The size where “managed cybersecurity” gets confusing
At roughly twenty-five people, most companies sit in an awkward middle. You are big enough that ransomware or a hijacked Microsoft 365 / Outlook setup would hurt for real. You are still small enough that hiring a dedicated security person is hard to justify, and “building a 24/7 security war room” is marketing you should ignore.
So the market fills the gap with a phrase: managed cybersecurity. Some providers mean a maintained set of protections. Others mean a dashboard and a quarterly PDF. A few mean a promise of around-the-clock watching they do not actually staff. If you cannot tell which one you bought, you do not have security—you have a line item.
This article is the owner version. For a company around that size, managed cybersecurity should mean a named team owns a defined set of protections, keeps them current, and can explain in plain English what is covered and what is not. That is the core of how we run managed cybersecurity at PrimeTech, including work scoped for small businesses without a security department.
What you are buying (and what you are not)
Honest scope first. A managed security setup for a twenty-five-person company is not an enterprise monitoring center. It is not a claim of 24/7 eyes on every alert. Those services exist, and some organizations need them. Most shops at this size need something more boring and more useful: strong passwords and multi-factor login (MFA), protection on each computer, safer email, regular updates, backups, records you can actually find later, and a cleaner Microsoft 365 setup—owned by someone who will still be answering the phone next quarter.
What you should expect from a serious engagement:
- A written list of users, computers, and admin accounts
- Protections installed and checked, not just licensed
- A review cadence (monthly or quarterly by plan) with open gaps, owners, and dates
- Clear “who to call” during the engagement—for what, and how fast you should expect a response
- Answers you can show an insurer, a customer, or a bank without inventing them
What you should not expect: theater. If a proposal leans on “always-on monitoring” language without describing who watches alerts, how often, and what happens on a Tuesday at 2 a.m., treat that as a red flag.
The protections, one by one
For a twenty-five-person shop—typically Microsoft 365 / Outlook, a mix of laptops, maybe a server or two, and a Wi‑Fi / firewall someone set up years ago—these are the pieces that matter.
1. Passwords, logins, and MFA
Most losses at this size still start with a password. Shared admin accounts, former employees who still have access, and MFA that was “rolled out” to half the company are the usual pattern. Managed cybersecurity starts by listing accounts, cleaning admin access, and turning on multi-factor authentication where it blocks the common failures: email, remote access, and admin roles.
You should be able to answer: who has admin rights, who left last year, and whether MFA is on for every account that can touch mail or finance systems.
2. Protection on each computer
Consumer antivirus and expired trials are not a plan. Business-grade protection on every workstation and server—with coverage you can count against your computer list—is. The point is not a fancy brand name. The point is settings that help stop ransomware, and proof the software is actually installed where people work.
3. Safer email and phishing defense
At twenty-five people, the inbox is still the front door. Filtering, settings that stop outsiders from easily faking your email address, and practical guidance beat annual training videos nobody watches. Managed cybersecurity treats email as a control problem: reduce what reaches the user, and make the remaining clicks less catastrophic because logins and computers are already hardened.
4. Updates and patching
Windows, browsers, and common business apps fall behind when nobody owns the schedule. A managed setup puts updates on a cadence, documents exceptions instead of ignoring them, and prioritizes anything reachable from the internet. You do not need a full “vulnerability program” on day one. You do need fewer unpatched machines with open remote access.
5. Backup and recovery readiness
Cloud sync is not a ransomware recovery plan. OneDrive and SharePoint help day to day; they do not automatically give you clean, tested restores after a virus encrypts your files. Managed cybersecurity includes backups of critical data and email, plus periodic restore tests so recovery is a fact you can describe—not a hope after the worst Tuesday of the year.
6. Records and visibility (without pretending you run a war room)
Useful logs should be kept where they help investigations, insurance questions, and “what happened last week?” conversations. That is visibility. It is not 24/7 monitoring. Mixing the two is how buyers get sold a story and receive a dashboard. An honest provider will say how often alerts and basic upkeep are reviewed, and what gets escalated during business hours.
7. Microsoft 365 / Outlook hardening
For most twenty-five-person companies, Microsoft 365 is the real network. Safer defaults, smarter sign-in rules, cleaner mailboxes and SharePoint, and tighter admin habits matter more than a new firewall sticker. If your provider cannot talk specifically about your Microsoft 365 setup, they are managing slogans, not your environment.
