Questions answered

IT and cybersecurity questions, answered plainly.

28 of the questions business owners search for most, with short, practical answers and links to deeper guides and services.

Reviewed October 11, 2026

Managed IT and IT support

How managed service providers work and what to expect from outsourced IT.

What is a managed service provider (MSP)?

A managed service provider is an outside company that takes ongoing responsibility for some or all of an organization's IT—typically help desk support, device and server management, monitoring, patching, security tools, backup oversight, and technology planning—for a recurring fee.

Unlike a technician you call only when something breaks, an MSP works under a written agreement that defines scope, response targets, and responsibilities, and it aims to prevent problems rather than just fix them.

What are managed IT services?

Managed IT services are ongoing IT functions delivered by a provider under a service agreement. Common services include user support, monitoring and maintenance of computers and servers, Microsoft 365 or Google Workspace administration, cybersecurity, backup and recovery, network management, vendor coordination, and IT strategy.

The exact services, hours, and response targets vary by provider and plan, so compare written scope rather than marketing labels.

What does an MSP do day to day?

On a typical day an MSP answers support requests, watches monitoring alerts, applies updates, checks backup results, manages user accounts, and investigates security alerts. Over the longer term it documents the environment, manages vendors and renewals, and helps leadership plan budgets, upgrades, and security improvements.

What is the difference between IT support and managed services?

Traditional IT support is usually reactive: you call when something breaks and pay for the time. Managed services are proactive: the provider monitors, maintains, and secures systems continuously for a predictable fee, with defined response targets and regular reporting.

Many businesses move from break-fix support to managed services when technology downtime, security requirements, or growth make reactive support too costly or risky.

How much does IT support cost for a small business?

Cost depends on the number of users and devices, the services included, security requirements, onsite needs, and compliance obligations. Managed IT is commonly priced per user or per device each month, while break-fix support is billed hourly.

Compare proposals by what is included—security tools, backup, after-hours coverage, and projects—rather than headline price alone.

Phishing and email security

Recognizing, reporting, and recovering from phishing and email fraud.

What is phishing?

Phishing is a type of cyberattack in which criminals impersonate a trusted person or organization to trick someone into revealing passwords, opening malware, or sending money. It most often arrives by email, but also by text message (smishing), phone call (vishing), collaboration apps, and QR codes.

Many phishing messages lead to a fake sign-in page that captures credentials, so a single click can lead to a compromised business account.

How do you spot a phishing email?

Look for pressure and anything unexpected. Common signs include urgency or threats, a sender address that does not match the display name, links whose destination differs from the text, unexpected attachments or shared documents, requests for passwords or MFA codes, and changes to payment or banking details.

Polished writing is no longer proof a message is genuine. When in doubt, verify through a known phone number or by going to the website directly.

How do I report a phishing email in Outlook or Gmail?

In Outlook, select the message, choose Report, then Report phishing. In Gmail, open the message, select the three-dot More menu, then Report phishing. Reporting removes the message and helps filters block similar emails.

At work, also follow your organization's reporting process so IT can check whether anyone else received it and block the sender. You can additionally forward phishing to reportphishing@apwg.org and report fraud to the FTC at ReportFraud.ftc.gov.

What is phishing over the phone or by text called?

Phishing by phone call or voicemail is called vishing (voice phishing). Phishing by text message is called smishing (SMS phishing). Both aim to get passwords, MFA codes, payments, or remote access, often by impersonating IT support, banks, delivery services, or executives.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard published as a DNS record. It tells receiving mail servers what to do with messages that claim to come from your domain but fail SPF or DKIM checks—deliver, quarantine, or reject—and sends reports showing who is sending as your domain.

DMARC makes it harder for criminals to spoof your domain and helps legitimate mail reach the inbox.

What is the difference between SPF, DKIM, and DMARC?

SPF lists the servers allowed to send email for your domain. DKIM adds a cryptographic signature that proves a message was authorized and not altered. DMARC ties them together by checking that SPF or DKIM aligns with the visible From domain and telling receivers how to handle messages that fail.

All three are published as DNS records and work best together.

Passwords and multifactor authentication

Protecting accounts with MFA, passkeys, and modern password practices.

What is multi-factor authentication (MFA)?

Multi-factor authentication requires two or more types of proof to sign in: something you know (a password or PIN), something you have (a phone, authenticator app, or security key), or something you are (a fingerprint or face). A stolen password alone is then not enough to access the account.

MFA is one of the most effective protections for email, remote access, and cloud applications.

What is phishing-resistant MFA?

Phishing-resistant MFA uses authenticators—such as FIDO2 security keys and passkeys—that cryptographically verify the real website before responding. A fake sign-in page cannot capture a code or credential it can reuse, unlike SMS codes or one-time passcodes that can be relayed by attackers.

