Managed cybersecurity | High Point, NC
Cybersecurity Services for North Carolina Businesses
Preferred Data protects North Carolina manufacturers and small businesses with 24/7 threat detection and response, multi-factor authentication, patching, email protection, staff training and backups we prove by restoring them. It is included in every managed IT plan, run from our High Point office, with on-site help within 200 miles.
- 39 years in business, since 1987
- 100+ active clients, 20+ year average tenure
- BBB Accredited, A+ rating
- 24/7 threat monitoring on every plan
- On-site within 200 miles of High Point
In every plan
The security baseline
- 24/7 threat detection and response, monitored by real people
- Multi-factor authentication
- Patching and updates
- Email threat protection
- Security awareness training
- Restore-tested backup
Security is the floor of every Preferred Data plan, not an upsell.
What do managed cybersecurity services include?
At Preferred Data, managed cybersecurity is six controls that come with every plan, including the smallest: 24/7 threat detection and response monitored by real people, multi-factor authentication, patching and updates, email threat protection, security awareness training, and backups we verify by restoring them. Nothing in that baseline is sold separately or removed to lower the price.
Detection and response runs on two layers. Endpoint detection and response (EDR) watches each computer and server for attacker behavior, not just known virus signatures, and managed detection and response (MDR) puts people behind it around the clock so an alert at 2 a.m. gets acted on, not read on Monday. Our article on why antivirus alone is no longer enough covers the difference in more detail.
Security is delivered as part of managed IT services, by the same team that patches your machines and answers your help desk calls. That matters during an incident: the team acting on an alert already knows your network, your servers and your line-of-business software.
- Preferred Essentials: the full baseline above, plus Microsoft 365 matched to each role and domain and email authentication that is locked and monitored.
- Preferred Professional: adds identity threat detection and response, an enterprise password manager, email encryption, and zero-trust VPN with DNS filtering.
- Preferred Complete: adds recurring vulnerability scanning, an annual security assessment with penetration test coordination, and compliance readiness management for CMMC and NIST 800-171.
Key takeaway: Monitoring without response means nobody acts on the alert, and backup without restore testing means you find out it failed on the worst possible day. Every plan includes both halves.
Why are North Carolina manufacturers targeted by ransomware?
Manufacturers are targeted because downtime is expensive and pressure to pay is high. The FBI reports that the most-reported ransomware strains of 2025 most impacted three critical sectors: critical manufacturing, healthcare and government facilities, and Verizon found ransomware in 48% of all breaches in its 2026 report, up from 44%.
The risk is not limited to defense suppliers or large plants. Among ransomware complaints from businesses outside the critical infrastructure sectors, the FBI lists non-critical manufacturing such as furniture and building materials at 5%, alongside contractors and engineering firms. That describes a large share of the Piedmont Triad, from furniture makers to textile mills and distribution and logistics operations.
In Verizon's 2026 data, exploitation of software vulnerabilities was the entry point for 38% of manufacturing breaches, and 87% of manufacturing breaches were financially motivated. Patching quickly and knowing what is exposed to the internet are not paperwork; they close the door attackers use most.
- More than 3,600 ransomware complaints reached the FBI in 2025, and the FBI notes the reported losses run low because many victims never report a dollar figure.
- Verizon counted 3,627 security incidents in manufacturing in its 2026 dataset, 2,713 of them with confirmed data disclosure.
- Plant floor systems (older PCs running machines, shared logins, vendor remote access) are often the weakest point. We handle OT and IT network segmentation to keep a compromised office PC away from production equipment.
Key takeaway: For a North Carolina manufacturer, ransomware is a production problem first and an IT problem second.
What security controls do cyber insurance carriers require?
Carriers now expect MFA, endpoint detection and response, and secure, tested backups before they will write or renew a policy. Insurance broker Marsh lists twelve controls insurers assess and states that adopting certain controls has become a minimum requirement of insurers, with insurability on the line.
| Control carriers assess | Essentials | Professional | Complete |
|---|---|---|---|
| Multi-factor authentication | Included | Included | Included |
| Endpoint detection and response (EDR) | Included, with 24/7 MDR | Included, with 24/7 MDR | Included, with 24/7 MDR |
| Email filtering and web security | Email threat protection | Adds email encryption, DNS filtering and zero-trust VPN | Included |
| Secured, tested backups | Restore-tested backup | Restore-tested backup | Restore-tested backup |
| Patch and vulnerability management | Patching, monitored 24/7 | Patching, monitored 24/7 | Adds recurring vulnerability scanning |
| Awareness training and phishing testing | Security awareness training | Security awareness training | Security awareness training |
The table above maps the controls on Marsh's list to the Preferred Data plan where each one is included. Whether a policy is issued, and at what price, is always the carrier's decision, so we say "built to what carriers expect", not "guaranteed insurable".
