top of page

Frequently Asked Questions From Small Business Owners

Small business owners often have questions about IT support, Microsoft 365, cybersecurity, compliance, AI, backups, assessments and what it is actually like to work with SNL-Tech Services. I provide Managed IT Services, Microsoft 365 and Google Workspace management, cybersecurity, IT assessments, AI governance, technical compliance support, backup and recovery, network and connectivity work, and other technology services for small businesses. Some questions have straightforward answers, while others depend on the way the business is set up, the technology already in place and the requirements that apply to that particular organization.

This FAQ brings together some of the questions I hear most often so you can get a clearer understanding of the services I provide and what might make sense for your business. If you do not see your question here, reach out. I am happy to talk through your environment and help you figure out the right next step.

Managed IT & Small Business IT FAQs

What does Managed IT actually mean for a small business?

Managed IT means I take ongoing responsibility for the technology your business depends on instead of only getting involved when something breaks. That can include user and device management, Microsoft 365 or Google Workspace, cybersecurity, networks, backups, updates, vendor coordination, documentation and day to day troubleshooting. For a small business, the biggest difference is continuity. I get to know the environment, the people using it and the decisions that have already been made. That allows me to look beyond the immediate problem and consider how changes may affect the rest of the business. Managed IT is not simply a help desk subscription. It is ongoing management of the technology that supports the company.

How do I know if my small business needs Managed IT Services?

Managed IT usually makes sense when technology has become important enough to the business that waiting for something to fail is no longer a good strategy. If employees depend on Microsoft 365, cloud applications, shared files, remote access, business networks or other systems every day, someone needs to be responsible for maintaining that environment and knowing how it fits together. It may also make sense when the owner or office manager has become the unofficial IT person, documentation is missing, different vendors are managing separate pieces of the environment or nobody is regularly reviewing security, backups, users and devices. Not every business needs the same level of ongoing support, which is why I prefer to understand the environment before recommending a Managed IT relationship.

How much does Managed IT cost?

Managed IT pricing at SNL-Tech Services is based primarily on the number of devices being managed, along with the complexity of the environment and the level of support the business needs. A small office with a handful of computers and a straightforward network is different from a company with dozens of devices, multiple locations, field employees, servers or more complicated security and compliance requirements. My Managed IT plans are structured around device counts, but I still review the environment before finalizing a proposal. That allows me to understand what is being managed and whether there are additional systems, projects or requirements that need to be considered.

Do I have to sign up for Managed IT to work with SNL-Tech Services?

No. Managed IT is only one way to work with SNL-Tech Services. Some businesses come to me for a specific project, a Microsoft 365 Audit, an IT Baseline Assessment, Cyber Insurance Readiness, AI Governance, Incident Response Planning, technical compliance implementation or another defined technology need. You may already have an IT provider and simply want an independent review of one part of the environment. If an assessment or project later shows that ongoing IT management would be useful, we can discuss that separately. Hiring me for one service does not automatically commit your business to a Managed IT agreement.

Can SNL-Tech Services work with my existing IT company or other technology vendors?

Yes. Small businesses often have several technology vendors involved in the same environment, including internet providers, software companies, copier vendors, phone providers, website companies, cloud vendors and specialized application support. I can work with those vendors when the technical work overlaps. That may mean helping troubleshoot an issue, providing configuration information, coordinating a change or making sure one vendor's work does not create a problem somewhere else in the environment. If you already have an IT provider and want an independent assessment or a specific project completed, we can also define that scope without assuming I am replacing them.

What kinds of businesses does SNL-Tech Services work with?

I primarily work with small businesses that depend on technology but do not necessarily have a full internal IT department. That includes law firms, healthcare and behavioral health practices, construction and trades businesses, farms and agricultural businesses, veterinary and animal care organizations, CPAs and financial services firms, government and defense contractors, industrial businesses and other small organizations with technology that needs to be managed properly. The industry matters because technology should support the way the business actually operates. A construction company with field crews has very different needs from a law firm, healthcare practice or CPA office. I take those differences into account instead of applying the same setup to every client.

