Got Questions?
FREQUENTLY ASKED QUESTIONS
Everything you've wanted to know about Cowboy MSP's services, pricing, and how we work. Can't find what you're looking for? Just ask us.
No questions matched your search. Try different keywords or ask us directly.
General
What is a Managed Service Provider (MSP) and why do I need one?
A Managed Service Provider handles your company's IT infrastructure, security, and support on an ongoing basis — think of us as your outsourced IT department. Instead of scrambling to find help when something breaks, you have a dedicated local team proactively monitoring and maintaining your technology 24/7. For Central Valley businesses, this means enterprise-grade IT expertise without the cost of full-time in-house staff.
Where does Cowboy MSP provide service?
We serve businesses throughout California's Central Valley, including Stockton, Tracy, Manteca, Escalon, Ripon, Salida, Riverbank, Oakdale, Modesto, Empire, Ceres, Hughson, Keyes, Patterson, Turlock, Denair, Hilmar, Delhi, Livingston, Winton, Atwater, Merced, Gustine, Newman, Los Banos, Chowchilla, and surrounding communities. Remote support is available anywhere, and on-site work is available throughout our service territory.
How is Cowboy MSP different from a break-fix IT company?
Break-fix companies only show up when things are already broken — and then charge by the hour. Cowboy MSP takes a proactive approach: we monitor your systems around the clock, catch issues before they become outages, apply patches and updates automatically, and provide unlimited remote support. The result is fewer headaches, less downtime, and a predictable monthly cost instead of surprise invoices.
What size businesses does Cowboy MSP work with?
We primarily serve small and mid-sized businesses with 5 to 150 users — from single-location offices to multi-site operations. Whether you're a 10-person ag business, a 60-person medical clinic, or a growing logistics company, we have a service tier designed around your needs. We're not a good fit for solo consultants or enterprise companies with in-house IT teams of 10+, but if that's you, we're happy to point you in the right direction.
Do I have to sign a long-term contract?
Our standard agreements are 12 months, which allows us to invest in properly onboarding and stabilizing your environment. We do offer month-to-month options at a slightly higher rate. We believe in earning your business every month through results — not locking you in. Talk to us about the right term for your situation.
Do you work with businesses that already have an internal IT person?
Yes — and it's more common than you'd think. We often act as the team behind the IT person: handling the tool stack, monitoring, security, and escalations while your internal hire or office manager handles day-to-day tickets. This hybrid model gives you the best of both worlds — local accountability and enterprise-grade infrastructure — without the cost of a full in-house team.
Are you available after hours and on weekends?
For critical issues — systems down, active security incidents, or anything that stops your business from operating — yes. We have an after-hours emergency line that pages an on-call engineer. Response for critical events is targeted under 30 minutes around the clock. For non-critical issues like a printer configuration or a password reset, those are queued for the next business day.
What industries do you specialize in?
We serve businesses across most industries in the Central Valley, with particular depth in agriculture and food processing, healthcare (HIPAA environments), legal and professional services, logistics and transportation, and construction. That said, our managed services approach is built around your business's specific needs — not a one-size-fits-all industry template.
Do you offer remote support or only on-site?
The majority of issues — probably 85% or more — are resolved entirely through remote support, which is faster and less disruptive for you. For issues that genuinely require hands on hardware, we dispatch a technician. We cover the Central Valley for on-site visits, and our remote support is available to any business in California and beyond.
What makes Cowboy MSP different from larger national MSPs?
We're local, which means we have real accountability. You can reach a named person, not a call center. When you need someone on-site, we can be there the same day — not next week. We're also small enough that every client relationship matters to us personally, but we run the same enterprise-grade tool stack (N-central RMM, SentinelOne EDR, Cove backup, Proofpoint) that large MSPs charge a premium for.
Can you support multiple office locations?
Yes. We manage multi-site environments regularly — businesses with two or three locations across the Central Valley are common for us, and we can support remote employees anywhere in the US. Our monitoring and management tools are cloud-based, so geography isn't a constraint. Each site gets the same standard of care, and we coordinate everything from a single pane of glass.
Will I have a dedicated point of contact?
Yes. Every client is assigned a dedicated account manager who knows your environment, your priorities, and your team. You're not calling a generic helpdesk and explaining your setup from scratch every time. Your account manager is your advocate inside Cowboy MSP and conducts regular check-ins to make sure everything is running the way you expect.
How do I submit a support ticket?
We give you multiple ways to reach us: email a dedicated support address, call our helpdesk line, or submit through the client portal. We don't require you to use only one channel — whatever is fastest for you in the moment works for us. Tickets are triaged by severity: business-down events jump to the front of the queue automatically.
Do you provide IT consulting and strategic planning, or just day-to-day support?
Both. Day-to-day reactive support is table stakes — what separates a good MSP from a great one is the strategic layer. We conduct regular business reviews where we look at your technology roadmap, upcoming hardware refreshes, licensing renewals, and security posture. We help you make smart decisions before you're forced into expensive emergency ones.
What if we're not happy with the service?
We want to earn your business every month. If something isn't working — response times, communication, a technician you didn't click with — tell us. We take feedback seriously and will address it directly. If after a good-faith effort things still aren't right, our agreements include a fair exit process. We don't hold clients hostage, and we have the confidence that most businesses that give us a real shot don't want to leave.
Web Design
What kinds of websites does CowboyMSP build?
We build three types of custom static websites: Countdown & Event Sites (coming-soon pages, event timers, single-purpose landing pages — $500 flat), Portfolio Sites (clean, memorable sites for creatives, students, and freelancers — $500 flat), and Professional Business Websites (multi-page sites for service businesses, built to rank and convert — from $2,500). Every site is hand-coded in HTML5, CSS3, and JavaScript. No WordPress, no page builders, no monthly CMS fees.
Do you build e-commerce or online store websites?
No — CowboyMSP does not build e-commerce or online store websites. We specialize exclusively in custom static sites: business websites, portfolios, landing pages, and event sites. Our focus on static HTML5/CSS3/JavaScript means blazing-fast performance and zero backend complexity, but it isn't suited for product catalogs or shopping carts. If you need an online store, we're happy to point you toward the right platform.
How much does a website cost?
Our pricing is flat-rate and transparent: Countdown/Event Sites — $500 flat. Portfolio Sites — $500 flat (1–3 pages, gallery, up to 2 revisions). Professional Business Websites — from $2,500 (multi-page, SEO-ready, contact form, maps, full branding). Additional pages beyond the standard set are $200/page. Extra revision rounds are $75 each. Rush delivery for simple/portfolio sites is an additional $200. You always know the price before we start.
How long does it take to build a website?
Simple countdown and portfolio sites are typically delivered in 5–7 business days. Professional business websites take 2–4 weeks from the time we receive your content and feedback. Rush delivery is available for simple and portfolio sites (48–72 hours) for an additional $200.
What technology do you use to build websites?
Every CowboyMSP website is hand-coded in pure HTML5, CSS3, and JavaScript — no WordPress, no Wix, no page builders. This means your site loads fast, has no plugin vulnerabilities, and doesn't require monthly software subscriptions to stay functional. You own clean, portable code that works anywhere.
Do you offer website hosting?
Yes — hosting is optional and flexible. Self-Managed ($0/month) — we hand you the files, you host on Cloudflare Pages, GitHub Pages, Netlify, etc. CowboyMSP Managed Hosting (from $25/month) — we handle hosting, SSL, CDN, and uptime monitoring. Domain Management ($15/month) — we manage your domain, renewals, and DNS (included in Standard Care Plans and above).
What are the monthly care plans?
Optional monthly plans keep your site healthy after launch: Basic — $25/mo (managed CDN hosting). Standard — $60/mo (hosting, uptime monitoring, minor content updates, Google Analytics, domain management). Pro — $100/mo (everything in Standard plus priority support and more extensive monthly updates). All plans are optional — self-hosting is always free.
Will my website work on mobile devices?
Yes — every site we build is fully mobile-responsive. We design and test across phones, tablets, and desktops. Mobile performance is a core SEO signal, so we build mobile-first on every project.
Is SEO included in the website build?
Yes. Every professional business website includes on-page SEO foundations: proper heading structure, meta titles and descriptions, canonical tags, Open Graph tags, schema markup, fast load times, and mobile optimization. Your site is technically ready for Google from day one.
What do you need from me to get started?
We need: your logo and brand colors, any photos you want to use, the text/copy for each page (or a brief so we can write it), and your goal for the site. For simple sites, a short form submission is all it takes. For business websites, we'll schedule a brief discovery call first.
How does the revision process work?
Every project includes two rounds of revisions at no extra charge. After the initial build you review and provide feedback, we revise and present the updated version. Additional revision rounds beyond two are $75 each.
Do you serve businesses outside of California?
Yes — our web design service is fully remote and available in all 50 states. Location is never a barrier. View our 50-state coverage here.
Will I own the website when it's done?
Yes, 100%. Once delivered and paid, all the HTML, CSS, and JavaScript code is yours — no licensing fees, no platform lock-in, no dependency on us. You can host it anywhere, modify it, or hand it to another developer.
