Skip to main content
For business owners · ISO 27001 readiness · Operational since 2009 · US-based

Stop AI, cyber, and compliance risk from running your business. One US team. One SLA.

If a breach hit tomorrow, would the business survive the week? Most owners find out they were not ready only after it is too late. EFROS runs the security team most owners cannot afford to hire directly.

24×7 SOC·MonitoredMicrosoft 365·HardenedEndpoints·EDR + MDRBackups·ImmutableCloud·Azure · AWS · GCPPhones·3CX · Teams

Free. Three minutes. No sales call. Calibrated against IBM Cost of a Data Breach, Verizon DBIR, and Sophos benchmarks. For owners who want a defensible number on hand before the next renewal or board conversation.

By Stefan Efros, CEO & Founder, EFROS
Updated ·

EFROS operating model

Three disciplines. One accountable SLA.

Cybersecurity and 24/7 SOC, managed IT, and system integration, run by the same team under one contract with one escalation path. AI Governance is a specialized program for clients running generative AI in regulated contexts, mapped to NIST AI RMF, ISO/IEC 42001, and applicable US state AI laws. It is engaged separately and it answers to the same SLA.

Diagram. Four lanes converge into one node. Lanes 01 to 03, Cybersecurity and SOC, Managed IT, and System Integration, run under one contract. Lane 04, AI Governance, is a specialized program engaged separately. All four escalate into one accountable SLA and one escalation path.

Converges to

One accountable SLA, one escalation path.

Three disciplines under one contract. AI Governance is engaged separately and answers to the same SLA and the same on-call path. Priority bands and response targets are on the Trust Center; performance against them is reported quarterly under NDA.

Emergency line
+1 (765) 888-8888
Coverage
24/7, incident response
See the SLA matrix
  • Core disciplines, one contract
  • Specialized program, engaged separately, same SLA

Response rail, P1 Critical

A P1 incident on the clock.

P1 Critical is a customer-impacting outage or an active confirmed incident. Every lane above escalates into this rail. The targets are the Fortress SOC figures from the SLA matrix.

  1. Detect

    24/7

    Fortress SOC monitoring

  2. Acknowledge

    30 minutes

    Acknowledgement target

  3. Contain

    1 hour

    Containment status target

  4. Mitigate

    4 hours

    Mitigation target

  5. Notify

    within24 hours

    Formal notification target

Fortress SOC P1 Critical targets from the Incident Response SLA matrix. P2 through P4 carry their own acknowledgement and mitigation windows; formal notification below P1 follows the regulatory clock where one applies. Performance against the matrix is reported quarterly under NDA. Read the full SLA matrix.

What EFROS is not

Most buyers file us under one of three categories. None of them fit.

Each category is good at what it sells. The difference is what happens after the alert fires, the ticket closes, or the report is delivered.

Daily IT operations

Pure MSSP
Not included. Not in scope
Generic MSP
Included. Core service
Big-4 audit
Not included. Not in scope
EFROS
Included. Core service

24/7 detection and response

Pure MSSP
Partial. Alerts, you respond
Generic MSP
Partial. Business hours, by ticket
Big-4 audit
Not included. Not in scope
EFROS
Included. Operated 24/7

Remediation of findings

Pure MSSP
Not included. Handed back to you
Generic MSP
Partial. When a ticket is opened
Big-4 audit
Not included. Listed in the report
EFROS
Included. Fixed by the team that found it

Compliance evidence, continuous

Pure MSSP
Partial. Log retention
Generic MSP
Not included. Not a deliverable
Big-4 audit
Partial. Point in time
EFROS
Included. Continuous, mapped to the framework

Incident response with pre-authorized containment

Pure MSSP
Partial. Escalated, you authorize each step
Generic MSP
Partial. Best effort, no SLA
Big-4 audit
Not included. Separate engagement
EFROS
Included. Pre-authorized. P1 acknowledged in 30 minutes.