Do you provide onsite IT support or only remote support?

I provide both remote and onsite IT support. Many Microsoft 365, cybersecurity, user management, troubleshooting, assessments and administrative tasks can be handled remotely, which allows issues to be addressed without always requiring a site visit. Onsite work makes sense when the project involves networking, WiFi, equipment, new locations, physical infrastructure or another issue that needs hands on involvement. I determine that based on the work rather than assuming everything should be remote or everything requires an onsite visit.

What areas does SNL-Tech Services serve?

SNL-Tech Services is based in Columbia, Maryland and works with small businesses throughout Maryland, Northern Virginia, Washington DC, Southern and Central Pennsylvania, the Eastern Panhandle of West Virginia and Northern Delaware. Many services can also be provided remotely outside the Mid Atlantic region. For projects, assessments, implementations or Managed IT relationships that require an onsite presence outside my normal service area, I am willing to travel when the scope of the engagement makes sense.

Microsoft 365 & Google Workspace FAQs

Is Microsoft 365 actually being managed, or are we just paying for the licenses?

That is one of the first questions I ask when I look at a Microsoft 365 environment. A business can have Microsoft 365 working perfectly well for email and files while many of the administrative, security and device management capabilities included with its licensing have never been reviewed or configured. Managing Microsoft 365 means looking beyond whether Outlook opens and employees can access OneDrive. It includes understanding identities, administrative access, MFA, Conditional Access where available, device management, Microsoft Defender, email security, SharePoint and OneDrive permissions, external sharing, third party applications, logging, backup and the other settings that matter to the particular business.

What is a Microsoft 365 Audit?

A Microsoft 365 Audit is a focused review of how your Microsoft 365 environment is currently configured, secured and managed. I also use the phrase Microsoft 365 Tenant Security Review when describing this work because the purpose is to look beyond whether Microsoft 365 is simply working and understand what is happening behind the scenes. The exact review depends on the licensing and environment, but it can include identities, administrative accounts, authentication, Conditional Access, Microsoft Defender, Intune and device management, email security, SharePoint, OneDrive, external access, third party applications, backup and other relevant controls. The result is a clearer picture of what is configured, what needs attention and what I would prioritize.

What is the difference between a Microsoft 365 Audit and an IT Baseline Assessment?

A Microsoft 365 Audit focuses specifically on the Microsoft 365 tenant. An IT Baseline Assessment is broader and looks at the overall technology environment, which may include computers, servers, networking, firewalls, WiFi, business applications, backups, user access, Microsoft 365 or Google Workspace and other technology the business depends on. If your main concern is Microsoft 365 security or configuration, the Microsoft 365 Audit is usually the more focused starting point. If you are not sure what technology the business has, how everything fits together or where the larger risks are, an IT Baseline Assessment may make more sense.

Does Microsoft 365 Business Premium automatically make my business secure?

No. Microsoft 365 Business Premium includes access to a number of security and management capabilities, including Microsoft Intune, Microsoft Defender for Business and Microsoft Entra ID P1, which supports features such as Conditional Access. Having the license available does not mean every capability has been configured appropriately for your organization. Someone still needs to determine which settings make sense for the business, configure them, test them and review them as users, devices and business requirements change. I often find that the licensing is already there, but the business is only using part of what it is paying for.

Can employees safely access Microsoft 365 from personal devices?

They can, but whether they should and what access they receive should be a business decision rather than something that happens by default. A company may decide that personal devices are acceptable for certain types of access while company data or more sensitive applications require a managed or compliant device. Microsoft 365 environments with the appropriate licensing can use tools such as Conditional Access and Intune to place more control around how users and devices access company resources. The right approach depends on the business, the information being accessed and whether the organization has regulatory, contractual or insurance requirements that affect device use.

Does my business need a separate backup for Microsoft 365?