Can you redesign or update my existing website?
Absolutely. Website redesigns are one of our most common requests. Whether your site looks dated, doesn't work on mobile, or isn't converting, we rebuild it from scratch in clean HTML5/CSS3/JavaScript — faster, modern, and platform-free.
How do I get a quote for my website?
Fill out our contact form or visit our web pricing page to see all project types and costs. We respond with a specific quote within one business day — no sales calls, no pressure.
Managed IT
What does "24/7 monitoring" actually mean in practice?
Our RMM (Remote Monitoring and Management) platform runs a lightweight agent on every covered device. It checks CPU load, disk health, memory usage, service availability, patch status, and dozens of other indicators every few minutes. If something looks wrong — a hard drive approaching failure, a server process crashing silently, unusual login activity — we get alerted automatically and can often resolve the issue before you even notice. After-hours critical alerts page an on-call engineer immediately.
What is your response time when we have an issue?
Our SLA commitments are:
- Remote support: Response within 1 business hour for standard issues.
- Critical / business-down events: 24/7 emergency line with a target response under 30 minutes.
- On-site visits: Same business day for most locations in our service area.
Do you support Macs or only Windows?
We fully support both Windows and macOS environments, including mixed shops. We also manage network hardware from vendors like Dell, Cisco, and Ubiquiti, and can support iOS and Android mobile devices enrolled in your MDM policy. If you run a specialized application on Linux, reach out and we'll assess compatibility.
What backup and disaster recovery options do you offer?
We partner with industry-leading platforms including Cove Data Protection (N-able) for image-based server backups, Microsoft Azure and local NAS solutions for file-level backup, and cloud-to-cloud backup for Microsoft 365 data (email, SharePoint, OneDrive, Teams). We test restores regularly — a backup you've never tested is not a backup. Recovery time objectives (RTOs) and recovery point objectives (RPOs) are defined in your service agreement based on your business needs.
Can you manage our Microsoft 365 or Google Workspace environment?
Yes — this is one of our most common service areas. We handle Microsoft 365 licensing, user provisioning and offboarding, Exchange/Teams configuration, SharePoint administration, security policy enforcement (MFA, Conditional Access, Intune MDM), and ongoing support. We are a Microsoft Partner. We can also manage Google Workspace environments and assist with migrations between platforms.
What happens when an employee leaves the company?
We have a defined offboarding checklist: disabling the account across all systems (Active Directory, Microsoft 365, VPN, cloud apps), transferring email and data to the appropriate manager, revoking MFA devices, recovering company hardware, and auditing access logs. This is a security-critical process and we can execute it same-day when given notice. We also offer user onboarding services — getting a new hire's workstation, accounts, and access fully ready before their first day.
What RMM and PSA tools do you use?
We run N-able N-central as our Remote Monitoring and Management platform — one of the most capable RMM tools in the industry. It gives us real-time visibility into every device, automated patch deployment, scripted remediations, and performance trending. On the ticketing and documentation side we use ConnectWise Manage. These aren't budget tools — they're what the largest MSPs in the country use.
How do you handle software patching?
Patching is automated and policy-driven. Windows OS patches are tested and deployed on a monthly cycle aligned with Patch Tuesday. Third-party application patches (Chrome, Adobe, Java, and hundreds more) are deployed on a separate schedule. Critical security patches — those actively exploited in the wild — get expedited deployment, often within 24–48 hours of release. You can review your patch compliance status in the client portal at any time.
Can you manage our servers, or just workstations?
We manage the full stack: workstations, laptops, physical servers, virtual machines (Hyper-V, VMware), NAS devices, network switches, firewalls, and access points. If a device is on your network and business-critical, we want eyes on it. Server monitoring includes disk health, RAID status, event log alerting, service availability, performance baselines, and scheduled maintenance windows.
Do you manage firewalls and network security?
Yes. We manage firewall configurations, firmware updates, VPN setups, and security policy reviews for appliances from Cisco Meraki, Fortinet, WatchGuard, and others. We also design and implement network segmentation to isolate guest Wi-Fi, IoT devices, and sensitive systems like point-of-sale or medical equipment from your main business network.
What endpoint protection do you use?
We deploy SentinelOne as our endpoint detection and response (EDR) platform — a best-in-class solution that uses AI-driven behavioral analysis rather than traditional signature-based antivirus. It catches threats that legacy AV misses, can automatically quarantine infected endpoints, and provides detailed forensic timelines of any incident. Every managed endpoint gets SentinelOne, no exceptions.
How do you handle printers and other peripherals?
Printers, scanners, label printers, and similar peripherals are supported as part of your managed environment. We handle driver deployment, network printer configuration, and troubleshoot connectivity and print queue issues. We don't manufacture or repair physical printer hardware, but we'll work with your vendor if a device needs physical service — and we'll make sure your network side is correctly configured when it comes back.
Can you help us move from on-premises servers to the cloud?
Yes — cloud migrations are one of our most requested projects. Whether you're moving file servers to SharePoint, replacing on-prem Exchange with Microsoft 365, or lifting workloads to Azure or AWS, we plan and execute migrations with minimal disruption. We don't push cloud for cloud's sake — we'll give you an honest assessment of what makes sense to move and what's better left on-premises given your workloads and budget.
Do you provide hardware procurement?
We can source and configure workstations, laptops, servers, networking gear, and peripherals through our vendor relationships. We don't mark up hardware significantly — our value is in the configuration, deployment, and asset documentation, not margins on the gear itself. We work primarily with Dell, Cisco, and Ubiquiti, but can source from other vendors based on your requirements or existing investments.
How do you document our IT environment?
Documentation is built from day one during onboarding and maintained continuously. We document your network topology, server configurations, software licenses, vendor contacts, warranty information, and critical credentials (stored in an encrypted password manager, never in a spreadsheet). When something breaks at 2am, we're not searching for information — it's already at our fingertips. You get access to your own documentation through the client portal.
Pricing & Contracts
How does your pricing work?
We charge a flat per-user monthly fee based on your service tier. That means your bill is predictable and scales simply as you hire or reduce headcount. There are no surprise hourly charges for covered support. Pricing varies by tier — see our MSP pricing page for current rates, or request a custom quote if you have specific needs.
Are there any setup or onboarding fees?
There is a one-time onboarding fee that covers our initial assessment, documentation of your environment, deployment of our monitoring agents, and getting everything properly configured and secured. This fee varies by the size and complexity of your environment. It's not a hidden charge — we'll quote it clearly upfront before you sign anything.
What's not included in the monthly fee?
Monthly managed services cover ongoing support, monitoring, patching, and administration of your existing environment. Items typically billed separately include:
- Hardware purchases (servers, workstations, networking gear)
- Software licenses (Microsoft 365, specialty applications)
- Major project work (new server deployments, office relocations, large migrations)
- After-hours emergency on-site dispatch beyond SLA (rare)
Can I cancel if I'm not satisfied?
Our standard agreements include a 30-day notice period to cancel. If we're truly not meeting your needs, we'd rather have an honest conversation and fix the problem — or help you transition gracefully — than hold you hostage to a contract. We'll provide full documentation of your environment and assist with a smooth handoff to whoever takes over.
What are your service tiers?
We offer three primary tiers. Essentials covers the foundational stack: RMM monitoring, patch management, EDR, and helpdesk support. Business adds advanced security layers, Microsoft 365 management, and backup. Enterprise includes everything in Business plus SOC monitoring, vCISO consulting, compliance management, and enhanced SLAs. Visit our pricing page for current per-user rates on each tier.
Is pricing per device or per user?
Per user — which is the fairest way to do it. Each user gets coverage for their workstation, laptop, and mobile device under a single seat. We don't nickel-and-dime you for each endpoint. Servers are priced separately as a line item since they require distinct monitoring and maintenance work above and beyond a typical user seat.
Do you charge extra for after-hours or emergency support?
No. If you're on a managed services agreement, after-hours and emergency support for covered services is included in your flat monthly fee. There's no overtime surcharge, no emergency call fee, no minimum hour billing. The predictability of your IT costs is the whole point of managed services — surprise invoices defeat that purpose entirely.
What happens to our rate if we hire more employees?
Your monthly invoice scales up by the per-user rate for each new seat. We true up quarterly — so if you hire in January and March, we adjust at the April billing cycle rather than sending mid-month invoices. If headcount drops, the same process applies in reverse. There's no penalty for scaling down.
Do you offer discounts for annual prepayment?
Yes. Clients who prepay annually receive a discount versus the standard monthly rate. The exact percentage depends on your tier and seat count — ask us for a quote that includes the annual prepay option alongside the monthly rate so you can compare. Many businesses find the annual option makes budgeting even more predictable.
Are there any price increases during our contract term?
We do not increase prices during an active contract term. Any rate changes take effect only at renewal, and we give at least 60 days' notice before a renewal with a rate adjustment. We're not in the business of locking you in at one rate and quietly raising it — that's not how we'd want to be treated, and it's not how we operate.
What does the onboarding fee cover exactly?
