Cybersecurity in Santa Clarita

Santa Clarita's Own Cybersecurity

Most practices and firms in the Santa Clarita Valley do not have a security team. They have someone good with computers, a firewall set up years ago, and the antivirus that shipped with the machines. This page names every layer we run, the product behind each one, and the clause that holds us to it.

The Layers, Named

Six layers, and what each one catches.

Every provider says layered. Few will itemize it. Here is ours, in the order an attacker meets it.

1. Identity

Most small-practice breaches start with a working password, not malware. MFA and least-privilege access by default, so a front-desk account cannot reach clinical or financial systems. Catches: credential theft, password reuse, the phished login.

2. Endpoint

ESET PROTECT Elite with XDR on every managed device. Not signature matching: it watches behavior, so ransomware is caught by what it does to your files rather than by being recognized. Catches: ransomware, malware, a script doing what no user would.

3. Email

Where the attack usually arrives. Filtering for phishing, impersonation, and the invoice that looks like a vendor you use. No filter is perfect, which is why staff training sits behind it. Catches: phishing, business email compromise, the fake wire request.

4. Network

Firewalls, segmentation, secured remote access. Segmentation is what most small offices skip, and it decides how bad an incident gets: one infected workstation, or all of them. Catches: lateral movement, exposed remote access, the unmanaged device.

5. Patching

ManageEngine Endpoint Central for operating system and third-party patching and vulnerability remediation, on a schedule rather than when someone remembers. Catches: known exploits, the stale browser, the server nobody rebooted.

6. Monitoring

Core infrastructure monitoring runs 24/7 for every managed client, per SLA Section 4. Catches: the slow intrusion, the alert at 2am, the thing no rule was written for.

Backups are not a layer. They are what is left when one fails, and they live on the disaster recovery page. Evidence for these controls, a different job from deploying them, sits under compliance.

Know What You Are Buying

XDR, MDR, and which one you are being sold.

Three acronyms get used interchangeably in sales calls. The difference is who is watching.

The three, in plain words

  • EDR watches one endpoint and acts on it. Software, no human.
  • XDR correlates across endpoints, identity, and email, so three small oddities read as one attack. Still no human.
  • MDR is a staffed security operations team watching that output and responding at any hour. This is the one that costs real money, because it is people.

What we run, and where

XDR is on every managed seat in the base stack, not held back for a higher tier. MDR, the staffed layer, is included on the regulated tier, where HIPAA and FTC Safeguards make around-the-clock human response a requirement rather than an extra.

A provider quoting EDR while saying the words managed detection is selling software and describing a team. Ask which one, in writing.

That question, and seventeen more worth asking any provider in writing, are published free at Observe Adapt Protect. It names no vendors and sells nothing. Use it on us first.

Observe · Adapt · Protect

What the first hour actually looks like.

Automated containment happens in machine time. The human clock is a separate published number.

Minute 0

Detected

ESET isolates the device the moment behavior crosses the line. No 20-minute figure applies here. This is software, and it is faster than a person.

Minute 20

A person, on it

First response to a remote request within twenty minutes during Standard Business Hours, regardless of priority. A rate measured monthly from the ticketing system.

Same day

Contained

A critical security issue carries a same-business-day resolution target. Scope established, credentials rotated, entry point closed.

72 hours

Told, in writing

A known or suspected breach is reported to you within seventy-two hours of discovery. Tighter than HIPAA or FTC Safeguards require of us.

Miss a resolution target and Section 3 requires a documented plan in your hands by the end of the next business day. Credits under Section 9 are applied to the next invoice automatically, with no claim to file.

The Paper Behind It

What it costs, and what you sign.

All of it is a promise until you can check it. The pricing calculator returns a firm number for your own environment before you speak to anyone, and all six agreements are published in full. Four clauses that bear on security work:

Notify the Client of any known or suspected data breaches without undue delay, and in any event within seventy-two (72) hours of discovery.
MSA Section 10, Data Protection and Security
SecureLynx does not sell or resell hardware or software licensing; Client purchases those directly, at its discretion.
MSA Section 4, Payment Terms
Credits are calculated as part of monthly reporting and applied automatically to the next month's invoice; no request or written notice from Client is required.
SLA Section 9, Service Credits
Arbitration is expressly excluded as a form of dispute resolution.
MSA Section 19, Dispute Resolution

Read them in context rather than trusting the excerpt. The cap in MSA Section 12 rises for a data breach specifically, and the Section 9 credits carry stated caps and are the sole remedy for a missed service level. Published, because a term you find later is worse than a term you read first.

What gets protected changes the work, so we scope separately for medical and dental practices and accounting firms. These layers sit on top of the daily work under managed IT, and the dated evidence they produce is kept in your Compliance Portal.

SecureLynx Assessment

Threats Evolve. Your Defense Should Too.

Run your own numbers, read the agreements, then call. Serving the Santa Clarita Valley and Southern California.

Common Questions

Cybersecurity, answered.

What does SecureLynx's cybersecurity cover?

We work in layers: identity and multi-factor authentication, endpoint protection, email security, network controls, and monitoring, so protection does not rest on a single tool and a single failure does not open the whole environment.

Is endpoint detection and response included or an add-on?

Included. Every managed seat runs ESET PROTECT Elite with XDR (extended detection and response) as part of the base stack, not as an upsell. Above that sits managed detection and response (ESET MDR): a dedicated security operations team watching and responding on the endpoints around the clock. It is included as standard on the regulated tier, priced into that engagement rather than sold as a separate add-on, where the compliance risk calls for it.

Can you help us meet cyber-insurance requirements?

Yes. We implement and document the controls carriers ask for, including MFA, endpoint protection, tested backups, and user training, and keep the evidence organized for the questionnaire and any review that follows.

How quickly will you respond when something goes wrong?

Our SLA commits to a first response to remote service requests within twenty (20) minutes during Standard Business Hours (Monday to Friday, 8:00 AM to 6:00 PM PT), regardless of priority. From there each request is triaged: a critical outage or security issue targets same-business-day resolution, degraded performance within 24 hours, routine requests within 48 hours. If a target is missed, Section 3 requires us to put a documented resolution plan in front of you by the end of the next business day. After-hours support is provided on a best-effort basis at no additional charge, though availability is not guaranteed. Note that these are help-desk response figures. Automated detection and response runs continuously and reacts in machine time, not in minutes.

Who is actually watching the alerts overnight?

It depends on your tier, and the honest answer matters. System monitoring for core infrastructure runs 24/7 for every managed client, and ESET PROTECT Elite with XDR acts automatically on an endpoint at any hour without a human in the loop. A human security operations team watching and triaging around the clock is ESET MDR, which is included on the regulated tier. On the base managed tier, alerts that need a person are worked during Standard Business Hours and on a best-effort basis outside them.

What areas do you serve?

SecureLynx serves the Santa Clarita Valley and the surrounding region: the full San Fernando Valley, Pasadena, Glendale, Burbank, Palmdale, Lancaster, Castaic, Ventura, and the communities in between. Our SLA targets on-site response within sixty (60) minutes inside the Santa Clarita Valley; elsewhere in Southern California, on-site timing varies with distance and conditions. On-site times are stated as targets rather than guarantees, and we say so in the agreement rather than only on the website.