There is not one answer that applies to every business. Microsoft 365 includes native retention and recovery capabilities, and Microsoft also offers Microsoft 365 Backup as an additional backup service. The question is whether those capabilities meet your business's actual recovery requirements. When I review backup strategy, I look at what data the business depends on, how long it needs to be retained, what kinds of failures or deletions it needs to recover from, how quickly the data needs to be restored and whether an independent backup copy makes sense. For some businesses, a separate third party Microsoft 365 backup is an appropriate additional layer of protection.

Do you support Google Workspace as well as Microsoft 365?

Yes. I work with both Microsoft 365 and Google Workspace environments. That can include user and administrative account management, security settings, access controls, business email, file sharing, backup options and general configuration. I also offer a Google Workspace Audit for businesses that want a focused review of how their environment is currently configured and where security or administrative settings may need attention. The goal is the same as with Microsoft 365: understand what is actually in place before making recommendations.

Cybersecurity & Cyber Insurance FAQs

What cybersecurity protections does a small business actually need?

There is no single cybersecurity setup that is right for every small business. The appropriate controls depend on the systems you use, the information you handle, how employees work, whether people access company resources remotely and whether you have regulatory, contractual or cyber insurance requirements. For many small businesses, I look closely at identity security, MFA, endpoint protection, email security, software updates, administrative access, device management, encryption, backups, logging, employee awareness and incident response. The goal is not to turn on every security feature available. It is to understand the actual environment and put the right protections around the technology the business depends on.

Is MFA enough to protect my business?

No. MFA is an important security control, but it is one part of a larger security strategy. A business can have MFA enabled and still have problems caused by an unmanaged device, excessive administrative permissions, phishing, malware, outdated software, insecure email configuration or poor backup and recovery practices. I generally look at security in layers. Identity protection, devices, email, access controls, backups, updates, monitoring and employee practices all play a role. MFA makes account compromise more difficult, but it should not be treated as the entire cybersecurity plan.

How do I know whether our cyber insurance questionnaire is answered correctly?

The safest approach is to compare the technical questions on the application or renewal directly against the environment that actually exists. If the questionnaire asks whether MFA is enabled, backups are tested or endpoint protection is deployed, the answer should be based on what can be verified rather than what someone assumes the IT provider has configured. That is also why I recommend keeping supporting documentation where practical. If a question is unclear or involves interpretation of policy language or coverage, the business should ask its broker, agent or carrier. My role is to help verify the technical side of the answer.

What is a Cyber Insurance Readiness Assessment?

A Cyber Insurance Readiness Assessment is a technical review driven by the insurer's actual questionnaire or renewal requirements. I review the technical questions against the environment, verify which controls are in place and identify areas where the business does not yet have enough information or where a control may need attention. Depending on the questionnaire, that may involve MFA, administrative accounts, endpoint protection, email security, encryption, backups, remote access, Microsoft 365 security, incident response or other controls. The purpose is to help the business submit technical answers based on evidence instead of assumptions.

Can SNL-Tech Services tell me whether my cyber insurance policy will cover a claim?

No. Coverage decisions depend on the policy language, the insurer and the circumstances of the incident. I do not provide insurance or legal advice and I cannot guarantee whether a carrier will approve or deny a particular claim. What I can do is help verify the technical controls that exist, document how they are configured and help the business answer technical questions more accurately. Questions about coverage, exclusions, policy interpretation and claims decisions should remain with the carrier, broker, agent or appropriate legal professional.

Does cyber insurance replace the need for cybersecurity?

No. Cyber insurance and cybersecurity serve different purposes. Cybersecurity is intended to reduce the likelihood and impact of an incident, while insurance may provide financial or response support depending on the policy and the event. A business still needs to protect its users, devices, accounts, data and systems even if it has insurance. In fact, cyber insurance applications often ask about the security controls already in place, which is another reason the technical environment should be understood and documented.

What should we do if an employee account or computer may have been compromised?