The one-time onboarding fee covers the labor to properly set up your environment: conducting the initial security and infrastructure assessment, documenting your network and systems, deploying monitoring agents to every device, configuring your backup jobs, enrolling endpoints in EDR, and establishing your security baselines. It's a real investment of engineer time — typically 10–20 hours depending on your size — and doing it right at the start prevents problems for years.
Can we do a month-to-month agreement instead of annual?
Yes, month-to-month is available at a slightly higher per-user rate. We understand some businesses aren't ready to commit to a 12-month term — particularly if they've been burned by a previous provider. We'd rather earn a long-term relationship than force one. Most clients who start month-to-month end up moving to annual once they see how we operate.
Do you offer nonprofit or education pricing?
We do offer discounted rates for registered nonprofit organizations. Educational institutions (K-12, community colleges) are evaluated case by case. If you're a nonprofit, mention it when requesting a quote and we'll apply the appropriate discount from the start. We believe in supporting organizations that do important work in our community.
What payment methods do you accept?
We accept ACH bank transfer, credit card, and check. ACH is our preferred method as it eliminates processing fees for both parties. Credit card payments may include a small processing surcharge depending on your agreement. Invoices are sent at the beginning of each billing cycle with net-15 terms for established clients.
Will I receive itemized invoices showing what I'm paying for?
Yes. Every invoice breaks down your per-user fees by tier, any add-on services, server seats, and one-time items separately. Nothing is bundled into a single opaque line item. If you ever have a question about a charge, your account manager can explain it line by line. Transparency in billing is something we take seriously.
Security
What cybersecurity protections are included?
Our managed security stack includes endpoint detection and response (EDR), managed antivirus, automated patch management for Windows and third-party apps, DNS filtering to block malicious websites, dark web monitoring for your company's email domains, multi-factor authentication enforcement, and security awareness training for your staff. Higher tiers add Security Operations Center (SOC) monitoring and advanced threat hunting.
Can Cowboy MSP help us meet HIPAA, PCI, or other compliance requirements?
Yes. We work with healthcare practices, dental offices, insurance firms, and other regulated businesses throughout the Central Valley. We can implement the technical controls required by HIPAA (encryption, access logging, BAA agreements), PCI DSS (network segmentation, cardholder data protection), and other frameworks. We're not a compliance law firm — for legal interpretation of regulatory requirements you'll want a compliance attorney — but we handle the technical implementation side thoroughly.
What should we do if we think we've been hacked or hit with ransomware?
Call our emergency line immediately: (209) 497-5758. While you wait, disconnect affected machines from the network by unplugging the ethernet cable or turning off Wi-Fi — do not power them off completely, as this can destroy forensic evidence. Do not pay any ransom demand before speaking with us. If you're an active client, our incident response procedures kick in automatically. If you're not yet a client and you're in crisis, call us anyway — we'll do our best to help.
Do you offer security awareness training for employees?
Yes. We partner with Breach Secure Now to deliver automated phishing simulation campaigns and micro-training modules for your team. Humans are the most commonly exploited entry point in cyberattacks, and regular training measurably reduces your risk. Training is included in our higher service tiers and available as an add-on for others.
What is MDR and do you offer it?
MDR stands for Managed Detection and Response — it's the evolution beyond traditional antivirus. Rather than just blocking known threats, MDR actively hunts for suspicious behavior, investigates alerts, and responds to incidents on your behalf. We include EDR (Endpoint Detection and Response via SentinelOne) on every managed device. Higher service tiers include 24/7 SOC-backed MDR where human analysts review alerts around the clock.
How do you protect against phishing and email-based attacks?
Email is the #1 attack vector for most businesses. We deploy Proofpoint Essentials (or comparable solutions) for inbound email filtering, which blocks malicious attachments, spoofed senders, and phishing links before they reach an inbox. We also enforce Microsoft 365 security baselines including anti-phishing policies, Safe Links, and Safe Attachments. On top of the technical layer, we run regular phishing simulation training so your team recognizes attacks that do get through.
What is multi-factor authentication (MFA) and do you enforce it?
MFA requires a second form of verification — typically an app notification or code — in addition to a password. It's one of the single most effective security controls available, blocking over 99% of account compromise attacks. We enforce MFA on all managed accounts as a baseline requirement — it's not optional. We configure Microsoft Authenticator or compatible apps and handle the enrollment process for your team.
Do you monitor the dark web for our credentials?
Yes. We run dark web monitoring against your company's email domains continuously. When employee credentials appear in breach databases — from past data leaks at third-party services your staff used — we alert you immediately so the affected passwords can be changed before an attacker exploits them. This is included in our standard security stack.
What is a SOC and does Cowboy MSP have one?
A Security Operations Center (SOC) is a team of dedicated security analysts who monitor alerts, investigate threats, and respond to incidents 24/7. We partner with Black Point Cyber for SOC-level monitoring on our Enterprise tier clients — giving you access to a full security operations team without the cost of building one in-house. For Essentials and Business tier clients, our team handles security monitoring during business hours with after-hours coverage for critical alerts.
How do you handle ransomware specifically?
Ransomware defense runs on multiple layers: prevention (patching, EDR, email filtering, MFA, network segmentation), detection (behavioral analysis that catches encryption activity before it spreads), and recovery (immutable offsite backups that ransomware can't reach or encrypt). If a ransomware incident does occur, our incident response process kicks in immediately — isolating affected systems, assessing the blast radius, and initiating recovery from clean backups. We also carry cyber liability insurance and can connect you with a breach attorney if needed.
Do you perform vulnerability assessments?
Yes. We conduct regular vulnerability scans of your network and endpoints as part of our ongoing service. Higher tiers include scheduled external vulnerability assessments that simulate what an outside attacker would see when probing your perimeter. Findings are prioritized by severity and fed directly into our patching and remediation workflow — a vulnerability scan that doesn't result in action isn't worth much.
What is DNS filtering and why does it matter?
DNS filtering intercepts web requests before they connect to malicious domains — blocking malware command-and-control servers, known phishing sites, and inappropriate content at the network level. It works on every device on your network, including phones and tablets, regardless of whether they have an endpoint agent installed. We deploy DNS filtering via Cisco Umbrella or comparable platforms as a standard layer in our security stack.
Can you help us create a cybersecurity policy for our business?
Yes. We help clients develop written information security policies (WISP) that cover acceptable use, password requirements, data classification, incident response procedures, and employee responsibilities. A documented policy is required for many compliance frameworks (HIPAA, SOC 2, cyber insurance applications) and serves as the foundation for a defensible security posture. We use policy templates adapted to your industry and size, then customize them to your actual environment.
How do you handle mobile device security?
We manage mobile devices through MDM (Mobile Device Management) policies — typically Microsoft Intune for businesses already in the Microsoft ecosystem. MDM allows us to enforce passcode requirements, enable remote wipe if a device is lost or stolen, prevent unapproved apps from accessing company data, and ensure company email is only accessible from enrolled, compliant devices. BYOD (bring your own device) environments get containerized company data so personal and work data remain separate.
What cyber insurance considerations should we be aware of?
Cyber insurance applications increasingly require documented security controls — and insurers are auditing claims more aggressively. The controls they most commonly ask about are: MFA on all accounts (especially email and remote access), endpoint detection and response, immutable backups, patch management, and employee security training. Having Cowboy MSP manage your security stack not only protects you — it gives you the documentation to prove those controls exist when you apply for or renew a policy.
Cloud Phones
What is a cloud phone system and why should I switch from a traditional PBX?
A cloud phone system (also called VoIP or UCaaS) routes your business calls over the internet instead of traditional phone lines. Benefits include: significantly lower monthly costs, features like auto-attendants, call recording, voicemail-to-email, and mobile apps at no extra charge, easy addition of lines without hardware changes, and the ability for employees to take business calls on their cell phones using your company number. Traditional PBX hardware is expensive, inflexible, and requires a vendor visit for almost any change.
What phone systems do you offer?
We primarily deploy and support GoTo Connect, a business-grade UCaaS platform. It includes unlimited domestic calling, video conferencing, SMS messaging, mobile app, auto-attendant, call queues, and call recording. We handle porting your existing phone numbers, provisioning physical desk phones if needed, and ongoing support. See our phone services page and phone pricing for full details.
Can we keep our existing phone numbers?
Yes — number porting is standard practice and we handle it for you. The process typically takes 2–4 weeks and your numbers remain active throughout the transition; there's no gap in service. We coordinate everything with your previous carrier and the new platform.
What internet speed do we need for VoIP calls to sound good?
Each concurrent call uses roughly 100 Kbps of bandwidth — so a standard business internet connection handles dozens of simultaneous calls easily. The bigger factor is Quality of Service (QoS) configuration on your router, which prioritizes voice traffic over general internet browsing. We configure this as part of our phone deployment. A jitter buffer and low latency connection matter more than raw speed. We'll assess your network before recommending a switch to make sure it's ready.
What features come standard with a cloud phone system?
Standard features include unlimited domestic calling, voicemail with email delivery, auto-attendant (virtual receptionist), call routing and ring groups, call recording, hold music, mobile apps for iOS and Android, desktop softphone, and a web-based admin portal. Advanced features like call analytics dashboards, CRM integrations, video conferencing, and SMS/MMS vary by plan. We'll map your current system's features to the new platform before migration so nothing is lost.
