1 min read
What Phoenix Small Businesses Should Expect from a Local IT Partner
Phoenix runs on small businesses. Nearly all of Arizona's companies, 99.5 percent according to the SBA Office of Advocacy, qualify as small...
4 min read
Jordan Hetrick
:
September 23, 2026
Phoenix businesses shopping for managed cybersecurity services are shopping in one of the hardest-hit states in the country. Arizonans reported $630 million in cybercrime losses to the FBI in 2025, the sixth-highest total of any state and the third-highest per resident. Nationwide, reported losses passed $20 billion, and business email compromise cost victims more than $3 billion, second only to investment fraud.
Attackers rarely care what a Phoenix business does or how many people it employs. Microsoft's 2025 report describes most of them as opportunists who target organizations of every size. A 15-person law firm with client files and a 150-person contractor sharing a Microsoft 365 tenant look the same from the outside: a login page and a payment process. Both show up in the FBI's numbers: among 2025 ransomware complaints from businesses outside critical infrastructure, law firms (18%) and contractors (17%) topped the list.
Managed cybersecurity services provide companies with a team that monitors, patches, and responds. The quality of that team varies widely, and the difference shows up in verifiable credentials.
Phoenix businesses shopping for managed cybersecurity services are shopping in one of the hardest-hit states in the country. Arizonans reported $630 million in cybercrime losses to the FBI in 2025, the sixth-highest total of any state and the third-highest per resident. Nationwide, reported losses passed $20 billion, and business email compromise cost victims more than $3 billion, second only to investment fraud.
Attackers rarely care what a Phoenix business does or how many people it employs. Microsoft's 2025 report describes most of them as opportunists who target organizations of every size. A 15-person law firm with client files and a 150-person contractor sharing a Microsoft 365 tenant look the same from the outside: a login page and a payment process. Both show up in the FBI's numbers: among 2025 ransomware complaints from businesses outside critical infrastructure, law firms (18%) and contractors (17%) topped the list.
Managed cybersecurity services provide companies with a team that monitors, patches, and responds. The quality of that team varies widely, and the difference shows up in verifiable credentials.
Microsoft's 2025 Digital Defense Report found that extortion or ransomware drove at least 52% of attacks with a known motive, while pure espionage accounted for 4%. Most people trying to break into your network are ordinary criminals running a business model, not intelligence agencies. CISA points out that small businesses hold valuable information and often have fewer resources dedicated to security.
The same report found that more than 97% of identity attacks are password attacks, and it points to a practical fix. Phishing-resistant multifactor authentication can block over 99% of identity-based attacks. That figure holds only when someone configures it correctly, covers the administrator accounts, and watches for sign-in attempts that look wrong. A credentialed provider does that work as part of its IT security services.
Arizona's breach notification law, A.R.S. § 18-552, generally requires you to notify affected individuals within 45 days after you determine a breach occurred. If a breach requires notifying more than 1,000 people, you must also notify the three largest nationwide consumer reporting agencies, the Attorney General, and the director of the Arizona Department of Homeland Security. For a knowing and willful violation, the statute lets the Attorney General impose a civil penalty of up to $10,000 per affected individual or the total economic loss, whichever is lower, capped at $500,000 per breach or series of related breaches. The law does not apply to HIPAA covered entities and their business associates, or to businesses subject to the Gramm-Leach-Bliley Act, which carry their own federal requirements.
Forty-five days sounds generous until you spend three weeks working out which systems an attacker touched. A provider with a tested incident response process, centralized logs, and experience with notification decisions gets you answers quickly. If you select a provider without those things, you will be reconstructing events from memory with the stress of a quickly approaching deadline.
Federal agencies have warned about this directly. In a 2022 joint advisory, CISA, the NSA, the FBI, and partner agencies from the UK, Australia, Canada, and New Zealand warned that attacks on managed service providers were rising and would likely continue, raising risk for the businesses those providers support. The advisory tells providers to enforce multifactor authentication on accounts that access customer environments, and tells customers to ensure contracts clearly specify who owns which security responsibilities.
Before you sign, ask how the provider protects its own administrator accounts, and get the split of responsibilities in writing.
Start with the people. Ask which engineers will work in your environment and what certifications they hold. Ask for references from Arizona companies in your industry, since a medical practice and a manufacturer face different regulations and different attackers. Ask what happens at 2 a.m. on a Saturday: who answers, how fast, and whether that person has the authority to isolate a compromised device.
Finally, ask for the paperwork behind the promises. A written information security program, an incident response plan, a documented patching schedule, and a clear escalation path show that a provider runs a process. CISA's guidance for small businesses puts similar expectations on the owner's side: train all staff on multifactor authentication, software updates, and phishing, and keep a written incident response plan that company leaders have formally approved. A good partner helps you meet that standard and shows you where you stand today through a risk assessment.
A credentialed provider runs managed cybersecurity services as a continuous program, not a string of one-time projects.
The last piece is reporting. CISA advises that the person running your security program update company leadership at least monthly, and more often at the start. Expect a monthly summary from your provider that shows what it blocked, what it fixed, and what still needs your decision. If a provider cannot show you that, you are paying for an activity you cannot verify.
The worst time to interview a security provider is during a ransomware negotiation.
PK Tech has supported Phoenix small businesses for over 16 years. In September 2026 we completed our third consecutive SOC 2 Type II audit, examined by Insight Assurance, an independent CPA firm. If you would like to see how your current setup holds up against the questions above, contact us for an assessment.
1 min read
Phoenix runs on small businesses. Nearly all of Arizona's companies, 99.5 percent according to the SBA Office of Advocacy, qualify as small...
1 min read
Most small business owners don't think about their network until it goes down. Then, in the middle of a Tuesday afternoon with customers waiting and...
5 min read
Key Takeaways Recurring IT issues and slow systems are early warning signs. Reactive IT leads to higher costs and more downtime. Cybersecurity...