The first priority is to contain the problem without unnecessarily destroying information that may be needed to understand what happened. Depending on the incident, that can mean isolating a device, securing affected accounts, reviewing sign in activity and logs, preserving relevant evidence and determining what other systems may be involved. The business should also follow its incident response plan and any notification requirements in its cyber insurance policy or applicable contracts. If the organization does not already have an incident response plan, that is something I can help develop before an emergency happens.

IT Assessments & Audits FAQs

What is an IT assessment, and when should a small business have one?

An IT assessment is a structured review of part or all of the technology environment so the business can understand what is actually in place, how it is configured and where there may be gaps or unanswered questions. The scope depends on the assessment. Some reviews focus on Microsoft 365 or Google Workspace, while others look more broadly at computers, networks, backups, security, applications and access. An assessment can make sense when a business is changing IT providers, preparing for a cyber insurance renewal, dealing with missing documentation, planning a major technology change or simply wants an independent view of the environment before making another decision.

Which IT assessment does my business need?

The right assessment depends on the question you are trying to answer. If the concern is mainly Microsoft 365, a Microsoft 365 Audit may be the best starting point. If you need a broader understanding of the entire IT environment, an IT Baseline Assessment may make more sense. If a cyber insurance questionnaire is driving the review, a Cyber Insurance Readiness Assessment is more focused. If the business is already using AI or wants to put governance around AI use, an AI Governance Assessment may be the right fit. I would rather choose the assessment around the actual problem than put every business through the same process.

What is an IT Baseline Assessment?

An IT Baseline Assessment is a broader review of the technology the business depends on. That can include computers, servers, user accounts, networks, firewalls, WiFi, business applications, backups, cloud services, remote access, endpoint security and documentation. The goal is to establish a clearer picture of the current environment and identify where important gaps, risks or dependencies exist. It is often useful when a business does not have current documentation, has inherited technology over time or wants to understand the environment before deciding what should be changed.

Can I hire SNL-Tech Services for an independent assessment if I already have an IT provider?

Yes. You do not have to replace your current IT provider in order to hire SNL-Tech Services for a focused assessment or independent review. Some businesses want a second set of eyes on Microsoft 365, cyber insurance controls, AI use or the broader IT environment. In those cases, I can define the assessment scope separately and document what I find. If remediation is needed afterward, the business can decide whether I perform that work, the existing IT provider handles it or another specialist becomes involved.

What happens after an assessment finds problems?

Finding a problem is only the first step. I help explain what the issue means, how important it is and what I would prioritize. Some findings may be simple configuration changes, while others may require a larger remediation project, documentation work or coordination with another vendor or specialist. The next step depends on the business and the scope of the assessment. I can perform technical remediation when it falls within my services, but an assessment does not automatically turn into a larger project or ongoing Managed IT agreement.

Does an IT assessment mean I have to hire SNL-Tech Services to fix everything you find?

No. The assessment is intended to give you a clearer understanding of the environment and the issues that deserve attention. If you want me to perform the remediation work, we can scope that separately. If you already have an IT provider or another vendor who should handle the changes, the assessment can still give you useful documentation and a clearer starting point for that work.

What is included in an IT assessment report?

The exact report depends on the assessment, but it generally documents the areas reviewed, what I was able to verify, the issues or gaps identified and the recommendations I would prioritize. For some assessments, the documentation may include technical findings, screenshots, configuration details, evidence, inventories or other supporting information. The goal is to give the business something useful and understandable rather than a generic checklist with no context.

Is an IT assessment the same as a formal compliance audit or certification?

No. An IT assessment performed by SNL-Tech Services is a technical review. It can help identify configuration gaps, document technical controls and support remediation, but it is not a formal legal opinion, regulatory certification or third party compliance assessment. If a business needs a formal assessor, attorney, compliance consultant or other specialist, I keep that role separate from the technical work and documentation I provide.

HIPAA, FTC Safeguards & CMMC FAQs

What does technical compliance support actually mean?

