Written programme support
The technical controls that sit inside a Massachusetts written information security programme: encryption enforcement, access control, authentication, monitoring, disposal and training records.
Remote IT Support · Boston, MA
Orca IT provides remote managed IT, cyber security and help desk to Boston businesses from Gilbert, Arizona. One pod of our own engineers owns your account. Massachusetts has its own written data security requirements, and we build environments that can satisfy them.
Boston, MA
Life sciences, hospitals, universities, asset management and robotics produce clients who ask precise questions and expect precise answers.
Massachusetts is one of the few states with a detailed written data security regulation of its own. Any business holding personal information about a Massachusetts resident is expected to maintain a written information security programme, with specified elements: designated responsibility, risk assessment, access controls, encryption of personal information on laptops and in transit, monitoring, vendor oversight and staff training. It is not optional and it is not vague. We build the technical half of that, encryption enforcement, access control, authentication, monitoring and logging, secure disposal, and provide documented evidence to sit inside your programme. The programme itself remains yours; we do not sign off on your compliance.
The life sciences sector in Kendall Square, the Seaport and out along the western suburbs adds another layer. Research data with real value, sponsor and partner security reviews, laboratory instruments running vendor-locked operating systems that must not be patched, and collaboration with external institutions that requires controlled sharing rather than blanket permissions. Segmentation, access governance and immutable backup are the practical answers, delivered under Pod Guard.
Financial services, including asset and investment management firms across the Financial District and Back Bay, bring documented control expectations of their own, along with an unusually high exposure to wire fraud and executive impersonation. Healthcare around the Longwood area brings HIPAA technical safeguards. And the region’s university-adjacent startups bring the familiar problem of a company that quadrupled headcount before anyone reviewed who had administrator rights.
We are a family-owned company in Gilbert, Arizona and we have no Boston office and no Massachusetts staff. Identity, cloud, server, security and help desk work runs through remote support and Pod Care. Physical jobs, a failed drive, rack work, cabling in an older building, are handled by a vetted local technician we arrange with your consent while your pod directs the work and does the configuration. Corridor neighbours use the same arrangement in New York, Philadelphia and Washington DC.
Massachusetts expects personal information to be encrypted on portable devices and in transit. We enforce it, report on it, and can show you which machines are compliant today.
Services
Six areas weighted for life sciences, healthcare, finance and research-adjacent businesses.
The technical controls that sit inside a Massachusetts written information security programme: encryption enforcement, access control, authentication, monitoring, disposal and training records.
Vendor-locked instrument systems segmented onto their own network with explicit rules, monitored, and with configuration and output data backed up independently of the instrument.
External sharing that is scoped and time-limited rather than open, role-based access to research data, and audit trails showing who reached what and when.
Email authentication, lookalike domain monitoring, mailbox rule alerting, phishing-resistant MFA and targeted simulation for the finance staff who actually receive the fraudulent instructions.
Encryption, unique user identification, audit controls, automatic logoff and restore-tested backups, documented so your risk assessment references real evidence.
Administrator rights audited, stale accounts removed, joiner and leaver processes documented, and licensing right-sized after a period of fast, unplanned hiring.
How It Works
We record which systems we access and which are excluded, and the list of managed devices is available to you on request at any time.
Attended sessions use a one-time link that you launch. Unattended agents are only installed on machines you approve, and they are inventoried.
Outbound encrypted connections, visible on screen for the whole session, with a single click to take back control or disconnect entirely.
Session logs, change records and test results are kept and made available, which is exactly what a written security programme expects a service provider to produce.
Arizona ignores daylight saving, so we are three hours behind you in summer and two in winter. Your 5pm is our early afternoon.
No. Orca IT is family owned and operates from Gilbert, Arizona, supporting Boston clients remotely with our own engineers. When physical work is genuinely required we arrange a vetted local technician for that task only, with your consent, while our engineers direct the visit and handle configuration.
We implement and evidence the technical elements: encryption of personal information on portable devices and in transit, access control and authentication, monitoring and logging, secure disposal, and training records. The written information security programme belongs to your business, and we supply the technical documentation that sits inside it.
They get isolated on their own network segment with explicit firewall rules and no general internet access, with everything that talks to them hardened and monitored. Their configurations and output data are backed up separately so an instrument failure does not cost you a study.
Arizona stays on Mountain Standard Time all year while Massachusetts changes twice, so we are three hours behind Boston from March to November and two hours behind from November to March. Our afternoon covers your close of business and any late escalations.
Yes. We maintain the control documentation, access review records, patch compliance data, endpoint coverage reports and backup test results, and we provide accurate technical answers. Where a control is missing we tell you what it costs to close rather than answering optimistically.
No, it just splits the work. Design, configuration, firewall rules, VLANs and Wi-Fi planning are done remotely by us. The physical installation is scheduled with a local installer working from our specification, and we verify and configure everything once it is in place.
Start with the free assessment and see exactly where your environment stands against what you are expected to maintain.
Talk to Your Pod
The free Deep Dive reviews identity, devices, access control, encryption, logging and backups, and shows you where a written information security programme would currently fall short.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.