Managed services · MCT Protect

Protecting your people and their accounts

Your email, your shared files, and the login that opens both go wherever your people go. MCT Protect covers that side of your business: the accounts, the identities behind them, and the people signing in every day.

Covers
Human and account risk
Priced per
Active user, per month
Pairs with
MCT Manage and MCT Edge

Where the exposure usually sits

Account exposure rarely looks dramatic, which is most of the difficulty with it. Four situations we run into regularly. Open any one for what is actually happening underneath.

  • The invoice that changed A vendor you pay every month sends updated bank details, with a reason it cannot wait until Monday. What is happening

    The message is genuine in every way a person checks. It comes from that vendor's real address, often inside a thread you have both been replying to, because their mailbox was taken over rather than imitated. The payment goes to the attacker, and money that has cleared is rarely recoverable. Catching it takes filtering that weighs the request and the relationship instead of only the sender, and someone who knows to confirm a change of bank details by phone using a number they already had.

  • The password from years ago One password, reused on a site breached in 2019, still working on your email this morning. What is happening

    Credentials from old breaches get collected, sorted, and tried in bulk against email and cloud accounts. A password that leaked from a site with no connection to your business still opens your mailbox if nobody has changed it since. Monitoring breach data tells us one of your addresses has surfaced, so the password gets changed before somebody tries it, and a password manager means one leak stops at one account instead of opening several.

  • The account nobody closed Somebody leaves. Their login keeps working, because switching it off was on nobody's list. What is happening

    Closing out access is a checklist item, and checklists slip when somebody leaves in a hurry or on bad terms. An account that still authenticates looks exactly like a current employee to every system you own, so nothing flags it and nothing looks unusual in a report. Keeping a current list of who can sign in to what, and cutting access the same day somebody leaves, is what closes this one.

  • The quiet forwarding rule A rule copying incoming mail somewhere else. Sometimes an employee set it up. Sometimes not. What is happening

    A forwarding rule, or one that files certain mail into a folder nobody opens, is a common next step once somebody is inside a mailbox. It keeps feeding them copies of your mail long after the password has been changed, which is why a password reset on its own often does not end the problem. These rules also get set up by employees for ordinary convenience, so they blend in. Watching for rules that appear without anybody asking for one is what surfaces them.

This page covers the account side only. Computers and servers are MCT Manage, and your network is MCT Edge.

What MCT Protect changes

Six services built around the account rather than the equipment. They matter most together, because each one covers for the others.

  • Fewer bad messages arrive Phishing and impersonation get filtered ahead of your mailbox, including mail sent from a genuine account that has been taken over. How it works

    Filtering sits in front of Microsoft 365 or Google Workspace and weighs the sender, the history between you, the links, and what the message is asking for. That combination is how it flags mail from a real account somebody else is now using. No filter catches everything, so the point is to bring the volume down to something a person paying attention can handle.

  • A takeover gets caught sooner We watch for sign-ins and mailbox rules that do not fit the person, and for your credentials surfacing in breach data. How it works

    Sign-in activity gets checked against what is normal for that person, so a login from a place they have never worked, or a mailbox rule nobody requested, raises an alert. Most of the value here is time. A takeover found the same day is a password reset and a short conversation. The same takeover found six weeks later is an incident, with every message sent in between to account for.

  • Your mail and files can be restored Microsoft 365 and Google Workspace keep short retention windows. We back those accounts up separately. How it works

    The retention built into Microsoft 365 and Google Workspace is aimed at somebody deleting a message by accident and noticing quickly. It is a short window, and it is not designed for a mailbox or a shared drive that has been deliberately cleared out. A separate backup of those accounts keeps a copy that is not governed by those windows, which is what makes a restore possible weeks later.

  • Your team gets harder to fool Regular short training with simulated phishing, plus a password manager, so one password stops opening several doors. How it works

    Training runs in short sessions with simulated phishing, so people meet a realistic attempt in a setting where getting it wrong costs nothing and teaches something. A password manager takes away the reason people reuse passwords in the first place. This is the part that depends on your team taking part, and it does as much work as any software on the list.

Every item here is a best practice rather than a guarantee. The layers exist because attempts do get through, and a team that stays watchful matters as much as anything we install. The item-by-item list of what is included is on the services page.

When it goes wrong

Take a thirty person firm. Accounts payable pays a vendor invoice carrying new bank details, because it came from the address that vendor always uses. It did. That mailbox had been taken over the week before, and nobody notices until the vendor asks where their payment went.

The far end of this is public record. In 2021 a New York credit union fired a part-time employee. Two days later her remote access still worked, so she deleted more than 20,000 files and about 3,500 directories, roughly 21 gigabytes, including mortgage loan applications and the credit union's own anti-ransomware software. She pleaded guilty in federal court, and cleanup cost the credit union around $10,000.

No malware was involved, and no firewall would have helped. One account should have stopped working, and nobody switched it off.

Source: U.S. Department of Justice, Eastern District of New York, guilty plea, unauthorized intrusion into a credit union's computer system, 2021.

How it is priced

Priced per Active user, per month, as one package
Terms Billed monthly, Net 30. Nothing prepaid.
Your number Quoted once we have your user count. Ask and we will send it.

One rate covers all six services for one person, discounted against buying the pieces separately. We price it as a package because the parts hold each other up. Filtering stops the message, training covers what gets past filtering, monitoring catches the account taken over anyway, and the backup is there when all three are beaten. Pulling a piece out saves a little and reopens the gap it was closing, so the full package is what we recommend for every user you have.

Billed per active user, often a different count than your devices. A clinic with 10 shared exam-room computers and 30 staff with email accounts has 10 devices on MCT Manage and 30 users on MCT Protect. We confirm the count with you before anything is billed, so nothing on the first invoice is a surprise.

Let's look at what your accounts are exposed to

Tell us what you run for email and shared files and how many people sign in. We will tell you what is exposed and what we would do about it, before you commit to anything.

Music City Technology · Pricing effective 2026 · Where this page and your signed agreement differ, the agreement governs.