Technical compliance support means helping the business turn applicable cybersecurity requirements into technology that is actually configured, documented and maintained. A policy may say that access needs to be controlled, activity needs to be logged or sensitive information needs to be protected, but someone still has to determine how those requirements apply to the systems the business actually uses. My role is the IT side of that work. I can review the technical environment, identify gaps, implement or remediate security controls and document how those controls are configured. I do not provide legal advice or make formal compliance determinations.

What part of HIPAA compliance does SNL-Tech Services handle?

I focus on the technical side of protecting electronic protected health information. Depending on the environment, that can include user access, authentication, audit logging, device security, Microsoft 365 configuration, transmission security, encryption decisions, backups, endpoint protection and other technical safeguards. HIPAA also includes administrative, physical, privacy and legal responsibilities that go beyond IT. I can work alongside the organization's compliance professional, attorney or other specialist by implementing the technical controls and providing documentation about how the IT environment is configured.

Does HIPAA currently require MFA and encryption?

The currently effective HIPAA Security Rule does not simply say that every regulated organization must implement the same MFA and encryption configuration. The Rule includes required standards as well as addressable implementation specifications, and organizations need to make documented decisions based on their risk analysis and the requirements that apply to their environment. HHS has proposed changes that would make requirements such as MFA and encryption more explicit and broadly mandatory, with limited exceptions, but those proposed changes have not replaced the currently effective Security Rule as of 2026. Regardless of the minimum regulatory language, I may still recommend MFA, encryption and other security controls when they are appropriate for protecting the business and its information.

What technical work can SNL-Tech Services provide for the FTC Safeguards Rule?

For financial institutions subject to the FTC Safeguards Rule, I can help implement and document technical safeguards within the IT environment. That may include MFA, access controls, encryption, endpoint protection, system and device inventories, logging and monitoring, backup and recovery, network security and incident response preparation. The business remains responsible for its overall information security program, risk assessment, Qualified Individual responsibilities and other requirements under the Rule. My role is to help make sure the technical environment supports those responsibilities.

What CMMC work does SNL-Tech Services provide for small defense contractors?

My CMMC work focuses on technical implementation, remediation and documentation. I can help review the systems, users and devices involved, identify technical gaps, implement applicable security controls and document how those controls are configured. For Level 1, that can include technical support for the safeguards protecting Federal Contract Information. For Level 2 environments involving Controlled Unclassified Information, I can help with the technical implementation of applicable NIST SP 800-171 Revision 2 requirements, evidence collection, system documentation, remediation and the technical portions of System Security Plan development. I do not perform formal CMMC certification assessments or certify another organization as compliant.

Does CMMC Level 1 require a third party assessment?

Under the current CMMC Phase I implementation in 2026, Level 1 uses an annual self assessment conducted by the organization, with results and the required affirmation entered into SPRS. A third party C3PAO assessment is not part of the current Level 1 self-assessment requirement. CMMC is currently under review by the Department of War, so businesses should continue checking the requirements in their actual solicitations and contracts rather than assuming the program will remain unchanged.

What is currently required for CMMC Level 2?

Under the current Phase I structure, CMMC Level 2 may use a self assessment every three years against the 110 requirements in NIST SP 800-171 Revision 2, along with an annual affirmation. Results are entered into SPRS. The Department of War suspended implementation of CMMC Phase II in July 2026 while the program is being reviewed. Phase I self-assessment requirements remain in place, and select government-led assessments may still occur. Because CMMC is actively changing, I verify the current program requirements before advising a contractor on technical preparation.

Does buying Microsoft 365 make my business HIPAA or CMMC compliant?

No. Microsoft 365 can provide technology that supports security and compliance responsibilities, but purchasing a license does not automatically configure the environment or make the business compliant with a particular framework. The appropriate licensing, configuration and documentation depend on the business, the information being handled and the requirements that apply. Features such as identity controls, device management, logging, encryption, email security and access restrictions still need to be evaluated and configured appropriately.

Are you a compliance attorney, CMMC assessor or formal certification body?