The fastest way to lose a claim is to answer "yes" on an application for a control that is only partly deployed, such as MFA on email but not on remote access. We document what is in place so your application matches reality. Our cyber insurance renewal playbook walks through the questions carriers ask.
Key takeaway: MFA, EDR and tested backups are three of the controls insurers assess, and all three are in every Preferred Data plan. Marsh also lists privileged access management, incident response planning and testing, remote desktop hardening, logging and monitoring, end-of-life systems and supply chain risk, which the standard plans do not list; ask us how they apply to your environment.
Do North Carolina defense contractors need CMMC in 2026?
Yes, if you hold or bid on Department of Defense contracts that involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC contract requirements took effect on November 10, 2025; the next phase, which would have required third-party certification for most CUI work, was suspended on July 13, 2026, and a September 3, 2026 class deviation now directs contracting officers to remove CMMC third-party assessment requirements from contracts while the program is reviewed. Self-attestation of NIST compliance is still required.
The CMMC program rule sets levels by the information you handle. Level 1 covers FCI and means meeting the 15 basic safeguarding requirements in FAR 52.204-21, with an annual self-assessment posted in the Supplier Performance Risk System (SPRS). Level 2 covers CUI and means meeting the 110 requirements of NIST SP 800-171 Rev 2.
What the suspension did not change matters more than what it did. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 and SPRS score submissions all remain in effect. A reform task force report was due to the DoD CIO on September 11, 2026 and had not been made public when this page was last verified. Our CMMC Phase 2 suspension briefing and Level 1 self-assessment guide go further.
- Preferred Complete includes compliance readiness management for CMMC and NIST 800-171: ongoing monitoring, documentation and evidence collection. It is also available as an add-on to Preferred Professional.
- We prepare you for the assessment. A CMMC certification is issued by an accredited third-party assessor (C3PAO) or recorded through your own self-assessment, never by your IT provider.
- If only part of your business touches CUI, scoping the assessment to that part can reduce cost. We plan that with you before any spending.
Key takeaway: The pause is on outside certification, not on the security controls. Contracts that include DFARS 7012 still require NIST 800-171 and an SPRS score today.
What does a breach cost, and how does 24/7 monitoring help?
IBM puts the global average cost of a data breach at $4.99 million in 2026, a 12% increase over the prior year and a record high. Around-the-clock detection and response shortens the time an attacker has inside your network, which is where most of that cost builds.
Paying the ransom is less common: in Verizon's 2026 data, 69% of ransomware victims did not pay, and the median payment among those who did was $139,875. Recovering without paying depends on backups the attacker could not reach, which is why ours are tested by actually restoring them. See backup and disaster recovery and our guide to testing your backups.
People are still the most common way in. Verizon found the human element in 62% of breaches, which is why security awareness training is in every plan rather than an add-on.
- 24/7 threat detection and response is in every plan. 24/7 help desk support (after hours and weekends) is part of Preferred Complete; Essentials and Professional have business-hours and extended-hours help desk support.
- Backups cover workstations and Microsoft 365, and restores are tested, not assumed.
- Third parties were involved in 48% of breaches in Verizon's 2026 report, so vendor remote access and shared accounts get the same MFA and monitoring as your own staff.
How is Preferred Data different from a national security provider?
We are a local company that has served North Carolina businesses since 1987, with more than 100 active clients whose average tenure is over 20 years. When something needs hands, an engineer from High Point can be on site anywhere within 200 miles, including the Piedmont Triad, Charlotte and Raleigh.
National providers often sell security as a tool plus an alert queue, and leave the fix to your internal IT staff. We run your IT and your security together, so the team that acts on an alert is the team that can isolate the machine, reset the account and restore the files.