How does the auto-attendant work?
The auto-attendant answers calls with a custom greeting and routes callers based on their input — press 1 for sales, press 2 for support, etc. — or by time of day (business hours vs. after hours). You configure it through the web portal or we can configure it for you. Changes take effect immediately with no hardware involvement. No more calling a phone company and waiting a week for a simple menu change.
Can employees use the system on their personal cell phones?
Yes. Both RingCentral and GoTo Connect have mobile apps that give employees full access to the business phone system from their personal iPhone or Android — calls, voicemail, messaging, and even video meetings. The app displays your business number as the caller ID, not the employee's personal cell. This is especially useful for remote workers and field staff who need to stay reachable without giving out personal numbers.
What happens to calls if our internet goes down?
You configure failover rules in advance. Typically this means calls automatically reroute to mobile phones or an alternate number when your primary internet connection is unavailable. RingCentral and GoTo Connect both support this natively — you set it up once and it activates automatically. For businesses where phone availability is critical, we also recommend a redundant 4G/LTE backup connection to keep the system online during ISP outages.
How long does the migration take?
A standard migration — porting your existing numbers and cutting over to the new system — typically takes 2–4 weeks. Most of that time is the number porting process with your current carrier, which is regulated and can't be rushed significantly. The actual system setup, user training, and device configuration happens in parallel, so you're not waiting on porting to do the rest. We coordinate the cutover to happen during off-hours or weekends to minimize disruption.
Do we need new desk phones or can we keep our existing ones?
It depends on your current equipment. Many modern SIP-compatible desk phones can be reprogrammed to work with RingCentral or GoTo Connect. Older proprietary PBX handsets (Nortel, older Cisco CallManager) typically can't be reused. We assess your existing hardware before the migration and give you a clear picture of what can stay, what needs to be replaced, and what the desk phone hardware would cost. Many businesses also take migration as an opportunity to go fully softphone (computer + headset) and eliminate desk phones entirely.
What kind of headsets work with the system?
Any USB or Bluetooth headset works with the desktop softphone application — Jabra, Poly (formerly Plantronics), and EPOS are popular choices. For dedicated desk phones, RingCentral and GoTo Connect support standard RJ-9 and 2.5mm headset connections. We can recommend specific models based on your work environment — call center environments have different needs than a quiet private office.
Can the system integrate with our CRM or helpdesk software?
Yes — both RingCentral and GoTo Connect offer integrations with major CRM platforms like Salesforce, HubSpot, and Zoho, as well as helpdesk tools like ServiceNow and Zendesk. These integrations enable screen-pop (automatically showing the caller's CRM record when they call), click-to-call from within the CRM, and automatic call logging. The availability of specific integrations depends on your plan tier.
Is call recording legal and how does it work?
Call recording legality varies by state — California is a two-party consent state, meaning all parties must be informed a call is being recorded. We configure the system to play an automatic disclosure message when recording is enabled to keep you compliant. Recordings are stored in the cloud and accessible through the admin portal. Retention periods and access controls are configurable. We recommend discussing call recording practices with your attorney before enabling it.
What support do you provide after the system is set up?
Once the system is live, you have two layers of support: RingCentral or GoTo Connect's own 24/7 technical support for platform-level issues, plus Cowboy MSP for anything related to your network, hardware, integrations, user changes, and day-to-day administration. Adding a new employee, changing a call routing rule, setting up a new ring group — those come to us. You don't need to manage your phone system yourself.
How does pricing work for cloud phone systems?
Cloud phone systems are priced per user per month, with costs varying by feature tier and number of users. Volume discounts apply at higher seat counts. Hardware (desk phones, headsets) is a one-time cost. We provide a full quote that includes the monthly per-seat license, any required hardware, and our setup and migration fee so you have a complete picture of the total investment. Visit our phone pricing page for current rates.
Getting Started
How does the onboarding process work?
After you sign on, here's what happens:
- Week 1: Discovery — we audit your current environment, document all hardware, software, accounts, and network topology.
- Week 2: Deployment — we install monitoring agents, endpoint protection, backup clients, and configure your security baselines.
- Week 3: Stabilization — we address any issues uncovered in discovery and make sure everything is running cleanly.
- Week 4+: Business as usual — proactive monitoring, regular patching, and responsive support become the norm.
How long does it take to get started?
From signed agreement to fully onboarded is typically 3–4 weeks, depending on the size and complexity of your environment. We can prioritize emergency situations — if you're in a critical state due to a security incident or your previous provider walking out, contact us and we'll fast-track where possible.
What do you need from us to get started?
Primarily: administrative credentials to your key systems (Active Directory, Microsoft 365, firewall), a list of your key applications and vendors, and someone on your side available for a few hours during the discovery week. We're organized and efficient — we'll send you a clear checklist so there are no surprises. Most business owners are pleasantly surprised by how little disruption the process involves.
Can you take over from our current IT person or provider?
Absolutely — IT transitions are something we handle regularly. Whether you're moving from an internal IT employee, a break-fix vendor, or another MSP, we'll manage the transition professionally. We'll request documentation handoff from the outgoing provider, and if that documentation doesn't exist (it often doesn't), we'll build it from scratch during onboarding. We won't leave you uncovered during the switchover.
Do you offer a free assessment before we commit?
Yes. We offer a free IT assessment that includes a high-level review of your network, security posture, backup strategy, and current infrastructure. You'll walk away with a clear picture of where you stand — and we'll give you an honest recommendation, even if it's that you don't need us yet. No hard sell, no pressure. Schedule yours here.
Will there be any downtime during onboarding?
For the vast majority of businesses, onboarding involves zero planned downtime. Installing monitoring agents and deploying security software happens silently in the background during business hours without interrupting users. The only scenarios that might involve brief, scheduled downtime are firewall replacements or major network reconfigurations — and we schedule those outside business hours with advance notice.
How do you handle the transition if we currently have no IT support?
Starting from scratch is actually easier than transitioning from a previous provider in some ways — there are no access credentials to chase down, no tool conflicts to resolve, and no bad habits to undo. We conduct a clean baseline assessment, document everything we find, and build your IT environment to our standards from the ground up. We'll identify and remediate any existing issues during discovery.
What if our previous IT provider won't cooperate with the handoff?
Unfortunately this happens. A departing provider withholding documentation or access credentials is an unprofessional but real situation we've navigated before. We know how to recover admin access to most systems, rebuild documentation from scratch, and work around an uncooperative outgoing vendor. We'll be straightforward with you about what we can and can't recover without their cooperation, and build a plan accordingly.
Do you train our employees during onboarding?
Yes. We conduct a brief end-user orientation — usually 30–45 minutes in person or over video — covering how to submit support tickets, how to recognize phishing attempts, password manager usage, and any new tools we're deploying. We also make reference guides available through the client portal. Security awareness is an ongoing program, not a one-time event, so training continues after onboarding through our phishing simulation and training platform.
What documentation will we receive after onboarding?
At the end of onboarding you receive a complete IT runbook: network diagram, device inventory with serial numbers and warranty dates, software license register, vendor and ISP contact list, admin credential documentation (in encrypted storage), backup configuration details, and your security baseline summary. This documentation is maintained and updated by us throughout the relationship — it's a living record, not a snapshot that goes stale.
How do you handle data security during the onboarding process?
Any credentials or sensitive information you share with us during onboarding are stored immediately in our enterprise-grade encrypted password manager (IT Glue). We operate on a need-to-know basis internally — only the engineers working your account have access to your credentials. We can sign an NDA before onboarding begins if your organization requires it. We carry professional liability insurance and are happy to provide our security and compliance documentation on request.
Can we run a pilot with just part of our team before going all-in?
Yes. Some larger businesses prefer to pilot our service with a single department or location before rolling out company-wide. This is a perfectly reasonable way to evaluate us in a real environment. We'll agree on a defined pilot scope, success criteria, and timeline upfront. Pilot pricing applies during the test period, and transitioning to a full agreement is straightforward once you're satisfied.
What happens if we need to pause or reduce service?
We understand business circumstances change. If you need to reduce headcount coverage temporarily — during a layoff, for example — we can adjust your seat count at the next billing cycle. We don't offer service pauses (our monitoring infrastructure remains active regardless), but we'll work with you on billing adjustments during genuinely difficult circumstances. We'd rather retain a client through a tough period than lose them over a rigid contract.
How do we escalate issues if we're not happy with a support response?
Every client has a named account manager who is your escalation path. If a ticket isn't being resolved to your satisfaction, email or call your account manager directly — not the general helpdesk queue. Your account manager has the authority to reprioritize tickets, assign senior engineers, and get involved personally. For anything that reaches a critical level and isn't moving, our principal engineer is also available as a final escalation.
Is there a client portal and what can we do in it?
Yes. You get access to our client portal where you can: submit and track support tickets in real time, view your device inventory and asset list, access your IT documentation, review patch compliance reports, and see your billing history. You can also add or remove users from your managed seat count through the portal. We find that businesses who actively use the portal have a better experience because they have full visibility into what's happening with their IT at all times.