No. SNL-Tech Services provides technical implementation, remediation, IT management and technical documentation. If a business needs legal interpretation, a formal compliance determination, an authorized assessment or another specialized professional, I keep that role separate. I can work with those professionals by implementing the technical controls, providing configuration information and producing the technical evidence they need from the IT environment.

AI Governance FAQs

Do small businesses really need an AI policy?

If employees are using AI for work, the business should have clear expectations around what tools are approved, what information can be entered into them and who is responsible for reviewing AI-generated work before it is used. An AI policy does not need to be a long legal document. For many small businesses, the goal is simply to create practical rules employees can understand and follow. That may include approved platforms, company versus personal accounts, handling of confidential information, acceptable use, review requirements and what employees should do if they are unsure whether information should be used with an AI tool.

Can employees use ChatGPT, Claude, Copilot, Gemini or other AI tools for work?

They can, but the business should make that decision intentionally instead of allowing every employee to choose tools and account types independently. Different AI platforms, plans and configurations have different terms, administrative controls, data handling practices and integration capabilities. Before approving an AI tool, I look at what employees want to use it for, what company information may be involved, which account or subscription is being used and whether the platform's current terms and controls are appropriate for that use. A tool that is reasonable for drafting general marketing copy may not automatically be appropriate for confidential client information, regulated data or sensitive internal records.

What is Shadow AI?

Shadow AI is the use of AI tools for business purposes without the organization's knowledge, approval or established governance. It can happen when an employee creates a personal AI account, installs an AI application, connects a service to company data or starts using a new AI feature without anyone responsible for IT or management knowing about it. The concern is not simply that employees are using AI. The problem is that the business may not know what tools are being used, what information is being entered, what permissions have been granted or which terms apply to those accounts. An AI Governance Assessment can help establish that visibility before the business decides what should be approved or restricted.

What is an AI Governance Assessment?

An AI Governance Assessment is a structured review of how AI is actually being used within the business. I look at the tools and accounts employees are using, the business processes involved, what types of company information may be interacting with AI and whether the organization has policies or technical controls around that use. The assessment can also include reviewing approved versus unapproved tools, personal versus company managed accounts, access permissions, Microsoft 365 integration, existing policies and areas where the business may need clearer guidance. The purpose is to understand what is happening before recommending additional AI tools or controls.

Is it safe to connect AI tools to Microsoft 365?

It can be, but the answer depends on the AI product, the Microsoft 365 environment, the permissions being granted and the information the AI tool will be able to access. For Microsoft Copilot and Copilot Chat used with organizational accounts, Microsoft currently applies enterprise data protection and says the tools respect existing identity and access permissions. Microsoft also says prompts, responses and Microsoft Graph data used by Copilot are not used to train foundation models. That does not mean every Microsoft 365 environment is automatically ready for AI. If SharePoint permissions, OneDrive sharing, administrative access or other controls are too broad, an AI tool may be able to surface information that users were already technically permitted to access but should not have had access to in the first place. That is why I prefer to review the underlying Microsoft 365 environment before connecting AI more deeply into company data.

Should employees use personal AI accounts for company work?

For routine business use, I generally prefer company managed accounts where the organization has evaluated the specific platform and plan. A company managed environment can give the business more control over access, administration, offboarding and the terms under which business information is being handled. The important point is not to assume that a personal account and a business account provide the same protections. For example, OpenAI currently states that ChatGPT Business workspace data is excluded from model training by default, while personal ChatGPT accounts have separate data controls that users can manage themselves. The exact protections should always be verified for the current product and plan before sensitive company information is used.

Does ChatGPT Business train on our company data?

OpenAI currently states that it does not use ChatGPT Business workspace data to train its models by default. ChatGPT Business is governed by OpenAI's business terms and privacy commitments, and workspace data is handled differently from personal ChatGPT use. That does not automatically mean every type of company information should be entered into ChatGPT Business. The organization still needs to consider its own contractual, legal, regulatory and internal requirements, as well as the features being used and any external apps or services connected to the workspace.

