top of page

Frequently Asked Questions

General IT Services FAQs

What does managed IT actually mean and do I need it?

Managed IT means I handle the technology your business runs on so you don't have to think about it. That includes keeping computers running, managing your Microsoft 365 or Google Workspace environment, endpoint protection, backup, email security, and being the person you call when something breaks. You get me directly, not a ticket queue. Most small businesses find they need managed IT when IT problems start costing them more time and money than a flat monthly fee would.

How much does managed IT cost?

Managed IT at SNL-Tech Services is a flat monthly fee based on the number of users in your business. Most small business engagements run $1,597 to $2,597 per month depending on your size and what you need. There are no hourly charges for normal support calls and no surprise invoices. Standalone assessments are also available starting at $995 if you're not ready for a managed services agreement.

What kinds of businesses do you work with?

Law firms, healthcare and behavioral health practices, construction companies, farms and equestrian facilities, financial services firms including CPAs and financial advisors, dental and medical offices, veterinary clinics, animal care businesses, trades businesses including plumbers, HVAC, electricians, and auto repair shops, and defense contractors pursuing CMMC compliance. If your industry isn't listed, reach out. I may still be a good fit.

What is the best cybersecurity solution for small businesses?

MFA on every account is the single most impactful control for most small businesses. Email is where most attacks start. A phished password with MFA enabled is a problem. A phished password without MFA is a breach. Beyond MFA: endpoint detection and response on every device, email security including anti-phishing and Safe Links, tested backup with offsite copies, and patch management. SNL-Tech Services handles all of these as part of managed IT.

Do you work outside of Maryland?

Yes. I work with businesses across Maryland, Northern Virginia, West Virginia, Delaware, Pennsylvania, and the DC area. Most of what I do is handled remotely. Audits, assessments, Microsoft 365 management, security configuration, and day-to-day support can all be done without stepping foot in your building. I come onsite when the situation calls for it such as network installations, camera systems, or shop WiFi. For situations requiring travel outside my typical coverage area, arrangements can be made. I have traveled as far as southern Georgia and Vermont to support clients onsite.

Cybersecurity & Data Protection FAQs

How can I protect my business from cyberattacks?

Start with MFA on every account, especially email. Most attacks start with a phished password and MFA stops them cold. Beyond that: endpoint detection and response on every device, email security including anti-phishing policies and SPF/DKIM/DMARC records, tested backup with offsite copies, and automatic patching. These aren't optional anymore. Cyber insurance carriers are requiring them and attackers are counting on small businesses not having them. SNL-Tech Services handles all of these as part of managed IT.

What should I do if my business experiences a data breach?

Call me immediately if you're a managed client. If you're not yet a client, call or text (301) 541-9242 directly. The first hour matters most. Do not turn off affected computers — preserve them for forensics. Disconnect them from the network but leave them powered on. Do not pay a ransom without talking to your carrier first. Notify your cyber insurance carrier as soon as possible — most policies have a reporting deadline. Document everything you can about what happened and when. SNL-Tech Services can help you contain the situation, coordinate with your carrier, and work through the recovery process.

Do small businesses really need cybersecurity?

Yes. Small businesses are specifically targeted because attackers know they tend to have weaker controls than large companies. Most ransomware attacks on small businesses don't come from sophisticated hackers. They come from criminals who send phishing emails to thousands of businesses at once and wait to see whose staff clicks. The ones who click and have no MFA, no endpoint protection, and no backup are the ones who pay ransoms. The ones who have those controls in place recover quickly or avoid the incident entirely. The cost of basic cybersecurity controls is a fraction of the cost of a single incident.

What if I already have IT support?

Depends on what you need. Some clients bring me in for a specific assessment or project. Some want me to take over entirely from a previous provider. Some have an internal person who handles basic support and want me to handle the security and compliance side. I can work in any of those situations without stepping on what's already in place.

Is my staff using AI tools without my knowledge?

Almost certainly yes. ChatGPT, Claude, Copilot, Gemini, and Grok are all free and easy to use. Your staff is using them to draft emails, summarize documents, research topics, and get work done faster. Most of it is happening on personal accounts with no policy and no oversight. That creates real exposure: client data entered into a personal AI account leaves your environment with no retention policy and no IT controls. If a lawsuit is filed, that chat history is discoverable. Cyber insurance carriers are adding AI-specific exclusions to policies. SNL-Tech Services offers an AI Governance Assessment that finds out what tools are in use, classifies the risk, and puts an Acceptable Use Policy in place. Flat rate $1,700.

AI and Compliance FAQs

Does HIPAA apply to my business?

If you're a healthcare provider, health plan, or healthcare clearinghouse, yes. That includes medical practices, dental offices, behavioral health providers, substance use disorder treatment programs, and more. If you handle protected health information as a business associate of one of those entities, it also applies to you. SNL-Tech Services signs a Business Associate Agreement with every healthcare client and handles the technical controls HIPAA requires including MFA, encryption, access controls, audit logging, and backup. The most frequently cited gaps in OCR enforcement actions are no completed risk analysis, no MFA, shared user accounts, and no tested backup.

Does the FTC Safeguards Rule apply to my CPA firm or financial advisory practice?

Yes. The FTC Safeguards Rule under GLBA covers financial institutions significantly engaged in financial activities, and the FTC's interpretation includes CPAs, tax preparers, and financial advisors who handle nonpublic personal information. The 2023 update added specific requirements many small firms still haven't addressed: mandatory MFA, encryption of customer data, a designated qualified individual responsible for the information security program, a Written Information Security Program, and an annual report to the board or governing body. Not having a WISP is a violation, not just a gap. SNL-Tech Services handles the technical implementation and documentation side of FTC Safeguards compliance.

What is shadow AI and why should my business care?

Shadow AI is any AI tool being used in your business without IT approval, oversight, or policy. ChatGPT, Claude, Copilot, Gemini, and Grok are all being used by staff at small businesses right now, mostly on personal accounts with no policy governing what data can go into them. This creates three problems. First, sensitive business or client data entering a personal AI account leaves your environment with no controls and no way to retrieve it. Second, if litigation is filed for any reason, AI chat history on personal accounts is discoverable and your business has no ability to manage or produce those records. Third, cyber insurance carriers are adding AI-specific exclusions to commercial policies. IBM's 2025 Cost of a Data Breach report found that shadow AI added $670,000 to average breach costs. SNL-Tech Services offers an AI Governance Assessment at $1,700 that identifies what tools are in use, classifies the risk, and delivers an Acceptable Use Policy and governance framework.

Still have questions about IT solutions for your business? 

bottom of page