What is a Managed Service Provider (MSP) and why do I need one?
A Managed Service Provider handles your company's IT infrastructure, security, and support on an ongoing basis — think of us as your outsourced IT department. Instead of scrambling to find help when something breaks, you have a dedicated local team proactively monitoring and maintaining your technology 24/7. For Central Valley businesses, this means enterprise-grade IT expertise without the cost of full-time in-house staff.
Where does Cowboy MSP provide service?
We serve businesses throughout California's Central Valley, including Stockton, Tracy, Manteca, Escalon, Ripon, Salida, Riverbank, Oakdale, Modesto, Empire, Ceres, Hughson, Keyes, Patterson, Turlock, Denair, Hilmar, Delhi, Livingston, Winton, Atwater, Merced, Gustine, Newman, Los Banos, Chowchilla, and surrounding communities. Remote support is available anywhere, and on-site work is available throughout our service territory.
How is Cowboy MSP different from a break-fix IT company?
Break-fix companies only show up when things are already broken — and then charge by the hour. Cowboy MSP takes a proactive approach: we monitor your systems around the clock, catch issues before they become outages, apply patches and updates automatically, and provide unlimited remote support. The result is fewer headaches, less downtime, and a predictable monthly cost instead of surprise invoices.
What size businesses does Cowboy MSP work with?
We primarily serve small and mid-sized businesses with 5 to 150 users — from single-location offices to multi-site operations. Whether you're a 10-person ag business, a 60-person medical clinic, or a growing logistics company, we have a service tier designed around your needs. We're not a good fit for solo consultants or enterprise companies with in-house IT teams of 10+, but if that's you, we're happy to point you in the right direction.
Do I have to sign a long-term contract?
Our standard agreements are 12 months, which allows us to invest in properly onboarding and stabilizing your environment. We do offer month-to-month options at a slightly higher rate. We believe in earning your business every month through results — not locking you in. Talk to us about the right term for your situation.
Do you work with businesses that already have an internal IT person?
Yes — and it's more common than you'd think. We often act as the team behind the IT person: handling the tool stack, monitoring, security, and escalations while your internal hire or office manager handles day-to-day tickets. This hybrid model gives you the best of both worlds — local accountability and enterprise-grade infrastructure — without the cost of a full in-house team.
Are you available after hours and on weekends?
For critical issues — systems down, active security incidents, or anything that stops your business from operating — yes. We have an after-hours emergency line that pages an on-call engineer. Response for critical events is targeted under 30 minutes around the clock. For non-critical issues like a printer configuration or a password reset, those are queued for the next business day.
What industries do you specialize in?
We serve businesses across most industries in the Central Valley, with particular depth in agriculture and food processing, healthcare (HIPAA environments), legal and professional services, logistics and transportation, and construction. That said, our managed services approach is built around your business's specific needs — not a one-size-fits-all industry template.
Do you offer remote support or only on-site?
The majority of issues — probably 85% or more — are resolved entirely through remote support, which is faster and less disruptive for you. For issues that genuinely require hands on hardware, we dispatch a technician. We cover the Central Valley for on-site visits, and our remote support is available to any business in California and beyond.
What makes Cowboy MSP different from larger national MSPs?
We're local, which means we have real accountability. You can reach a named person, not a call center. When you need someone on-site, we can be there the same day — not next week. We're also small enough that every client relationship matters to us personally, but we run the same enterprise-grade tool stack (N-central RMM, SentinelOne EDR, Cove backup, Proofpoint) that large MSPs charge a premium for.
Can you support multiple office locations?
Yes. We manage multi-site environments regularly — businesses with two or three locations across the Central Valley are common for us, and we can support remote employees anywhere in the US. Our monitoring and management tools are cloud-based, so geography isn't a constraint. Each site gets the same standard of care, and we coordinate everything from a single pane of glass.
Will I have a dedicated point of contact?
Yes. Every client is assigned a dedicated account manager who knows your environment, your priorities, and your team. You're not calling a generic helpdesk and explaining your setup from scratch every time. Your account manager is your advocate inside Cowboy MSP and conducts regular check-ins to make sure everything is running the way you expect.
How do I submit a support ticket?
We give you multiple ways to reach us: email a dedicated support address, call our helpdesk line, or submit through the client portal. We don't require you to use only one channel — whatever is fastest for you in the moment works for us. Tickets are triaged by severity: business-down events jump to the front of the queue automatically.
Do you provide IT consulting and strategic planning, or just day-to-day support?
Both. Day-to-day reactive support is table stakes — what separates a good MSP from a great one is the strategic layer. We conduct regular business reviews where we look at your technology roadmap, upcoming hardware refreshes, licensing renewals, and security posture. We help you make smart decisions before you're forced into expensive emergency ones.
What if we're not happy with the service?
We want to earn your business every month. If something isn't working — response times, communication, a technician you didn't click with — tell us. We take feedback seriously and will address it directly. If after a good-faith effort things still aren't right, our agreements include a fair exit process. We don't hold clients hostage, and we have the confidence that most businesses that give us a real shot don't want to leave.
What kinds of websites does CowboyMSP build?
We build three types of custom static websites: Countdown & Event Sites (coming-soon pages, event timers, single-purpose landing pages — $500 flat), Portfolio Sites (clean, memorable sites for creatives, students, and freelancers — $500 flat), and Professional Business Websites (multi-page sites for service businesses, built to rank and convert — from $2,500). Every site is hand-coded in HTML5, CSS3, and JavaScript. No WordPress, no page builders, no monthly CMS fees.
Do you build e-commerce or online store websites?
No — CowboyMSP does not build e-commerce or online store websites. We specialize exclusively in custom static sites: business websites, portfolios, landing pages, and event sites. Our focus on static HTML5/CSS3/JavaScript means blazing-fast performance and zero backend complexity, but it isn't suited for product catalogs or shopping carts. If you need an online store, we're happy to point you toward the right platform.
How much does a website cost?
Our pricing is flat-rate and transparent: Countdown/Event Sites — $500 flat. Portfolio Sites — $500 flat (1–3 pages, gallery, up to 2 revisions). Professional Business Websites — from $2,500 (multi-page, SEO-ready, contact form, maps, full branding). Additional pages beyond the standard set are $200/page. Extra revision rounds are $75 each. Rush delivery for simple/portfolio sites is an additional $200. You always know the price before we start.
How long does it take to build a website?
Simple countdown and portfolio sites are typically delivered in 5–7 business days. Professional business websites take 2–4 weeks from the time we receive your content and feedback. Rush delivery is available for simple and portfolio sites (48–72 hours) for an additional $200.
What technology do you use to build websites?
Every CowboyMSP website is hand-coded in pure HTML5, CSS3, and JavaScript — no WordPress, no Wix, no page builders. This means your site loads fast, has no plugin vulnerabilities, and doesn't require monthly software subscriptions to stay functional. You own clean, portable code that works anywhere.
Do you offer website hosting?
Yes — hosting is optional and flexible. Self-Managed ($0/month) — we hand you the files, you host on Cloudflare Pages, GitHub Pages, Netlify, etc. CowboyMSP Managed Hosting (from $25/month) — we handle hosting, SSL, CDN, and uptime monitoring. Domain Management ($15/month) — we manage your domain, renewals, and DNS (included in Standard Care Plans and above).
What are the monthly care plans?
Optional monthly plans keep your site healthy after launch: Basic — $25/mo (managed CDN hosting). Standard — $60/mo (hosting, uptime monitoring, minor content updates, Google Analytics, domain management). Pro — $100/mo (everything in Standard plus priority support and more extensive monthly updates). All plans are optional — self-hosting is always free.
Will my website work on mobile devices?
Yes — every site we build is fully mobile-responsive. We design and test across phones, tablets, and desktops. Mobile performance is a core SEO signal, so we build mobile-first on every project.
Is SEO included in the website build?
Yes. Every professional business website includes on-page SEO foundations: proper heading structure, meta titles and descriptions, canonical tags, Open Graph tags, schema markup, fast load times, and mobile optimization. Your site is technically ready for Google from day one.
What do you need from me to get started?
We need: your logo and brand colors, any photos you want to use, the text/copy for each page (or a brief so we can write it), and your goal for the site. For simple sites, a short form submission is all it takes. For business websites, we'll schedule a brief discovery call first.
How does the revision process work?
Every project includes two rounds of revisions at no extra charge. After the initial build you review and provide feedback, we revise and present the updated version. Additional revision rounds beyond two are $75 each.
Do you serve businesses outside of California?
Yes — our web design service is fully remote and available in all 50 states. Location is never a barrier. View our 50-state coverage here.
Will I own the website when it's done?
Yes, 100%. Once delivered and paid, all the HTML, CSS, and JavaScript code is yours — no licensing fees, no platform lock-in, no dependency on us. You can host it anywhere, modify it, or hand it to another developer.
Can you redesign or update my existing website?