Can SNL-Tech Services help us choose which AI tools employees are allowed to use?

Yes. I can help the business review how employees want to use AI, which platforms and account types are being considered, what company information may be involved and what administrative or technical controls are available. The goal is not to choose a platform based only on which AI produces the best answer in a demo. I look at how the tool fits into the existing IT environment, how accounts will be managed, what data will be involved, what permissions the tool may need and what policies should exist around its use. From there, the business can make a more informed decision about which tools should be approved and how employees should use them.

Backup, Incident Response & Recovery FAQs

Does Microsoft 365 or Google Workspace replace the need for backup?

Not necessarily. Microsoft 365 and Google Workspace include native retention and recovery capabilities, but the right backup strategy depends on what data the business depends on, how long it needs to be retained, how quickly it needs to be restored and what kinds of failures or deletions the business wants to be able to recover from. Microsoft now also offers Microsoft 365 Backup as a separate backup service for Exchange Online, SharePoint and OneDrive. Third party backup solutions are another option. I look at the business's actual recovery needs before recommending whether native recovery, Microsoft 365 Backup, a third party backup platform or another approach makes sense.

How do I know whether our backups will actually work when we need them?

A backup should not be considered reliable simply because a dashboard says the job completed successfully. The business should understand what is being backed up, where the backup is stored, how long data is retained and what the recovery process actually looks like. Testing matters because a backup is only useful if the data can be restored when the business needs it. I look at backup status, retention, recovery options and whether restore testing makes sense for the environment. CISA specifically recommends regularly testing the availability and integrity of backups as part of ransomware and disaster recovery preparation.

Does a small business really need an incident response plan?

If the business depends on technology, I believe it should have a practical plan for what happens when something goes wrong. An incident response plan does not need to be a massive document. It should give the business a clear starting point for handling events such as a compromised account, ransomware, lost device, suspicious email activity, data exposure or another cybersecurity incident. The value is having responsibilities, contacts, communication steps and recovery priorities identified before the business is under pressure. NIST's current incident response guidance emphasizes preparation, response and recovery as part of ongoing cybersecurity risk management rather than treating incident response as something that starts only after an attack.

What should be included in a small business incident response plan?

The plan should reflect the business that will actually use it. I generally want it to identify who has decision making authority, who employees should contact, which technology vendors and insurance contacts may need to be involved, which systems are most important and how the business will communicate if normal systems are unavailable. It should also address practical response steps such as account containment, device isolation, evidence preservation, backup and recovery considerations and the process for bringing systems back into operation. The exact plan depends on the environment, regulatory obligations, contracts and cyber insurance requirements that apply to the business.

Who should employees call first if they think something has been hacked?

Employees should have a clear internal contact identified before an incident happens. That may be the owner, office manager, designated security contact or IT provider depending on the business. The important thing is that employees know who to contact immediately and do not spend valuable time trying to figure it out during the incident. If SNL-Tech Services manages the environment, I can help the business document those escalation procedures and determine what technical steps need to happen next.

What is the difference between incident response, disaster recovery and backup?

Backup is the process of keeping recoverable copies of important data or systems. Disaster recovery focuses on restoring technology and business operations after a major outage, failure or destructive event. Incident response focuses on how the organization identifies, contains, investigates, communicates about and recovers from a cybersecurity incident. They overlap, but they are not the same thing. A business can have good backups and still struggle during an incident if nobody knows who should isolate a device, secure an account, contact the insurer or determine which systems need attention first. Likewise, an incident response plan is much more useful when the business has reliable recovery options behind it.

What should we do first during a ransomware incident?

The first priority is usually containment. Depending on the circumstances, that can mean isolating affected systems or devices from the network, protecting unaffected systems and determining what has actually been impacted before restoration begins. The business should follow its incident response plan, preserve relevant evidence and involve the appropriate technical, insurance, legal or regulatory contacts when required. CISA's current ransomware guidance specifically recommends isolating affected systems, prioritizing critical services and restoring from known good backups during recovery.