We also work inside manufacturing environments every day: ERP systems, shop floor PCs, label printers and the shared accounts that come with them. Security that ignores those systems leaves the most important part of the business uncovered.
Before you sign with anyone, compare providers on the questions in our guide to choosing a cybersecurity provider. A good provider will tell you in writing what its plan does and does not cover.
- Start with the free cybersecurity assessment tool to see where you stand.
- For software your business builds or runs, ask about AI-assisted security audits of code and infrastructure.
- Compare the three plans side by side on the pricing page, then book a review of your environment.
Related services
Free cybersecurity policy templates
Insurers, auditors and customers ask for written security policies. Read each template in full, then build your own in a few minutes with recommended answers already filled in.
Information Security Policy template
Establish the core security program every insurer, auditor and customer now asks about: data classification, access control, patching, encryption, logging and vendor risk.
Incident Response Plan template
Know exactly who does what in the first hours of a ransomware attack, data breach or business email compromise, including who to call and which notification clocks start.
Password and MFA Policy template
Modern password and MFA rules based on current NIST SP 800-63B guidance: long passphrases, a password manager, no forced resets, and phishing-resistant MFA where it matters.
IT Acceptable Use Policy template
Set clear rules for how employees use company computers, email, internet, software and data, and what monitoring they should expect.
Cybersecurity questions we hear most
How much do cybersecurity services cost in North Carolina?
Preferred Data prices every plan per user per month, and the security baseline is included rather than billed as an extra. We quote after reviewing your environment, because device counts, servers and compliance needs change the price. Each plan includes monthly technician hours (2, 4 or 8), and anything outside the plan is quoted in writing before work starts.
Is 24/7 monitoring included in every plan?
24/7 threat detection and response, monitored by real people, is in every plan including Preferred Essentials. What differs by plan is help desk coverage: business hours on Essentials, extended hours on Professional, and 24/7 support including nights and weekends on Complete.
Can Preferred Data get us CMMC certified?
We prepare you for CMMC; we do not issue the certification. Preferred Complete includes readiness management for CMMC and NIST 800-171 (monitoring, documentation and evidence collection), and it is an add-on to Preferred Professional. Level 1 is a self-assessment. Level 2 is either self-assessed or assessed by an accredited third party (C3PAO), depending on the contract, and third-party assessment requirements are currently suspended.
Will your services help us qualify for cyber insurance?
Every plan is built to the controls carriers ask about most: MFA, endpoint detection and response, email protection, patching, training and tested backups. The underwriting decision always belongs to the carrier. We document what is actually in place so your application answers are accurate, which protects you at claim time.
What is the difference between EDR and MDR?
EDR (endpoint detection and response) is software on each computer and server that spots and can stop attacker behavior. MDR (managed detection and response) is the people who watch those alerts around the clock and act on them. Every Preferred Data plan includes both.
Do you offer penetration testing?
Preferred Complete includes an annual security assessment with penetration test coordination, plus recurring vulnerability scanning. We scope the test with you; fixes are handled within your plan hours or quoted in writing before work starts.
Do you only work with businesses in the Piedmont Triad?
Our office is in High Point, and we provide on-site service within 200 miles, which covers Greensboro, Winston-Salem, Charlotte, Raleigh and most of North Carolina. Monitoring, patching and most support are delivered remotely.
Sources
- Verizon, 2026 Data Breach Investigations Report, Executive Summary
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- IBM, Cost of a Data Breach Report 2026
- Marsh, Cyber resilience: 12 key controls to strengthen your security
- Federal Register, Cybersecurity Maturity Model Certification (CMMC) Program final rule (32 CFR 170)
- eCFR, 32 CFR Part 170, CMMC Program (Level 1 and Level 2 requirements)
- Federal Register, DFARS final rule on CMMC contract requirements (effective November 10, 2025)
- Holland & Knight, DOW Suspends CMMC Phase II Requirements (July 2026)
- Covington, Inside Government Contracts: CMMC Reform Task Force Updates (September 2026)
- Nextgov/FCW, CMMC Phase 2 suspension locked into binding regulation (September 9, 2026)
Find out where your business is exposed
Tell us how your business runs and what your insurer or customers are asking for. We will review your environment and tell you in writing what each plan covers and what it does not.
Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265