Absolutely. Website redesigns are one of our most common requests. Whether your site looks dated, doesn't work on mobile, or isn't converting, we rebuild it from scratch in clean HTML5/CSS3/JavaScript — faster, modern, and platform-free.
How do I get a quote for my website?
Fill out our contact form or visit our web pricing page to see all project types and costs. We respond with a specific quote within one business day — no sales calls, no pressure.
What does "24/7 monitoring" actually mean in practice?
Our RMM (Remote Monitoring and Management) platform runs a lightweight agent on every covered device. It checks CPU load, disk health, memory usage, service availability, patch status, and dozens of other indicators every few minutes. If something looks wrong — a hard drive approaching failure, a server process crashing silently, unusual login activity — we get alerted automatically and can often resolve the issue before you even notice. After-hours critical alerts page an on-call engineer immediately.
What is your response time when we have an issue?
Our SLA commitments are:
- Remote support: Response within 1 business hour for standard issues.
- Critical / business-down events: 24/7 emergency line with a target response under 30 minutes.
- On-site visits: Same business day for most locations in our service area.
Do you support Macs or only Windows?
We fully support both Windows and macOS environments, including mixed shops. We also manage network hardware from vendors like Dell, Cisco, and Ubiquiti, and can support iOS and Android mobile devices enrolled in your MDM policy. If you run a specialized application on Linux, reach out and we'll assess compatibility.
What backup and disaster recovery options do you offer?
We partner with industry-leading platforms including Cove Data Protection (N-able) for image-based server backups, Microsoft Azure and local NAS solutions for file-level backup, and cloud-to-cloud backup for Microsoft 365 data (email, SharePoint, OneDrive, Teams). We test restores regularly — a backup you've never tested is not a backup. Recovery time objectives (RTOs) and recovery point objectives (RPOs) are defined in your service agreement based on your business needs.
Can you manage our Microsoft 365 or Google Workspace environment?
Yes — this is one of our most common service areas. We handle Microsoft 365 licensing, user provisioning and offboarding, Exchange/Teams configuration, SharePoint administration, security policy enforcement (MFA, Conditional Access, Intune MDM), and ongoing support. We are a Microsoft Partner. We can also manage Google Workspace environments and assist with migrations between platforms.
What happens when an employee leaves the company?
We have a defined offboarding checklist: disabling the account across all systems (Active Directory, Microsoft 365, VPN, cloud apps), transferring email and data to the appropriate manager, revoking MFA devices, recovering company hardware, and auditing access logs. This is a security-critical process and we can execute it same-day when given notice. We also offer user onboarding services — getting a new hire's workstation, accounts, and access fully ready before their first day.
What RMM and PSA tools do you use?
We run N-able N-central as our Remote Monitoring and Management platform — one of the most capable RMM tools in the industry. It gives us real-time visibility into every device, automated patch deployment, scripted remediations, and performance trending. On the ticketing and documentation side we use ConnectWise Manage. These aren't budget tools — they're what the largest MSPs in the country use.
How do you handle software patching?
Patching is automated and policy-driven. Windows OS patches are tested and deployed on a monthly cycle aligned with Patch Tuesday. Third-party application patches (Chrome, Adobe, Java, and hundreds more) are deployed on a separate schedule. Critical security patches — those actively exploited in the wild — get expedited deployment, often within 24–48 hours of release. You can review your patch compliance status in the client portal at any time.
Can you manage our servers, or just workstations?
We manage the full stack: workstations, laptops, physical servers, virtual machines (Hyper-V, VMware), NAS devices, network switches, firewalls, and access points. If a device is on your network and business-critical, we want eyes on it. Server monitoring includes disk health, RAID status, event log alerting, service availability, performance baselines, and scheduled maintenance windows.
Do you manage firewalls and network security?
Yes. We manage firewall configurations, firmware updates, VPN setups, and security policy reviews for appliances from Cisco Meraki, Fortinet, WatchGuard, and others. We also design and implement network segmentation to isolate guest Wi-Fi, IoT devices, and sensitive systems like point-of-sale or medical equipment from your main business network.
What endpoint protection do you use?
We deploy SentinelOne as our endpoint detection and response (EDR) platform — a best-in-class solution that uses AI-driven behavioral analysis rather than traditional signature-based antivirus. It catches threats that legacy AV misses, can automatically quarantine infected endpoints, and provides detailed forensic timelines of any incident. Every managed endpoint gets SentinelOne, no exceptions.
How do you handle printers and other peripherals?
Printers, scanners, label printers, and similar peripherals are supported as part of your managed environment. We handle driver deployment, network printer configuration, and troubleshoot connectivity and print queue issues. We don't manufacture or repair physical printer hardware, but we'll work with your vendor if a device needs physical service — and we'll make sure your network side is correctly configured when it comes back.
Can you help us move from on-premises servers to the cloud?
Yes — cloud migrations are one of our most requested projects. Whether you're moving file servers to SharePoint, replacing on-prem Exchange with Microsoft 365, or lifting workloads to Azure or AWS, we plan and execute migrations with minimal disruption. We don't push cloud for cloud's sake — we'll give you an honest assessment of what makes sense to move and what's better left on-premises given your workloads and budget.
Do you provide hardware procurement?
We can source and configure workstations, laptops, servers, networking gear, and peripherals through our vendor relationships. We don't mark up hardware significantly — our value is in the configuration, deployment, and asset documentation, not margins on the gear itself. We work primarily with Dell, Cisco, and Ubiquiti, but can source from other vendors based on your requirements or existing investments.
How do you document our IT environment?
Documentation is built from day one during onboarding and maintained continuously. We document your network topology, server configurations, software licenses, vendor contacts, warranty information, and critical credentials (stored in an encrypted password manager, never in a spreadsheet). When something breaks at 2am, we're not searching for information — it's already at our fingertips. You get access to your own documentation through the client portal.
How does your pricing work?
We charge a flat per-user monthly fee based on your service tier. That means your bill is predictable and scales simply as you hire or reduce headcount. There are no surprise hourly charges for covered support. Pricing varies by tier — see our MSP pricing page for current rates, or request a custom quote if you have specific needs.
Are there any setup or onboarding fees?
There is a one-time onboarding fee that covers our initial assessment, documentation of your environment, deployment of our monitoring agents, and getting everything properly configured and secured. This fee varies by the size and complexity of your environment. It's not a hidden charge — we'll quote it clearly upfront before you sign anything.
What's not included in the monthly fee?
Monthly managed services cover ongoing support, monitoring, patching, and administration of your existing environment. Items typically billed separately include:
- Hardware purchases (servers, workstations, networking gear)
- Software licenses (Microsoft 365, specialty applications)
- Major project work (new server deployments, office relocations, large migrations)
- After-hours emergency on-site dispatch beyond SLA (rare)
Can I cancel if I'm not satisfied?
Our standard agreements include a 30-day notice period to cancel. If we're truly not meeting your needs, we'd rather have an honest conversation and fix the problem — or help you transition gracefully — than hold you hostage to a contract. We'll provide full documentation of your environment and assist with a smooth handoff to whoever takes over.
What are your service tiers?
We offer three primary tiers. Essentials covers the foundational stack: RMM monitoring, patch management, EDR, and helpdesk support. Business adds advanced security layers, Microsoft 365 management, and backup. Enterprise includes everything in Business plus SOC monitoring, vCISO consulting, compliance management, and enhanced SLAs. Visit our pricing page for current per-user rates on each tier.
Is pricing per device or per user?
Per user — which is the fairest way to do it. Each user gets coverage for their workstation, laptop, and mobile device under a single seat. We don't nickel-and-dime you for each endpoint. Servers are priced separately as a line item since they require distinct monitoring and maintenance work above and beyond a typical user seat.
Do you charge extra for after-hours or emergency support?
No. If you're on a managed services agreement, after-hours and emergency support for covered services is included in your flat monthly fee. There's no overtime surcharge, no emergency call fee, no minimum hour billing. The predictability of your IT costs is the whole point of managed services — surprise invoices defeat that purpose entirely.
What happens to our rate if we hire more employees?
Your monthly invoice scales up by the per-user rate for each new seat. We true up quarterly — so if you hire in January and March, we adjust at the April billing cycle rather than sending mid-month invoices. If headcount drops, the same process applies in reverse. There's no penalty for scaling down.
Do you offer discounts for annual prepayment?
Yes. Clients who prepay annually receive a discount versus the standard monthly rate. The exact percentage depends on your tier and seat count — ask us for a quote that includes the annual prepay option alongside the monthly rate so you can compare. Many businesses find the annual option makes budgeting even more predictable.
Are there any price increases during our contract term?
We do not increase prices during an active contract term. Any rate changes take effect only at renewal, and we give at least 60 days' notice before a renewal with a rate adjustment. We're not in the business of locking you in at one rate and quietly raising it — that's not how we'd want to be treated, and it's not how we operate.
What does the onboarding fee cover exactly?
The one-time onboarding fee covers the labor to properly set up your environment: conducting the initial security and infrastructure assessment, documenting your network and systems, deploying monitoring agents to every device, configuring your backup jobs, enrolling endpoints in EDR, and establishing your security baselines. It's a real investment of engineer time — typically 10–20 hours depending on your size — and doing it right at the start prevents problems for years.