AI governance under US frameworks

Pure MSSP
Not included. Not in scope
Generic MSP
Not included. Not in scope
Big-4 audit
Partial. Advisory, separate engagement
EFROS
Included. Specialized program, aligned to NIST AI RMF

Accountability: one contract, one SLA

Pure MSSP
Partial. Security only, IT is a second vendor
Generic MSP
Partial. IT only, security is a second vendor
Big-4 audit
Not included. Engagement letter per audit
EFROS
Included. One contract, one SLA, one number to call

What you get

Pure MSSP
Alerts
Generic MSP
Tickets
Big-4 audit
A report
EFROS
An operated program
  • Included
  • Partial
  • Not included

The 30-minute figure is the published P1 acknowledgment target under Fortress SOC engagements. The full P1 to P4 matrix, with performance reported quarterly under NDA, is on the trust page. Scope detail for detection and response is under MDR and Incident Response.

● Risk Dashboard · Preview

Ten categories evaluated. One score each.

The free scan evaluates six categories from public data in 60 seconds. Four further categories require a full authenticated assessment: Microsoft 365 posture, endpoint protection, backup readiness, and incident response.

The dial on the right is a sample of what your live result looks like. Drop your domain and the same dashboard renders with your actual scores in about sixty seconds.

Free · 60 seconds · Read-only public DNS, mail, and TLS data. We never touch your network.
Per-category breakdown

Each card is one of the ten categories evaluated. The six free scan categories surface from public data; the four grayed ones require an authenticated engagement.

Sample · Security Score
A
89/100

Domain Security

DNSSEC · CAA · NS

Sample · Security Score
B
72/100

Email Authentication

SPF · DKIM · DMARC

Sample · Security Score
A
91/100

Web Security

HSTS · CSP · cookies

Sample · Security Score
A+
96/100

Brand Protection

Typosquats · BIMI

Sample · Security Score
A+
100/100

Infrastructure

DNSBL · CDN · CAA

Sample · Security Score
C
65/100

Compliance Readiness

CCPA / CPRA · security.txt

Engineer Assessment only
n/a

Microsoft 365 Posture

Conditional Access · Defender

Engineer Assessment only
n/a

Endpoint Protection

EDR · MDR · patching

Engineer Assessment only
n/a

Backup Readiness

3-2-1 · immutability · RTO

Engineer Assessment only
n/a

Incident Response

Playbooks · tabletops · retainer

Preview shown with sample data. Live scan delivers your actual scores. The Security Score covers domain, email, web, brand, infrastructure, and compliance categories from public data. The four grayed categories require an authenticated engagement and are not part of the free scan. EFROS does not request passwords or sensitive credentials through public website forms.

Free tools

Different question? Different tool.

Three more self-serve tools. Each one runs in the browser, shows your result on screen, and emails the full write-up you can hand to a CFO, a broker, or a board. Nothing to install, no credentials asked.

  • What a breach would cost · 3 minutes

    Exposure Calculator

    A dollar range for one incident, adjusted for your industry, revenue, and coverage: response, downtime, churn, legal exposure, and the premium hike at renewal. It also shows the gap your insurance would not cover.

    Next: a range on screen, not a single number. The full breakdown, including the out-of-pocket cost after insurance, lands in your inbox.

  • Where you stand

    Readiness Quiz

    Yes or no questions an owner can answer without calling IT. An honest verdict before you talk to anyone, including us.

    Next: your verdict on screen, Ready, At-Risk, or Exposed. The playbook you can run this week lands in your inbox.

  • Specialized programAI under US rules

    AI Risk Score

    For teams running Microsoft 365 Copilot or custom AI under US rules. Your use cases mapped to NIST AI RMF and the state laws that apply to you.

    Next: your US risk tier and the frameworks that apply, on screen. The full report with cited recommendations lands in your inbox.

All tools

Who EFROS is built for

Built for operational companies that cannot afford disruption.

EFROS is built for operational companies (SMB, mid-market, and enterprise) where IT downtime, email compromise, ransomware, regulatory exposure, or vendor confusion translates straight into business loss. Engagement models range from fully managed IT through co-managed operations to Fortress SOC coverage, scoped to your risk profile rather than your headcount.

Start with the role closest to yours.

Healthcare CIO

Pain
HIPAA breach liability, ransomware aimed at hospitals, and clinical AI workflows landing inside the EHR with no governance.
Outcome
24/7 SOC coverage, ePHI data loss prevention, and evidence mapped to NIST AI RMF, Colorado SB 26-189, and HHS-OCR Section 1557, ready before the next audit.
Evidence
4 weeksHIPAA audit closed for a multi-specialty healthcare provider, versus the typical 8-10. Zero findings.Read the healthcare case study

Best-fit industries

Also a fit: real estate and other operations-heavy businesses.

