About

Security leadership, with hands on the keyboard.

Figure IT is led by Nick Rutherford, a security engineer who sets how the work gets done: the baseline every client starts from, the playbooks every alert is investigated against, and the procedure that runs when something is genuinely wrong. He still spends his day in security operations, so the standards come from the work itself.

Who leads Figure IT.

Nick founded Figure IT to give small businesses the security leadership they would otherwise only get by hiring a security manager. He is the technical lead behind every engagement: he designs the security baseline, writes the investigation playbooks and response procedures the work runs on, and sets the standard for when an alert becomes an incident.

His work covers the whole environment a small business depends on: Microsoft 365 and Google Workspace tenants, endpoints, networks, backups, and now the AI tools connected to them. He also guides clients through compliance, turning frameworks like CMMC and HIPAA into a plan a business can actually finish.

Every procedure is written down, so the work never depends on one person remembering how it's done. That is a leadership decision as much as a technical one. It's what lets work move between people without anything getting lost.

What Nick leads

  • Security operations: triage standards and written verdicts
  • Incident response: severity, containment and post-incident review
  • Compliance readiness for CMMC, HIPAA, PCI-DSS and SOC 2
  • Site takeovers, run to a written survey, cutover and close-out procedure
  • Security assessments of AI integrations, against ten named risks

Why we do it this way.

Small businesses get sold enterprise security theatre or nothing at all. The pitch is usually a dashboard nobody reads and a contract that renews itself. Meanwhile the actual gaps are boring and unglamorous: a shared admin account with no MFA, a backup that hasn't been restored since it was installed, a firewall subscription that lapsed in 2023.

We work on the boring things first, because that is where breaches actually come from. When the fundamentals are solid we move up the stack, and we tell you plainly when something isn't worth buying yet.

The other half of the job is being reachable. Most of the frustration we hear about previous providers isn't technical. It's a ticket that sat for four days and a person who never called back.

The newer half of the work is AI. We build the integrations that connect AI assistants to real business systems, and we assess the ones other people built. It ended up in our hands for the same reason the rest did: it's an access problem wearing a different hat.

What that looks like day to day

  • You get a named technician who knows your environment
  • Alerts are reviewed by a human, with a written verdict
  • Documentation is yours, and you get it if you leave
  • Quarterly reviews cover risk and budget, not upsells
  • Every incident written up in plain English, with what changed after it

Who we work with.

We work with businesses that have outgrown "the nephew who's good with computers" but don't need an enterprise contract. If you're a professional services firm, contractor, medical practice, multi-location operator, or DoD supplier with 10 to 150 seats, you're who we built this for.

That includes businesses whose IT is already covered and who just need someone watching their security. We're based in metro Atlanta and go on-site anywhere in the area. Remote support is available anywhere.

One line we hold: we don't take on clients who refuse a minimum security baseline. MFA and endpoint protection aren't upsells. They're the floor.

Writtenevery engagement scoped and quoted in writing before work starts
10–150people using computers: the size we're built for
Atlantaon-site across metro Atlanta, remote support anywhere
Yoursdocumentation and credentials, handed over if you ever leave

Want to talk to the people who'd actually be supporting you?

Start with a short call about what you run.

Start a conversation