Can we do a month-to-month agreement instead of annual?
Yes, month-to-month is available at a slightly higher per-user rate. We understand some businesses aren't ready to commit to a 12-month term — particularly if they've been burned by a previous provider. We'd rather earn a long-term relationship than force one. Most clients who start month-to-month end up moving to annual once they see how we operate.
Do you offer nonprofit or education pricing?
We do offer discounted rates for registered nonprofit organizations. Educational institutions (K-12, community colleges) are evaluated case by case. If you're a nonprofit, mention it when requesting a quote and we'll apply the appropriate discount from the start. We believe in supporting organizations that do important work in our community.
What payment methods do you accept?
We accept ACH bank transfer, credit card, and check. ACH is our preferred method as it eliminates processing fees for both parties. Credit card payments may include a small processing surcharge depending on your agreement. Invoices are sent at the beginning of each billing cycle with net-15 terms for established clients.
Will I receive itemized invoices showing what I'm paying for?
Yes. Every invoice breaks down your per-user fees by tier, any add-on services, server seats, and one-time items separately. Nothing is bundled into a single opaque line item. If you ever have a question about a charge, your account manager can explain it line by line. Transparency in billing is something we take seriously.
What cybersecurity protections are included?
Our managed security stack includes endpoint detection and response (EDR), managed antivirus, automated patch management for Windows and third-party apps, DNS filtering to block malicious websites, dark web monitoring for your company's email domains, multi-factor authentication enforcement, and security awareness training for your staff. Higher tiers add Security Operations Center (SOC) monitoring and advanced threat hunting.
Can Cowboy MSP help us meet HIPAA, PCI, or other compliance requirements?
Yes. We work with healthcare practices, dental offices, insurance firms, and other regulated businesses throughout the Central Valley. We can implement the technical controls required by HIPAA (encryption, access logging, BAA agreements), PCI DSS (network segmentation, cardholder data protection), and other frameworks. We're not a compliance law firm — for legal interpretation of regulatory requirements you'll want a compliance attorney — but we handle the technical implementation side thoroughly.
What should we do if we think we've been hacked or hit with ransomware?
Call our emergency line immediately: (209) 497-5758. While you wait, disconnect affected machines from the network by unplugging the ethernet cable or turning off Wi-Fi — do not power them off completely, as this can destroy forensic evidence. Do not pay any ransom demand before speaking with us. If you're an active client, our incident response procedures kick in automatically. If you're not yet a client and you're in crisis, call us anyway — we'll do our best to help.
Do you offer security awareness training for employees?
Yes. We partner with Breach Secure Now to deliver automated phishing simulation campaigns and micro-training modules for your team. Humans are the most commonly exploited entry point in cyberattacks, and regular training measurably reduces your risk. Training is included in our higher service tiers and available as an add-on for others.
What is MDR and do you offer it?
MDR stands for Managed Detection and Response — it's the evolution beyond traditional antivirus. Rather than just blocking known threats, MDR actively hunts for suspicious behavior, investigates alerts, and responds to incidents on your behalf. We include EDR (Endpoint Detection and Response via SentinelOne) on every managed device. Higher service tiers include 24/7 SOC-backed MDR where human analysts review alerts around the clock.
How do you protect against phishing and email-based attacks?
Email is the #1 attack vector for most businesses. We deploy Proofpoint Essentials (or comparable solutions) for inbound email filtering, which blocks malicious attachments, spoofed senders, and phishing links before they reach an inbox. We also enforce Microsoft 365 security baselines including anti-phishing policies, Safe Links, and Safe Attachments. On top of the technical layer, we run regular phishing simulation training so your team recognizes attacks that do get through.
What is multi-factor authentication (MFA) and do you enforce it?
MFA requires a second form of verification — typically an app notification or code — in addition to a password. It's one of the single most effective security controls available, blocking over 99% of account compromise attacks. We enforce MFA on all managed accounts as a baseline requirement — it's not optional. We configure Microsoft Authenticator or compatible apps and handle the enrollment process for your team.
Do you monitor the dark web for our credentials?
Yes. We run dark web monitoring against your company's email domains continuously. When employee credentials appear in breach databases — from past data leaks at third-party services your staff used — we alert you immediately so the affected passwords can be changed before an attacker exploits them. This is included in our standard security stack.
What is a SOC and does Cowboy MSP have one?
A Security Operations Center (SOC) is a team of dedicated security analysts who monitor alerts, investigate threats, and respond to incidents 24/7. We partner with Black Point Cyber for SOC-level monitoring on our Enterprise tier clients — giving you access to a full security operations team without the cost of building one in-house. For Essentials and Business tier clients, our team handles security monitoring during business hours with after-hours coverage for critical alerts.
How do you handle ransomware specifically?
Ransomware defense runs on multiple layers: prevention (patching, EDR, email filtering, MFA, network segmentation), detection (behavioral analysis that catches encryption activity before it spreads), and recovery (immutable offsite backups that ransomware can't reach or encrypt). If a ransomware incident does occur, our incident response process kicks in immediately — isolating affected systems, assessing the blast radius, and initiating recovery from clean backups. We also carry cyber liability insurance and can connect you with a breach attorney if needed.
Do you perform vulnerability assessments?
Yes. We conduct regular vulnerability scans of your network and endpoints as part of our ongoing service. Higher tiers include scheduled external vulnerability assessments that simulate what an outside attacker would see when probing your perimeter. Findings are prioritized by severity and fed directly into our patching and remediation workflow — a vulnerability scan that doesn't result in action isn't worth much.
What is DNS filtering and why does it matter?
DNS filtering intercepts web requests before they connect to malicious domains — blocking malware command-and-control servers, known phishing sites, and inappropriate content at the network level. It works on every device on your network, including phones and tablets, regardless of whether they have an endpoint agent installed. We deploy DNS filtering via Cisco Umbrella or comparable platforms as a standard layer in our security stack.
Can you help us create a cybersecurity policy for our business?
Yes. We help clients develop written information security policies (WISP) that cover acceptable use, password requirements, data classification, incident response procedures, and employee responsibilities. A documented policy is required for many compliance frameworks (HIPAA, SOC 2, cyber insurance applications) and serves as the foundation for a defensible security posture. We use policy templates adapted to your industry and size, then customize them to your actual environment.
How do you handle mobile device security?
We manage mobile devices through MDM (Mobile Device Management) policies — typically Microsoft Intune for businesses already in the Microsoft ecosystem. MDM allows us to enforce passcode requirements, enable remote wipe if a device is lost or stolen, prevent unapproved apps from accessing company data, and ensure company email is only accessible from enrolled, compliant devices. BYOD (bring your own device) environments get containerized company data so personal and work data remain separate.
What cyber insurance considerations should we be aware of?
Cyber insurance applications increasingly require documented security controls — and insurers are auditing claims more aggressively. The controls they most commonly ask about are: MFA on all accounts (especially email and remote access), endpoint detection and response, immutable backups, patch management, and employee security training. Having Cowboy MSP manage your security stack not only protects you — it gives you the documentation to prove those controls exist when you apply for or renew a policy.
What is a cloud phone system and why should I switch from a traditional PBX?
A cloud phone system (also called VoIP or UCaaS) routes your business calls over the internet instead of traditional phone lines. Benefits include: significantly lower monthly costs, features like auto-attendants, call recording, voicemail-to-email, and mobile apps at no extra charge, easy addition of lines without hardware changes, and the ability for employees to take business calls on their cell phones using your company number. Traditional PBX hardware is expensive, inflexible, and requires a vendor visit for almost any change.
What phone systems do you offer?
We primarily deploy and support GoTo Connect, a business-grade UCaaS platform. It includes unlimited domestic calling, video conferencing, SMS messaging, mobile app, auto-attendant, call queues, and call recording. We handle porting your existing phone numbers, provisioning physical desk phones if needed, and ongoing support. See our phone services page and phone pricing for full details.
Can we keep our existing phone numbers?
Yes — number porting is standard practice and we handle it for you. The process typically takes 2–4 weeks and your numbers remain active throughout the transition; there's no gap in service. We coordinate everything with your previous carrier and the new platform.
What internet speed do we need for VoIP calls to sound good?
Each concurrent call uses roughly 100 Kbps of bandwidth — so a standard business internet connection handles dozens of simultaneous calls easily. The bigger factor is Quality of Service (QoS) configuration on your router, which prioritizes voice traffic over general internet browsing. We configure this as part of our phone deployment. A jitter buffer and low latency connection matter more than raw speed. We'll assess your network before recommending a switch to make sure it's ready.
What features come standard with a cloud phone system?
Standard features include unlimited domestic calling, voicemail with email delivery, auto-attendant (virtual receptionist), call routing and ring groups, call recording, hold music, mobile apps for iOS and Android, desktop softphone, and a web-based admin portal. Advanced features like call analytics dashboards, CRM integrations, video conferencing, and SMS/MMS vary by plan. We'll map your current system's features to the new platform before migration so nothing is lost.
How does the auto-attendant work?
