an insurer or a regulator what you do.
- HIPAA
- NIST CSF
- PCI DSS
- FTC Safeguards Rule
- IRS Pub. 4557
- ISO 27001
- GDPR / CCPA
We build and evidence controls against these frameworks. Where a formal certification or attestation is required, we will tell you exactly what we hold and what we do not.
Questions
The things people ask first
Do we have to replace everything we already have?
Usually the opposite. Most of what you own is probably fine and just unmanaged, set up once by somebody who has since moved on. We insist on replacing the things that are so far out of support that keeping them costs more than changing them. Everything else comes back as a list with dates against it.
We already have an IT person. Does that rule us out?
Not at all, and they are usually glad to see us. The internal person is good at the things closest to the business. Nobody enjoys being the one who has to care about patching at eleven at night. We will also tell you if the two of us would overlap, including when that means you do not need us.
How fast do you respond?
Depends how much it is hurting you. A whole office down and one slow printer are not the same event and we do not price them as though they are. The actual targets are published rather than implied.
See the response targetsCan you work with our practice-management or clinical software?
Yes, and we will talk to the vendor for you if you would rather not relay messages between two technical parties. Some firms prefer to keep that relationship themselves, which is fine.
We will also say when a vendor requirement, or something your office already does, is the actual security problem. That conversation is awkward. It is also the one worth paying for.
What is the $100,000 cybersecurity warranty?
A warranty on the security stack we deploy, included with Complete. It is not insurance and does not replace it. The conditions are published rather than buried, because a warranty you cannot read the conditions of is just a number.
Read the warranty conditionsMore on the how we work page, or just ask us.
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967