Close the Gaps Hackers Exploit
Ransomware shows up in 88% of breaches at small businesses, against 39% at large enterprises. Six straightforward controls close the gaps it comes through — and most Columbia businesses have zero of them in place.
You don’t need a massive budget or an enterprise security team to keep your business safe. You need six fundamental controls, each one designed to close a specific gap that attackers actively target.
Dealing with a problem right now? Call (803) 881-3771 — you’ll get a straight answer on whether we can help and what it would take. Not a sales pitch.
What’s at stake
What’s Actually at Stake — and What Actually Fixes It
You’re on this page because something raised a flag. Maybe your insurer asked about your security controls. Maybe a colleague got hit with ransomware. Maybe you just know your business is running on consumer-grade tools, or nothing at all.
That instinct is right. In the Identity Theft Resource Center’s 2025 Business Impact Report, which surveyed 662 executives at companies with 500 or fewer employees, 81% had suffered a breach — and 62.5% of those reported losses above $250,000.
You may have seen the claim that 60% of small businesses close within six months of a cyberattack. We’re not going to repeat it, because it isn’t true. The organization everyone credits it to publicly disavowed it, and a security researcher who went looking for businesses that actually closed because of a breach found 35 worldwide since 2001.
Here’s the honest version. Most breached businesses don’t close. They lose money, time, and client confidence, and they spend months cleaning up something a weekend of setup would have prevented. The ones that do fail share a profile: fewer than 100 employees, thin cash reserves, no tested way to restore their data, and clients who left.
The program
Six Controls. Six Gaps Closed. That’s the Whole Program.
A real cybersecurity program for a small business doesn’t look like what the big IT companies sell. Those tools have a place, but not before the basics are handled.
Multi-Factor Authentication
On every account that holds sensitive data — email, banking, accounting, practice management, cloud storage. Paired with a password manager so your team isn’t drowning in credentials.
Automatic Security Updates
Unpatched software is now the single most common way attackers get in. Patches applied when they’re released, not queued for a testing cycle that never happens.
Email Security & Training
Technical filtering in Microsoft 365 or Google Workspace, plus staff training built on education and positive reinforcement — not fake phishing tests designed to catch your employees failing.
Backup & Recovery, Tested Quarterly
Critical data backed up in two locations, tested every quarter, documented, and reported to you. A backup that’s never been tested isn’t a backup. It’s a hope.
Restricted Admin Access
Your employees don’t need the ability to install software or change system settings. Restricting admin access eliminates an entire category of problems before they start.
Your Three Core Documents
An incident response plan, a password policy, and an offboarding checklist. Who to call when something goes wrong, how your team handles credentials, and how to kill access the day someone leaves.
What we don’t do — and why it matters
We do not send fake phishing emails designed to trick your employees into clicking. That approach builds anxiety and resentment, not security. Employees stop flagging suspicious messages because they’re afraid of being the one who “failed the test.” We treat your staff like capable adults who will use their judgment when given the right information and encouragement.
Insurance
Your Cyber Insurer May Already Require These Controls
Insurers increasingly mandate specific security controls before they’ll write a policy. The requirements showing up most often are multi-factor authentication on all email and remote access, employee cybersecurity training, and tested backup and recovery procedures.
The risk isn’t just a denied claim. It’s a voided policy. When a business attests on its application that a control is in place and it isn’t, the carrier can move to rescind the policy entirely — not deny one claim, but unwind the coverage as though it never existed.
In a 2022 case, an insured attested that multi-factor authentication was deployed across its systems. After a ransomware incident, MFA was found on the firewall and nowhere else. The carrier moved to rescind a $1 million policy, and the parties stipulated to voiding it.
Nobody on that application set out to lie. They believed a control was in place because someone said it was, and nobody verified it.
What you actually get
Compliance Documentation That Exists on Paper, Not in a Sales Pitch
Most IT companies mention compliance and never deliver the documents. Every managed agreement produces real artifacts — the risk assessment, the written security plan, the incident response plan, the quarterly restore report. When a carrier audit or a regulatory inquiry arrives, the answer is already written.
Geoffrey Giles
Founder · former Virtual CIO
Why us
Built by Someone Who Managed $24 Million in Annual IT Spend — and Saw What Wasn’t Working
Soda City Systems was founded by a former Virtual CIO at a national managed IT provider, where he managed $24 million in annual IT spend across South Carolina. That role made one thing clear: as IT firms grow and get acquired, businesses with 10 to 50 employees stop getting the attention they need.
Your problems stop repeating.
Every issue we resolve gets a second look — what caused it, and what would prevent it. The businesses that have worked with us longest call us the least.
You never start over with a stranger.
You have an accountant who already knows your books. You have an attorney who already knows your contracts. Now you have an IT team that already knows your technology.
Your IT company doesn’t outgrow you.
We’re not an enterprise firm that occasionally takes a small client, and not a solo consultant who disappears for a week. Founder-operated and locally owned, built for businesses your size and only your size.
Questions
Common Questions About Small Business Cybersecurity
Do I need cybersecurity if my business only has five or ten employees?
Yes, and your size is exactly why. Attackers aren’t manually selecting targets — they run automated scans looking for systems with missing controls. A five-person business with no MFA is easier to breach than a 500-person company with a security team.
We already have antivirus software. Isn’t that enough?
Antivirus is one layer, and usually the only one small businesses have. It doesn’t cover stolen passwords, it doesn’t stop someone clicking a phishing link, it doesn’t give you a tested backup if ransomware hits, and it doesn’t restrict who can install software. If your current antivirus is configured correctly, we leave it in place and build around it.
How much does cybersecurity cost for a small business?
It’s part of our managed IT agreement, not a separate line item. The six controls are included in every managed plan because they’re non-negotiable fundamentals, not add-ons.
Does my industry have specific cybersecurity requirements?
Several do. Medical and dental practices must meet HIPAA security standards. Insurance agencies in South Carolina fall under the SC Insurance Data Security Act. Law firms have attorney-client privilege obligations. CPA and accounting firms are subject to IRS Publication 4557 and the FTC Safeguards Rule. Auto dealerships have been covered by the FTC Safeguards Rule since it took effect in 2003; June 9, 2023 was the deadline for the eight newer requirements added in 2021.
What happens if we get hit with ransomware?
That’s exactly what your incident response plan and tested backups are for. If your backups are current and tested — which ours are, quarterly — you have a clean copy of your data ready to restore. The goal is to get back up and running from a known-good backup, not to negotiate with the attacker.
Free IT walkthrough
Find Out Where Your Business Stands
Tell us about your business and we’ll walk through your current security posture together — which of the six controls you have in place, which ones you’re missing, and what it takes to close the gaps.
It takes about an hour. No pressure, no contracts, no 47-slide presentation.
Book your walkthrough
We’ll call you back within one business hour.