The auto-attendant answers calls with a custom greeting and routes callers based on their input — press 1 for sales, press 2 for support, etc. — or by time of day (business hours vs. after hours). You configure it through the web portal or we can configure it for you. Changes take effect immediately with no hardware involvement. No more calling a phone company and waiting a week for a simple menu change.
Can employees use the system on their personal cell phones?
Yes. Both RingCentral and GoTo Connect have mobile apps that give employees full access to the business phone system from their personal iPhone or Android — calls, voicemail, messaging, and even video meetings. The app displays your business number as the caller ID, not the employee's personal cell. This is especially useful for remote workers and field staff who need to stay reachable without giving out personal numbers.
What happens to calls if our internet goes down?
You configure failover rules in advance. Typically this means calls automatically reroute to mobile phones or an alternate number when your primary internet connection is unavailable. RingCentral and GoTo Connect both support this natively — you set it up once and it activates automatically. For businesses where phone availability is critical, we also recommend a redundant 4G/LTE backup connection to keep the system online during ISP outages.
How long does the migration take?
A standard migration — porting your existing numbers and cutting over to the new system — typically takes 2–4 weeks. Most of that time is the number porting process with your current carrier, which is regulated and can't be rushed significantly. The actual system setup, user training, and device configuration happens in parallel, so you're not waiting on porting to do the rest. We coordinate the cutover to happen during off-hours or weekends to minimize disruption.
Do we need new desk phones or can we keep our existing ones?
It depends on your current equipment. Many modern SIP-compatible desk phones can be reprogrammed to work with RingCentral or GoTo Connect. Older proprietary PBX handsets (Nortel, older Cisco CallManager) typically can't be reused. We assess your existing hardware before the migration and give you a clear picture of what can stay, what needs to be replaced, and what the desk phone hardware would cost. Many businesses also take migration as an opportunity to go fully softphone (computer + headset) and eliminate desk phones entirely.
What kind of headsets work with the system?
Any USB or Bluetooth headset works with the desktop softphone application — Jabra, Poly (formerly Plantronics), and EPOS are popular choices. For dedicated desk phones, RingCentral and GoTo Connect support standard RJ-9 and 2.5mm headset connections. We can recommend specific models based on your work environment — call center environments have different needs than a quiet private office.
Can the system integrate with our CRM or helpdesk software?
Yes — both RingCentral and GoTo Connect offer integrations with major CRM platforms like Salesforce, HubSpot, and Zoho, as well as helpdesk tools like ServiceNow and Zendesk. These integrations enable screen-pop (automatically showing the caller's CRM record when they call), click-to-call from within the CRM, and automatic call logging. The availability of specific integrations depends on your plan tier.
Is call recording legal and how does it work?
Call recording legality varies by state — California is a two-party consent state, meaning all parties must be informed a call is being recorded. We configure the system to play an automatic disclosure message when recording is enabled to keep you compliant. Recordings are stored in the cloud and accessible through the admin portal. Retention periods and access controls are configurable. We recommend discussing call recording practices with your attorney before enabling it.
What support do you provide after the system is set up?
Once the system is live, you have two layers of support: RingCentral or GoTo Connect's own 24/7 technical support for platform-level issues, plus Cowboy MSP for anything related to your network, hardware, integrations, user changes, and day-to-day administration. Adding a new employee, changing a call routing rule, setting up a new ring group — those come to us. You don't need to manage your phone system yourself.
How does pricing work for cloud phone systems?
Cloud phone systems are priced per user per month, with costs varying by feature tier and number of users. Volume discounts apply at higher seat counts. Hardware (desk phones, headsets) is a one-time cost. We provide a full quote that includes the monthly per-seat license, any required hardware, and our setup and migration fee so you have a complete picture of the total investment. Visit our phone pricing page for current rates.
How does the onboarding process work?
After you sign on, here's what happens:
- Week 1: Discovery — we audit your current environment, document all hardware, software, accounts, and network topology.
- Week 2: Deployment — we install monitoring agents, endpoint protection, backup clients, and configure your security baselines.
- Week 3: Stabilization — we address any issues uncovered in discovery and make sure everything is running cleanly.
- Week 4+: Business as usual — proactive monitoring, regular patching, and responsive support become the norm.
How long does it take to get started?
From signed agreement to fully onboarded is typically 3–4 weeks, depending on the size and complexity of your environment. We can prioritize emergency situations — if you're in a critical state due to a security incident or your previous provider walking out, contact us and we'll fast-track where possible.
What do you need from us to get started?
Primarily: administrative credentials to your key systems (Active Directory, Microsoft 365, firewall), a list of your key applications and vendors, and someone on your side available for a few hours during the discovery week. We're organized and efficient — we'll send you a clear checklist so there are no surprises. Most business owners are pleasantly surprised by how little disruption the process involves.
Can you take over from our current IT person or provider?
Absolutely — IT transitions are something we handle regularly. Whether you're moving from an internal IT employee, a break-fix vendor, or another MSP, we'll manage the transition professionally. We'll request documentation handoff from the outgoing provider, and if that documentation doesn't exist (it often doesn't), we'll build it from scratch during onboarding. We won't leave you uncovered during the switchover.
Do you offer a free assessment before we commit?
Yes. We offer a free IT assessment that includes a high-level review of your network, security posture, backup strategy, and current infrastructure. You'll walk away with a clear picture of where you stand — and we'll give you an honest recommendation, even if it's that you don't need us yet. No hard sell, no pressure. Schedule yours here.
Will there be any downtime during onboarding?
For the vast majority of businesses, onboarding involves zero planned downtime. Installing monitoring agents and deploying security software happens silently in the background during business hours without interrupting users. The only scenarios that might involve brief, scheduled downtime are firewall replacements or major network reconfigurations — and we schedule those outside business hours with advance notice.
How do you handle the transition if we currently have no IT support?
Starting from scratch is actually easier than transitioning from a previous provider in some ways — there are no access credentials to chase down, no tool conflicts to resolve, and no bad habits to undo. We conduct a clean baseline assessment, document everything we find, and build your IT environment to our standards from the ground up. We'll identify and remediate any existing issues during discovery.
What if our previous IT provider won't cooperate with the handoff?
Unfortunately this happens. A departing provider withholding documentation or access credentials is an unprofessional but real situation we've navigated before. We know how to recover admin access to most systems, rebuild documentation from scratch, and work around an uncooperative outgoing vendor. We'll be straightforward with you about what we can and can't recover without their cooperation, and build a plan accordingly.
Do you train our employees during onboarding?
Yes. We conduct a brief end-user orientation — usually 30–45 minutes in person or over video — covering how to submit support tickets, how to recognize phishing attempts, password manager usage, and any new tools we're deploying. We also make reference guides available through the client portal. Security awareness is an ongoing program, not a one-time event, so training continues after onboarding through our phishing simulation and training platform.
What documentation will we receive after onboarding?
At the end of onboarding you receive a complete IT runbook: network diagram, device inventory with serial numbers and warranty dates, software license register, vendor and ISP contact list, admin credential documentation (in encrypted storage), backup configuration details, and your security baseline summary. This documentation is maintained and updated by us throughout the relationship — it's a living record, not a snapshot that goes stale.
How do you handle data security during the onboarding process?
Any credentials or sensitive information you share with us during onboarding are stored immediately in our enterprise-grade encrypted password manager (IT Glue). We operate on a need-to-know basis internally — only the engineers working your account have access to your credentials. We can sign an NDA before onboarding begins if your organization requires it. We carry professional liability insurance and are happy to provide our security and compliance documentation on request.
Can we run a pilot with just part of our team before going all-in?
Yes. Some larger businesses prefer to pilot our service with a single department or location before rolling out company-wide. This is a perfectly reasonable way to evaluate us in a real environment. We'll agree on a defined pilot scope, success criteria, and timeline upfront. Pilot pricing applies during the test period, and transitioning to a full agreement is straightforward once you're satisfied.
What happens if we need to pause or reduce service?
We understand business circumstances change. If you need to reduce headcount coverage temporarily — during a layoff, for example — we can adjust your seat count at the next billing cycle. We don't offer service pauses (our monitoring infrastructure remains active regardless), but we'll work with you on billing adjustments during genuinely difficult circumstances. We'd rather retain a client through a tough period than lose them over a rigid contract.
How do we escalate issues if we're not happy with a support response?
Every client has a named account manager who is your escalation path. If a ticket isn't being resolved to your satisfaction, email or call your account manager directly — not the general helpdesk queue. Your account manager has the authority to reprioritize tickets, assign senior engineers, and get involved personally. For anything that reaches a critical level and isn't moving, our principal engineer is also available as a final escalation.
Is there a client portal and what can we do in it?
Yes. You get access to our client portal where you can: submit and track support tickets in real time, view your device inventory and asset list, access your IT documentation, review patch compliance reports, and see your billing history. You can also add or remove users from your managed seat count through the portal. We find that businesses who actively use the portal have a better experience because they have full visibility into what's happening with their IT at all times.
STILL HAVE QUESTIONS?
Our team is happy to answer anything not covered here — no commitment required.