Best-fit conditions

  • Heavy reliance on Microsoft 365, email, VoIP, CRM, dispatch, TMS, ERP, or cloud systems
  • Downtime translates directly to revenue or compliance impact
  • Cyber-insurance renewal pressure or questionnaire pressure
  • Need endpoint, email, identity, backup, and cloud controls aligned under one SLA
  • Tired of vendor handoffs and unclear accountability
  • Need executive-level reporting against documented frameworks
Where EFROS is probably not the right fit
  • Very small operators that only need basic break-fix support
  • Buyers shopping purely on lowest-helpdesk price
  • Organizations unwilling to improve baseline security controls
  • Engagements where EFROS cannot obtain proper written authorization

Twenty minutes is enough to tell whether EFROS fits your risk profile. No deck, no pitch.

Book a 20-Minute Call

What has changed for owners and operators

IT is no longer a department. It's the operating spine.

Six issues that used to belong to the IT team are now executive concerns, and a seventh arrived in May. Each one is pinned to a month in 2026 and to something we published that month, so you can read the reasoning instead of taking the headline. Each one is fixable. None of them gets fixed by buying more tools.

  1. Weak identity is an open door

    Intrusions start at an identity boundary, not a network boundary, and MFA gaps, dormant admin rights, and missing Conditional Access are configuration decisions rather than purchases.

    Read: Implementing Zero Trust Security: A Practical Framework

  2. IT downtime is a business risk

    When dispatch, billing, EHR, or email stops, revenue and signed obligations stop with it, and a reactive ticket queue cannot carry that load once incidents overlap.

    Read: Why Managed IT Services Matter for Growth

    Also: Case study: 140 sites under a contracted uptime SLA

  3. Business email compromise drains wires

    Lookalike domains, account takeover, and altered invoices work against companies that never enforced DMARC, MFA, and payment verification: controls you configure and verify, not products you buy.

    Read: Top Cybersecurity Threats Businesses Face in 2026

    Also: Freight broker email security

  4. Vendor fragmentation hides accountability

    When several vendors share overlapping scope, an incident that crosses a boundary belongs to no one, and the finding stays open until one named party owns closing it.

    Read: Virtual CISO: When, Why, and How to Choose One in 2026

    Also: Case study: 3 vendors consolidated to 1 SLA

  5. Ransomware targets operational systems

    Attackers aim at the systems the business cannot run without, not at the IT department, and insurance carriers want evidence of working controls before paying a claim.

    Read: Ransomware Response Playbook: The First 24 Hours

  6. Endpoints are the perimeter

    Laptops on home networks, personal devices, and contractor machines are where intrusions start, and without EDR plus 24/7 monitoring an attacker can sit unnoticed for months.

    Read: MDR vs EDR vs XDR: Complete Comparison Guide for 2026

  7. AI enters the regulated stack

    Specialized program

    Copilot and unsanctioned assistants now read the same mailboxes, files, and records your auditors care about, so AI needs an inventory, a policy, and an incident path.

    Read: Microsoft 365 Copilot Governance Checklist for SMB

    Also: AI Incident Response: What's Different from Cyber

Not sure which of these apply to you? The Security Score checks six public categories in 60 seconds and asks for no credentials. Run the Security Score

Service tiers

Three ways to engage. One team behind all of them.

Pick the tier that matches where you are right now. Every tier is a fixed monthly fee with named contacts on both sides. If you ever need to leave, you take clean documentation and a working tenant with you.

Tier 1

Core IT

IT that just works.

The entry point for operational companies that need accountable, everyday IT.

Includes

  • Helpdesk and user support
  • Microsoft 365 administration
  • Device management (Windows, macOS)
  • Patch management
  • Backup monitoring
  • Network and endpoint health checks
  • Vendor coordination across SaaS and infrastructure

Custom pricing by environment

Get started with Core IT 

Tier 2Most chosen

Secure Operations

IT plus the security controls insurers ask for.

For companies that want to keep passing the cyber insurance questionnaire.

