Answers
Frequently asked questions
Everything we get asked, in one place. Grouped by service, industry, and city. Jump to a section:
Managed IT — questions we get
- How quickly do you actually respond?
- A human tech on our team picks up or replies within 15 minutes during business hours (7am–7pm local). Off-hours P1 incidents route to an on-call engineer.
- Is backup and cybersecurity included, or extra?
- Included on every plan. EDR, MDR, managed backup, and phishing awareness training are baseline — not upsold at incident time.
- Can we keep our current apps?
- Yes. We support whatever's in your environment — line-of-business apps, industry software, custom in-house tools. We'll flag things that are risky to keep, but the choice is yours.
- Do you replace our IT vendor or work alongside them?
- Both models work. If you already have internal IT, see the Co-managed IT service, which is designed to plug into an existing team.
- What is the minimum contract length?
- 12-month initial term, then month-to-month with 30 days' notice to cancel. No auto-renewal locks.
- How do you handle on-site work?
- Included in-city for Tucson and Minneapolis clients — we have local techs in both metros. Regional on-sites are billed at cost.
Cybersecurity — questions we get
- What is the difference between EDR and MDR?
- EDR is the tool that watches an endpoint for suspicious behavior. MDR is the humans — SOC analysts — watching the EDR alerts 24/7 and responding. Tool without humans is a dashboard nobody's reading.
- Are you HIPAA-compliant?
- We operate a HIPAA-aligned environment and sign Business Associate Agreements (BAAs) with covered entities. Formal compliance is your organization's posture; we make it achievable.
- What happens if we get hit?
- Documented incident response runbook. Containment goal within 4 hours, forensic partner on retainer, cyber insurance carrier notification support, breach-counsel intro if needed.
- Do you handle SOC 2 audits?
- We prepare and evidence controls, and coordinate with the audit firm. Formal opinion is issued by an independent CPA firm — we're not that firm.
- How is this different from just buying a firewall?
- Firewalls block traffic at the perimeter. Modern attacks arrive via phishing, credential stuffing, and supply chain — none of which a firewall stops. This is defense in depth: identity, endpoint, user behavior, monitoring, response.
- Do you sell cyber liability insurance?
- No — we're not brokers. We can introduce you to insurance partners we trust in AZ and MN who understand IT-heavy risks.
Microsoft 365 — questions we get
- How long does a Google Workspace → M365 migration take?
- Typically 2–4 weeks end-to-end for under 50 users, from kickoff to cutover. The cutover itself happens over a weekend so weekday productivity is unaffected.
- Will users lose emails or calendar events?
- No. We use coexistence during the transition, then run delta syncs at cutover so any last-minute email arrives cleanly. We've done dozens without a lost message.
- Do you handle Microsoft licensing?
- Yes. We can sell licensing via Microsoft CSP, or manage your own tenant if you prefer. We recommend the mix that costs least for your actual usage — often that means downgrading someone from E3 to Business Standard.
- What about Intune device management?
- Included in setups where MDM is needed. Baseline policies for Windows and macOS, BYOD-friendly configuration, iOS/Android for corporate email.
- Is backup really needed for M365?
- Yes. Microsoft retains deleted items 30–90 days depending on the item type, then they're gone forever. Third-party backup (Veeam, Datto, or similar) retains years.
- Do you support SharePoint and Teams governance?
- Yes. Information architecture, permission models, external sharing policies, and Teams sprawl controls — the boring stuff that keeps M365 usable at 100+ users.
Co-managed IT — questions we get
- Will you make our internal IT person obsolete?
- No. Co-managed exists to make them more effective, not to replace them. Their tickets, their roadmap, their org chart — we just bring the bench.
- How do escalations work?
- Documented criteria — hardware failure, security incident, migration project, etc. Your team ships us the ticket via a shared queue; we own resolution and report back with root cause.
- Can we use your security tools without full managed IT?
- Yes, that's the most common co-managed configuration. You keep the help desk in-house; we run EDR, MDR, backup, and awareness training on your endpoints.
- What happens if our IT person quits?
- We can bridge coverage while you hire, then hand back to the new person with full documentation. Some clients convert to fully Managed IT during the gap and stay there.
- Do you cover after-hours P1 only, or all after-hours?
- Configurable. Most clients do P1-only after 6pm; some do full evening coverage for retail hours; a few do 24/7. You pick the SLA that matches your business.
- Who owns the roadmap?
- Your IT leader. We provide input from our other clients and vendor conversations, but you make the calls.
Server Management — questions we get
- Do you support Windows Server and Linux?
- Yes to both. Windows Server 2016 through 2025, and RHEL/CentOS/Rocky/Ubuntu/Debian on the Linux side. We'll flag what's at end-of-life.
- What about VMware vs Hyper-V?
