SOC monitoring online Response SLA · < 15 min Status · All systems nominal
CMMC · NIST · HIPAA aligned EST · 09:00 – 18:00
Cyber security for SMBs · Est. 2001

Threats don't wait for
business hours. Neither do we.

ZDT delivers enterprise-grade cyber security for small and medium businesses — monitoring your network, patching what breaks, and responding when it matters, for a flat monthly fee.

No long-term contracts Flat monthly pricing Real humans, not bots
Live SOC feed · Simulated
--:--:--
14:02:11OKendpoint-07 · policy sync↗
14:02:18WARNfirewall · repeated auth from 91.203.*.*↗
14:02:24BLOCKphishing · inbound mail w/ spoofed domain✕
14:02:33OKbackup-primary · 1.4 TB verified↗
14:02:41OKmfa · challenge succeeded · j.reyes↗
14:02:52WARNpatch · 3 workstations 11 days behind↗
Endpoints
47 monitored
Threats / 24h
128 blocked
Uptime / 30d
99.98%
Cyber security for SMBs

The security partner
your insurer wishes
you'd already hired.

We reduce cyber risk for small and medium businesses — and document it in a way your auditors, insurers, and board will accept on the first pass.

Operating since
2001
Over two decades protecting regional SMBs.
Clients protected
180+
From 5-seat firms to 250-seat operations.
Mean response
11m
From alert to human on the keyboard.
Client retention
96%
Of clients renew after year one.
Cyber risk self-check · 60 seconds

Is your business
an easy target?

Answer five questions and we'll tell you — in plain English — where your cyber posture probably breaks. No email required until you want the full report.

No credit card No sales call Free risk scorecard

Quick risk check

Click the statements that describe your business today.
Trusted by operators in
Law
Healthcare
Realty
Logistics
Accounting
Retail

Attackers don't skip you because you're small. They pick you because you are.

Ransomware is targeting SMBs

SMBs are now the primary target because defenses are typically weaker and payouts are still worthwhile to attackers.

SMB share of ransomware victims · 43% and growing

One phishing email is enough

The majority of SMB breaches start with a well-crafted email and a busy person clicking the wrong link on a Tuesday.

Of breaches start with email · 83%

Dwell time is the killer

The longer an attacker is in the network unnoticed, the bigger the bill. Most SMBs detect intrusions in weeks, not minutes.

Median dwell time · 21 days for unmonitored networks

Six capabilities, one point of contact — wrapped into a flat monthly fee.

01 /
Risk Assessment
A guided audit of your people, devices, accounts, and network — with a written report that your insurer and board can read.
from $1,800
02 /
Managed Detection & Response
24/7 monitoring of endpoints, email, and identity — with a human on the keyboard within 15 minutes of a real alert.
from $24 /seat/mo
03 /
Identity & Access Hardening
MFA rollout, role review, privileged-account cleanup, and offboarding automation — the layer that stops most breaches.
from $3,500
04 /
Phishing Training & Simulation
Quarterly simulations with plain-English coaching for users who click — not shaming dashboards your team will ignore.
from $6 /seat/mo
05 /
Backup & Recovery Engineering
3-2-1 backups, immutability, and quarterly tabletop restores — because an untested backup is a story, not a control.
custom
06 /
Compliance & Insurance Readiness
Evidence packages for cyber insurance renewals, CMMC, HIPAA, and NIST CSF — drafted the way underwriters want them.
from $4,800

Three plans. No surprise invoices. Cancel with 30 days' notice.

Essentials
$18/seat/mo
For 5–25 seat teams starting from zero. The layer your cyber insurer will actually ask about.
  • Managed endpoint protection
  • Email & identity monitoring
  • Quarterly phishing simulation
  • Monthly written report
  • 24/7 SOC response
  • Compliance evidence package
Start with Essentials
Regulated
Custom
For firms operating under HIPAA, CMMC, SOC 2, or a strict cyber insurance rider.
  • Everything in Managed
  • Dedicated security engineer
  • Evidence package & audit support
  • Quarterly tabletop exercise
  • Vendor & vCISO liaison
  • Executive & board reporting
Talk to a specialist

What reducing risk actually looks like.

From first call to continuous protection, in four steps.

Step 01 · 30 min

Discovery call

A plain-English conversation about your business, your data, and what you are already doing. No pitch deck.

Step 02 · 7 days

Risk assessment

A written scorecard of your current posture against NIST CSF — so the plan is based on evidence, not guesswork.

Step 03 · 2–4 weeks

Stabilize

We close the top five findings first — MFA, backups, email, endpoints, offboarding — before anything else.

Step 04 · Ongoing

Protect & report

24/7 monitoring, monthly reports your leadership team will actually read, and a quarterly strategic review.

Questions business owners actually ask.

We're too small to be a target — aren't we?+
The opposite is true. Automated attacks don't know you're small; they scan for open ports, weak passwords, and unpatched systems. Attackers preferentially target SMBs because defenses are typically weaker and payouts still justify the effort.
How is this different from my IT provider?+
Your IT provider keeps things running. We assume something will eventually break, and we plan for the day an attacker is already inside. The two jobs complement each other — we work alongside existing IT, not instead of it.
Will this help with our cyber insurance renewal?+
Yes. Most of our clients see their cyber insurance premiums hold flat or decrease at renewal once our evidence package is attached to their application. We draft it in the format underwriters want.
Do you require long-term contracts?+
No. All managed plans are month-to-month after an initial 90-day stabilization period. You can cancel with 30 days' notice.
What happens when something actually goes wrong?+
A ZDT engineer is on the line within 15 minutes of a validated alert, 24/7. We contain first, notify you, then work the incident until resolution — and produce a written post-mortem your insurer can keep on file.
Do you work with companies outside the US?+
We primarily serve North American SMBs. For clients with international offices or remote staff abroad, we can support covered seats — ask us about scoping.

A studio-sized team doing enterprise-grade work.

ZDT L.L.C. has been helping small and medium businesses defend themselves since 2001. We started because we kept watching local firms get breached, pay to recover, and then get breached again — because their existing providers treated security as an afterthought.

We stay small on purpose. When you hire ZDT, you hire the senior engineer who will be handling your incident at 2 a.m. — not a rotating account manager who read about your business the morning of the call.

Get a free, no-obligation cyber risk scorecard for your business.

30-minute call, no sales deck, and a written scorecard you can keep whether you hire us or not.

Send a note, or pick a time.

Send us a note

We respond within one business day. For active incidents, call 571-969-3390.

We'll only use this to reply to your inquiry. No marketing lists, no third-party sharing.

✓ Message received — expect a reply within one business day.

Or book a 30-minute call

Pick any open slot. You'll get a calendar invite immediately.
Free 30-min risk assessment — book this week Book now →
Tweaks