Everything in Core IT, plus

  • Endpoint protection (EDR) with behavioral detection
  • Email security hardening (phishing, spoofing, DLP)
  • Microsoft 365 security baseline (CIS Foundations Benchmark)
  • Vulnerability management with monthly remediation cycles
  • Security awareness support for end users
  • DNS, SPF, DKIM, DMARC review and enforcement
  • Backup and disaster recovery validation (test restores, not just runs)

Custom pricing by environment

Get a Secure Operations quote 

Tier 3

Fortress SOC

24/7 monitoring with someone on the other end.

For companies that have to show ongoing security operations to an auditor, insurer, or board.

Everything in Secure Operations, plus

  • 24/7 SOC monitoring (continuous, not business hours)
  • SIEM and log monitoring with custom detection content
  • Incident Response workflow with containment authorized in advance
  • Threat detection and tiered escalation
  • Compliance support (SOC 2, HIPAA, PCI DSS, NIST CSF)
  • Quarterly executive risk reporting, written for the board
  • Annual security roadmap aligned to business risk

Custom pricing by environment

Request an Engineer Assessment 

Not sure which tier fits? Run a free Security Score. It checks six categories from public data only, asks for no credentials, and the score is on screen in 60 seconds. If you want the findings mapped to a tier, book a call and a senior engineer will tell you which fits, or that none of ours do.

Pricing
Each tier is quoted per environment. Published starting prices are on the pricing page.
Incident response
Fortress SOC runs on the published SLA: a P1 incident is acknowledged within 30 minutes. Read the SLA matrix
● Trust & documentation

We write things down.

Runbooks, escalation paths, change history, vendor contacts, security policies. The reason IT outages drag on at most companies is that the person who knew how it worked isn’t in the room. We make that a non-issue.

  • Security baked into IT operations, not bolted on after the breach
  • Your external risk visible to you before it’s visible to an attacker
  • Escalation paths and IR runbooks written down, not stored in someone’s head
  • Risk reports built for the people who actually sign the budget
  • Audit attestations and partner letters shared under NDA on request
  • Plans from $175/user/month. Audits from $4,500. See /pricing.
SOC
--:--:--UTC
Online · monitoring
Detection
--:--:--UTC
Correlation live
Response
--:--:--UTC
Containment armed
Compliance
--:--:--UTC
Evidence flowing

Frequently asked

What buyers ask before they enter their domain.

Straight answers. If yours isn't here, run a Security Score and we'll follow up with the specifics for your environment.

What is the difference between an MSP and an MSSP?

An MSP runs your IT operations: helpdesk, devices, network, backups, Microsoft 365 administration. An MSSP runs your security operations: 24/7 SOC monitoring, threat detection, incident response, compliance evidence. They are not the same job. Most mid-market companies need both, which is why we do both under one contract.

Does EFROS replace our current IT provider?

Often, yes. That's usually the cleanest fit. We can also work alongside an internal team in a co-managed model where we own specific layers (security operations, Microsoft 365, system integration) and your team owns the rest. We write down where the boundary sits during onboarding so nobody has to guess later.

Can EFROS work with our internal IT team?

Yes. Co-managed engagements are common, especially in our Secure Operations and Fortress SOC tiers. We bring the security operations layer; your team keeps user-facing IT.

Is the free Security Score safe?

Yes. The Security Score is a read-only external check built from public data. We check publicly observable signals: DNS, email authentication (SPF, DKIM, DMARC), TLS, HTTP security headers, subdomain enumeration, and reputation. We do not log into anything, install agents, or run intrusive tests.

Do you need passwords or access to scan our domain?

No. The scan is entirely external and read-only. You give us a domain name. We look at what the open internet sees. No credentials, no agents, no inbound network access.

What size company is EFROS best for?

EFROS serves SMB, mid-market, and enterprise organizations. Engagement scope is driven by risk profile, workload mix, regulatory obligations, and operating requirements, not by employee headcount. Typical engagements include fully managed IT, co-managed operations alongside an internal team, vendor consolidation, executive risk reporting, and Fortress SOC coverage for higher-risk environments. The best indicator of fit is the workload (Microsoft 365, hybrid cloud, regulated data, multi-vendor stacks) and the industry vertical, not the employee count.

Do you support Microsoft 365?

Yes. Microsoft 365 administration is included in our Core IT tier. Microsoft 365 security baseline (Conditional Access, Defender XDR, Intune, DLP) is included in Secure Operations and Fortress SOC. Specific vendor partnership and credential details are released under NDA via the Trust Center.