What is MFA fatigue?

MFA fatigue, or push bombing, is an attack in which someone who already has a user's password sends repeated MFA approval prompts until the user taps approve to make them stop. Number matching, phishing-resistant methods, and training users to deny and report unexpected prompts reduce the risk.

How often should business passwords be changed?

Current NIST guidance recommends against forcing routine password changes on a fixed schedule. Instead, require long, unique passwords, screen them against known breached passwords, use MFA, and require a change when there is evidence or suspicion of compromise.

Firewalls, endpoints, and detection

What common security technologies do and how they fit together.

What is a firewall and what does it do?

A firewall is a security device or software that controls network traffic based on rules, allowing approved connections and blocking others. A business firewall sits between the office network and the internet and often also provides VPN access, intrusion prevention, web filtering, and separation between internal network zones.

A firewall needs current firmware, reviewed rules, and monitoring to stay effective.

What is endpoint security?

Endpoint security protects the devices people use—laptops, desktops, servers, and mobile devices—from malware, misuse, and data loss. It typically combines antivirus or endpoint detection and response, encryption, device management, patching, and controls on administrator rights.

What is EDR in cybersecurity?

EDR (endpoint detection and response) is security software that records activity on computers and servers, detects suspicious behavior, and gives responders tools to investigate, isolate devices, and remove threats. It goes beyond traditional antivirus, which mainly blocks known malicious files.

EDR is most effective when someone monitors and acts on its alerts, which is what managed detection and response (MDR) provides.

What is the difference between EDR and XDR?

EDR focuses on endpoints such as laptops and servers. XDR (extended detection and response) correlates signals from endpoints plus other sources—email, identity, cloud applications, and sometimes the network—to detect attacks that move across systems.

Ransomware, backup, and recovery

Preventing ransomware and recovering data when something goes wrong.

How do you prevent ransomware attacks?

No single control prevents every attack, but layered safeguards greatly reduce the risk: MFA on email and remote access, prompt patching of internet-facing systems, monitored endpoint detection and response, email filtering, least-privilege access, network segmentation, and employee training.

Just as important, keep isolated or immutable backups and test restores so the business can recover if prevention fails.

What should you do if you get ransomware?

Disconnect affected devices from the network without powering them off, then contact your IT or incident response provider, cyber insurer, and legal counsel. Preserve evidence, report the incident to the FBI through IC3 and to CISA, and restore only from backups confirmed to be clean after the entry point is closed.

What is cloud backup?

Cloud backup copies business data from servers, computers, or cloud applications to a provider's secure storage, giving an offsite copy that survives local hardware failure, theft, or disaster. Good cloud backup includes encryption, MFA-protected management, immutable retention, and tested restores.

Does Microsoft back up my Microsoft 365 data?

Microsoft keeps the Microsoft 365 service resilient and provides recycle bins and retention policies, but those are not the same as an independent backup. Customers remain responsible for protecting their data against deletion, ransomware, and account compromise beyond the native retention windows.

Cyber insurance and compliance

Insurance coverage and the security frameworks small businesses ask about most.

What is cyber insurance and what does it cover?

Cyber insurance helps businesses manage the financial impact of security incidents. Policies commonly cover first-party costs—such as incident response, data restoration, and business interruption—and third-party costs, such as liability and regulatory defense. Some policies also address extortion and funds-transfer fraud.

Coverage, limits, exclusions, and required security controls vary widely, so review the policy with your broker.

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense program that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Requirements are being phased into DoD contracts, and the required level depends on the information a contractor handles.

What are CMMC Level 1 and Level 2?

Level 1 (Foundational) applies to contractors handling only FCI and covers 15 basic safeguarding requirements, verified by an annual self-assessment. Level 2 (Advanced) applies to contractors handling CUI and aligns with the 110 requirements in NIST SP 800-171, verified by self-assessment or a third-party assessment depending on the contract. Level 3 adds requirements for the most sensitive programs.

What is HIPAA compliance?

HIPAA compliance means meeting the requirements of the HIPAA Privacy, Security, and Breach Notification Rules for protecting patient health information. For IT, the Security Rule requires administrative, physical, and technical safeguards for electronic protected health information, starting with a documented risk analysis.

Free IT & cybersecurity assessment

Understand your priorities before IT and security problems become expensive.

Start with a no-obligation conversation about your technology, Microsoft 365 environment, backup readiness, and material cybersecurity concerns.

  • Preliminary security and IT review
  • Microsoft 365 configuration discussion
  • Backup and recovery-readiness review
  • Prioritized next-step recommendations

By submitting, you ask Meta IT Pro to contact you about this request and acknowledge our Privacy Policy. Do not include passwords, authentication codes, financial details, medical records, or other sensitive information.