- Both. We also support Proxmox and bare-metal hypervisors on request. Post-Broadcom VMware licensing changes are pushing many clients to Hyper-V or Proxmox — we help evaluate.
- Do you cover cloud instances (Azure, AWS, GCP)?
- Yes — IaaS server management across all three major clouds. IAM, patching, backup, monitoring, cost review.
- What's your patching approach?
- Test/prod separation, monthly cadence, always with a rollback plan. Emergency patches (critical CVEs) go same-week after test.
- How often do you test backups?
- Monthly restore tests. If the backup doesn't restore cleanly, we treat it as no backup and file a ticket to fix.
- Do you replace failed hardware?
- We coordinate replacement (warranty claim or purchase), handle the rebuild, and validate the restore. On-site hands are included for Tucson and Minneapolis.
Healthcare IT — questions we get
- Do you sign BAAs?
- Yes. We sign Business Associate Agreements with every clinic client and maintain BAAs with our own downstream vendors (Microsoft, Google, backup providers). We'll walk your auditor through the chain.
- Can you support our EMR?
- Yes — we work alongside the EMR vendor on the IT layer (network, endpoint, identity, backup, escalations). We won't reconfigure clinical workflows in the EMR itself; that stays with your EMR vendor and your compliance officer.
- What happens if we have a breach?
- Our documented IR runbook covers containment within 4 hours, forensic partner engagement, breach counsel intro, and the 60-day HIPAA notification timeline. We help you meet the deadline, not blow past it.
- Are you HITRUST-certified?
- We are not. HITRUST certification is an organization-level attestation; we operate a HIPAA-aligned environment and can produce evidence for your own compliance framework, but the formal certification stays with your organization.
Dental IT — questions we get
- Do you know Dentrix / Eaglesoft?
- Yes. We handle the server, database, backup, and workstation side. Chairside workflow questions still go to your practice management vendor, but we coordinate the escalation.
- Can you patch during the day?
- No — practices lose money when systems restart mid-appointment. Patches run after 6 PM local, with rollback ready, so open-of-business the next morning is normal.
- What about imaging hardware?
- We support the workstation, drivers, and network side of digital imaging. Sensor hardware issues escalate to the imaging vendor, but we coordinate and stay involved until it's working.
- Do you handle multi-office practices?
- Yes. Standardized environments across offices, centralized identity, and shared reporting so leadership sees one view instead of one per site.
Legal IT — questions we get
- Do you support Clio / MyCase / PracticePanther?
- Yes — we handle the environment side (identity, endpoint, network, backup). Workflow questions in the platform go to the vendor, but IT integration is our lane.
- Can you help with cyber insurance renewals?
- Yes. We'll fill out the technical portions of your carrier's questionnaire, provide evidence of controls, and flag gaps before you submit. This is one of the highest-value things we do for law firms.
- How do you handle privileged information?
- Our team signs confidentiality obligations. Access to your systems is role-based, logged, and reviewed. We can produce audit trails on demand.
- What if we get hit?
- Documented IR runbook, containment goal within 4 hours, forensics partner on retainer, breach counsel intro. Cyber carrier notification support so you don't blow the policy.
Tucson, AZ — questions we get
- How fast do you respond to Tucson clients?
- A technician on our team picks up the phone within 15 minutes during business hours (Mon–Fri, 8am–6pm MST). Emergency issues route to on-call staff 24/7.
- What businesses in Tucson do you serve?
- We work best with small and mid-size businesses (10–200 employees) across Pima County — professional services, healthcare, dental practices, and light manufacturing especially.
- Do you visit client sites in Tucson?
- Yes. Every plan includes on-site visits for hardware installs, office moves, and issues that need hands-on work. Remote-first for speed, on-site when it matters.
- Are you HIPAA-ready for Tucson medical practices?
- Yes. We build HIPAA-aligned environments for dental practices, small clinics, and specialty providers, and can walk auditors through the controls.
Minneapolis, MN — questions we get
- How fast do you respond to Twin Cities clients?
- A technician on our team picks up the phone within 15 minutes during business hours (Mon–Fri, 8am–6pm CST). Emergency issues route to on-call staff 24/7.
- What businesses in Minneapolis do you serve?
- Small and mid-size businesses (10–200 employees) across the Twin Cities — professional services, dental, small clinics, and manufacturing.
- Do you visit client sites in Minneapolis and Saint Paul?
- Yes. Every plan includes on-site visits across Hennepin and Ramsey counties for installs, office moves, and hands-on work.
- Do you handle after-hours support for Minnesota businesses?
- Yes. 24/7 emergency support is included on every plan — you get a real technician, not a queue.
Ready to make IT boring again?
Book a 20-minute intro call. We'll tell you within that call whether we're a fit.