Do you provide 24/7 monitoring?

Yes. The Fortress SOC tier includes 24/7 Security Operations Center coverage with named escalation paths and pre-authorized containment actions documented in the IR policy you sign during onboarding.

Do you help with business email compromise?

Yes. We contain compromised accounts, preserve forensic evidence, reset trust across affected systems, and harden Microsoft 365 against repeat compromise. Available as part of Secure Operations and Fortress SOC, or as a standalone incident retainer.

Do you support logistics and trucking companies?

Yes. Logistics and freight is one of our six industry verticals. We protect dispatch, ELD, GPS, TMS, accounting, VoIP, and driver communications, with specific BEC and ransomware controls relevant to the industry.

Do you offer VoIP and 3CX management?

Yes. We deploy, manage, and support 3CX phone systems including SIP trunking, mobile apps, video, and contact center. Vendor partnership documentation is available under NDA via the Trust Center. See the 3CX service page for what's included.

How fast can we start?

Typically two weeks from contract to live monitoring. Day 0 to 14 covers contract, SLA, named contacts, secure access, and any priority-1 fixes in parallel. Day 15 to 30 brings monitoring online. Full steady-state operations by Day 90. The exact path is documented at /how-we-engage.

Do you offer AI governance and US AI-law compliance?

Yes. AI Governance is a specialized program at EFROS, mapped to NIST AI RMF 1.0 and ISO/IEC 42001, plus state AI laws: Colorado SB 26-189 (the amended AI law: transparency/disclosure, effective 2027), NYC LL144, CA AB 2013, and applicable sector overlays (HIPAA, SR 11-7, CMMC). The program covers AI inventory and shadow-AI discovery, vendor risk and BAA negotiation, policy and acceptable-use enforcement, Microsoft 365 Copilot tenant configuration, and quarterly board-grade reporting. Entry engagement is a fixed-fee AI Risk Audit; recurring tiers are AI Governance Foundation and AI Governance Operations. Full detail at /services/ai-governance/.

Do you support HIPAA-regulated healthcare organizations?

Yes. Healthcare is one of our core verticals. We operate HIPAA-compliant Microsoft 365 with BAA, manage PHI Security Rule controls (administrative, physical, technical safeguards), execute BAAs with clinical AI vendors (Abridge, Suki, DAX, Heidi, MS DAX Copilot), and produce the documentation HHS-OCR examiners actually open. Healthcare-specific AI governance overlays Colorado SB 26-189 (the amended AI law: transparency/disclosure, effective 2027) and HHS-OCR Section 1557 algorithmic non-discrimination requirements. See /resources/colorado-ai-act-healthcare/ for the healthcare deployer playbook.

Do you handle CMMC Level 2 readiness for defense supply chain?

Yes. CMMC 2.0 Level 2 readiness is a defined service. We run a NIST SP 800-171 R2 gap assessment across the 14 control families, produce the System Security Plan (SSP) and Plan of Action and Milestones (POA&M), implement controls for CUI handling, federate to an authorized C3PAO for assessment, and operate ongoing evidence collection. The free CMMC Readiness Quiz at /tools/cmmc-readiness/ gives you a directional readiness score plus gap list before the formal engagement scopes a remediation budget.

Three ways to engage

Start with a free Security Score.

Sixty seconds, public data only. Then book a 20-minute call if you want a senior engineer to walk the findings with you. If you are in the middle of an incident, skip both and call the line.

  • Free scan · 60 seconds

    Your domain, scored across six categories from public data.

    Nothing installed, nothing to log into, nothing to sign.

    Categories
    Six
    Data
    Public only
    Access
    No credentials

    Run Free Security Score

    Next: enter your domain, and six category grades render on screen in about 60 seconds.

  • Engineer call · 20 minutes

    Book a 20-minute call

    A senior engineer walks the findings with you and says what matters first. No commitment, no pressure to sign anything.

    Next: pick a slot on the calendar and get an invite. Bring your score if you have one.

  • Incident line · 24/7

    Active incident? Call now

    Call the emergency line: +1 (765) 888-8888

    Ransomware, a taken-over mailbox, a wire that went to the wrong account. Call first, read second.

    Next: the line is open 24/7, or request a callback and we call back within 30 minutes. The page covers the first minutes: disconnect but do not power off, stop touching the system, do not pay yet.