Managed IT and cybersecurity for Maryland professional services firms.
EDG.tech runs IT and security for consulting, engineering, architecture, staffing, and marketing firms across Gaithersburg, Rockville, Bethesda, Germantown, Washington, DC, and Frederick: client files protected client by client, laptops that work from any client site, the controls to pass a client security questionnaire, and 24/7 monitoring. Complete is $100 per user per month; Essentials is $45 per device per month.
Who this is for
For firms of roughly 5 to 100 people that sell expertise and hold client information to deliver it: management and IT consultants, engineering and architecture practices, staffing and recruiting firms, marketing and PR agencies. Firms that are themselves IT or security providers, and firms large enough to have a CISO, are not who we are built for.
What is at stake for a professional services firm?
The questionnaire comes before the contract
Larger clients now send a vendor security questionnaire with the master services agreement: multi-factor authentication, endpoint protection, encryption, backup, incident response, cyber insurance, and a named person responsible. A firm that answers no, or cannot answer, loses the work to one that can. There is no statistic for the deals you never hear about.
Invoice fraud is built for firms that bill by the project
The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints and $3.05 billion in losses in 2025. The professional services version is a client paying a real invoice to a fraudulent account after a spoofed email from your firm changed the remittance details, which leaves you unpaid and your client's trust gone.
A breach of client data is reportable, and it is your name on the notice
Maryland's Personal Information Protection Act requires reasonable security for personal information you hold and notice to affected individuals within 45 days of discovering a breach, and most client contracts add their own notice clauses, often 24 to 72 hours. A consultant's laptop with an unencrypted drive and a client roster on it meets every one of those definitions.
Source: Maryland Attorney General: PIPA guidelines for businesses
What do clients and contracts ask of a professional services firm?
Professional services firms rarely face a sector regulation of their own; the obligations come from clients and contracts. Master services agreements now carry security schedules that require encryption, multi-factor authentication, incident notice within a set number of hours, and the right to audit. Firms serving healthcare clients sign business associate agreements; firms serving financial clients inherit Safeguards Rule flow-downs; firms serving government contractors inherit controls from their customers' frameworks. Maryland's Personal Information Protection Act applies to the personal data in your files, and professional liability and cyber-insurance carriers ask for the same controls at renewal. EDG.tech builds the controls into the plan and maintains the evidence, so the security schedule in a contract is something you sign with confidence rather than hope.
How does EDG.tech serve professional services firms?
Questionnaire answers that are true
We keep a current statement of your controls, policies, and insurance mapped to the questions clients actually send, with evidence behind each answer, and we sit with you on the ones that need a sentence rather than a checkbox, so proposals go out the same week the questionnaire arrives.
Project files separated by client, by design
Shared drives and collaboration spaces are organized so each client's files, drawings, and deliverables are visible only to the team on that engagement, with external sharing controlled and logged, and everything archived and retained to the contract's terms when the engagement closes.
Laptops that work from any client's conference room
Encrypted laptops with multi-factor authentication and a secure connection back to the firm, large design and CAD files synced rather than emailed, printing and screen sharing that work on a client's network, and a helpdesk that fixes a consultant's machine remotely before the 9 AM meeting.
Billable hours that stay billable
Time tracking, project management, and billing systems kept up and backed up, new hires equipped and productive on day one, departing staff removed the same hour with their files reassigned, and a monthly report that shows utilization lost to IT so the number stays near zero.
Which plan fits a professional services firm?
Enterprise-grade managed IT & cybersecurity, fully managed, 24/7.
See EDG.tech CompleteProfessional services firms belong on Complete. Every consultant carries client data on a laptop, a phone, and a mailbox, and the client questionnaires ask for the monitoring, identity protection, and incident response that only the 24/7 security operations center in Complete provides. Essentials fits a very small practice whose clients have not yet started asking.
EDG.tech Essentials is $45 per device per month. Compare both plans
"Your client's security questionnaire is really asking one thing: will working with you put us at risk? We make sure the honest answer is no, and that you can prove it," says Duane Epperly, founder of EDG.tech.
Professional services IT questions, answered
Can you help us pass a client's security questionnaire?
Yes. We maintain a current statement of your controls, policies, and insurance mapped to the questions clients send, with evidence behind each answer, and we help you write the answers that need explanation. Firms on Complete typically meet the multi-factor authentication, endpoint, encryption, backup, and monitoring requirements out of the box.
What does managed IT cost for a consulting or engineering firm?
EDG.tech Complete is $100 per user per month and includes helpdesk, patching, encryption, multi-factor authentication, backup, email and identity protection, and 24/7 monitoring. A 20-person firm pays $2,000 per month. Essentials is $45 per device per month for smaller practices. Add-ons such as a client-specific compliance project are quoted per client environment.
Our staff work from client sites and home. Can you support that?
Yes. Encrypted laptops with multi-factor authentication connect securely from any network, files sync rather than travel as attachments, and the helpdesk fixes most problems remotely without the consultant coming to an office. We also set up the client-site essentials, printing, screen sharing, and guest networks, so the first day on site is not spent on IT.
How do you keep one client's files away from another's?
We structure your shared drives and collaboration spaces by engagement, so only the assigned team sees each client's files, with external sharing controlled and logged. When an engagement ends, its files are archived and retained to the contract's terms, and access is removed. Conflicts of interest become a setting rather than a policy memo.
Ready for IT you never have to worry about?
Book a free 30-minute consultation, or start with a free security assessment. You get a fixed price within two business days. No pressure, no jargon.