Can SNL-Tech Services help build an incident response plan before something happens?

Yes. I offer Incident Response Planning as a standalone service for small businesses that want a practical plan based on their actual environment rather than a generic template. I work with the business to understand its technology, people, vendors, responsibilities, communication needs, insurance contacts and recovery priorities. The goal is to create a plan that employees and decision makers can actually use when something happens.

Working With SNL-Tech Services FAQs

Will I work directly with Shay?

Yes. SNL-Tech Services is a single-operator managed IT business, so you work directly with me. I get to know the environment, the people using it and the decisions that have already been made rather than passing you between different technicians or support tiers. When another vendor or specialist needs to be involved, I can coordinate with them, but I stay involved in the technical work and the relationship with the client.

Can I hire SNL-Tech Services for a one time project?

Yes. You do not need to sign up for Managed IT Services in order to work with me. I take on defined technology projects, assessments, Microsoft 365 and Google Workspace work, cybersecurity remediation, network and connectivity projects, AI governance, incident response planning, technical compliance implementation and other engagements when they fit within the services I provide.

What happens during the free consultation?

The free consultation is a chance for me to understand what prompted you to reach out, what technology your business depends on and what you are trying to accomplish. You do not need to have all of the technical details figured out before we talk. I may ask about your users, devices, Microsoft 365 or Google Workspace environment, network, business applications, security concerns, existing IT support and any regulatory, contractual or insurance requirements that may affect the work. From there, I can help determine whether the next step should be Managed IT, an assessment, a specific project or something else.

What if I do not know which IT service I need?

That is completely fine. Many businesses reach out because they know something is not working well or they are concerned about part of the environment, but they do not yet know which service fits the problem. My first step is to understand what is happening and what you are trying to solve. I would rather recommend the right starting point after hearing the situation than expect you to diagnose the technology problem before contacting me.

Do you work with businesses that already have an IT provider?

Yes. Some businesses hire SNL-Tech Services for an independent assessment, a specific project or technical work that falls outside the scope of their existing provider. I can work alongside the current IT company when that makes sense. The scope and responsibilities should be clear so everyone understands which part of the environment or project I am handling.

Do you provide both onsite and remote support?

Yes. Many services can be provided remotely, including Microsoft 365 and Google Workspace management, cybersecurity work, assessments, troubleshooting, administrative changes and AI governance. I also provide onsite support for work that requires a physical presence, such as networking, WiFi, equipment installation, new office setup and other infrastructure projects. Whether a visit is needed depends on the work being performed.

Do you travel outside your normal service area?

Yes, when the engagement makes sense. My primary service area includes Maryland, Northern Virginia, Washington DC, Southern and Central Pennsylvania, the Eastern Panhandle of West Virginia and Northern Delaware. Many services can be provided remotely outside that region. For assessments, projects, implementations or Managed IT relationships that require onsite work, I am also willing to travel elsewhere in the United States when the scope justifies it.

What kinds of businesses are a good fit for SNL-Tech Services?

I work best with small businesses that rely heavily on technology and want someone to understand and manage the environment rather than only respond when something breaks. That includes businesses such as law firms, healthcare and behavioral health practices, construction and trades companies, farms and agricultural businesses, veterinary and animal care organizations, CPAs and financial services firms, defense contractors, industrial businesses and other small organizations with technology that has become important to day to day operations.

What is the best way to get started?

The easiest way is to contact SNL-Tech Services and tell me what is prompting you to look for help. It may be an ongoing IT problem, a Microsoft 365 concern, a cyber insurance renewal, compliance requirements, an upcoming project or simply the feeling that nobody has looked at the whole environment in a while. From there, we can talk through the situation and determine what the most practical next step looks like.

Still Have Questions About Your Business IT?

 

If you do not see your question here, tell me what is happening with your technology and I can help you determine the right next step

bottom of page