8. Reviews and evidence
Protections decay. People leave. Laptops get replaced without the security software. Managed cybersecurity includes a living list of gaps and a review rhythm that matches the plan—quarterly at a minimum for many shops, monthly when the risk or customer pressure is higher. The output should be short enough that an owner will read it.
How this differs from Managed IT
Managed IT keeps the business running: help desk, computers, Wi‑Fi and printers, Microsoft 365 / Outlook day to day, and the tickets that never stop. Managed cybersecurity focuses on the protection stack and security upkeep. Many companies need both. Plenty of local shops start with Managed IT that already includes meaningful security work, then deepen the stack as customers or insurers ask harder questions.
If a vendor uses the words interchangeably, ask them to list the protections they own versus the tickets they answer. The answers should not be the same paragraph.
What “good” looks like at ~25 people
Picture a professional services firm, a specialty contractor, a small manufacturer, or a healthcare-adjacent office. Roughly two dozen users on Microsoft 365. One or two people who “handle IT” in addition to their real jobs. An insurer questionnaire that arrived last month. A customer that asked whether MFA and backups are in place.
In that shop, good managed cybersecurity looks like this after onboarding:
- Every user account has MFA; shared passwords for admin roles are gone
- Protection on each computer matches the laptop and server inventory
- Email filtering and anti-spoofing settings are on, and someone owns exceptions
- Updates run on a schedule; critical internet exposure is closed or documented
- Backups exist for the systems that would stop the business, and a restore has been tested
- You have a one-page summary you can hand to an insurer without guessing
None of that requires a war room. It requires ownership.
Pricing and plans, without the fog
At PrimeTech, the managed security stack is packaged as Covered, Protected, and Managed—flat per-person monthly rates scoped around the protections above. Covered focuses on the essentials (protection on each computer, updates, MFA support, email filtering). Protected adds tested backups, quarterly reviews, and network upkeep. Managed adds a tighter review cadence, help with compliance paperwork, and priority response. Details live on the managed cybersecurity page; the point here is the structure: you should know what tier buys which protections.
Onboarding for most environments is measured in weeks, not quarters: inventory, priority gaps, deploy the stack, document who to call. If a provider needs six months to “assess” a twenty-five-person Microsoft 365 setup before touching MFA, you are funding a process, not an outcome.
Questions to ask any provider
Before you sign, force specificity:
- Which protections do you install and maintain, by name?
- How do you verify coverage—license counts, or software checked against your computer list?
- Do you run overnight monitoring as a real service, or are you managing a protection stack on a defined schedule?
- What happens when something looks wrong at night or on a weekend—honestly?
- What evidence do I get for insurance and customer questionnaires?
- How is this different from the Managed IT retainer I already have (or need)?
Vague answers are the product. Precise answers are the service.
FAQ
Is managed cybersecurity the same as a 24/7 monitoring center?
No. A full monitoring center (sometimes called a SOC) is a dedicated team watching alerts around the clock. A managed security stack is the set of protections that prevent and contain most common losses at small-business scale. Some companies eventually need both. Most twenty-five-person shops need the stack first, without pretending they bought a war room.
Do we need 24/7 monitoring at this size?
Usually not as a default purchase. You need MFA, clean logins, protection on each computer, safer email, updates, and tested backups—kept current. Continuous monitoring products can be useful later; they are a poor substitute for basics that are not finished.
How long until we are “covered”?
Most environments can be onboarded in about two weeks after a short assessment: inventory, close the highest gaps, deploy the stack, and document who to call. Perfection is not the goal. A defensible baseline with named owners is.
Can this sit alongside our existing IT company?
Often yes. Some IT companies already deliver strong upkeep; others focus on tickets and leave security as defaults. A clear split—who owns passwords and MFA, who owns backups and restore tests, who owns Microsoft 365 hardening—prevents the gap where everyone assumed someone else was watching.
Want a plain-English read on your stack?
PrimeTech deploys and maintains a practical managed security stack for businesses that cannot staff a security team—without overnight monitoring theater or 24/7 marketing claims.
Book a 15-Minute Call → Managed Cybersecurity More Insights