Recommended Technology Platform

Every tool and standard we recommend has been tested in real-world environments. These are the platforms and practices we trust and deploy for our clients every day.

Last reviewed: April 2026

General

There is no one-size-fits-all for equipment, but we have several best-practices we recommend to ensure your environment is supportable and reliable. This is a general list, but your business may have more stringent requirements that we will bring up with you over time. In addition to any requirements below, we recommend all equipment either has an active warranty or a spare is kept on-site at all times.

Unlimited Support Clients

For clients with unlimited support plans, it is essential to meet or exceed the following requirements to maintain eligibility. Failure to do so may result in additional charges.

All Other Clients

For clients without unlimited support, these baseline standards are not mandatory for service; however, not meeting them may lead to issues affecting your business's security, stability, or overall suitability.

Computers

We recommend laptops and desktops with the following minimum specifications and an active warranty from the manufacturer.

  • Current Generation Intel Core i5/i7/i9 or Core Ultra 5/7/9 Processor within 5 Prior Generations
  • 16GB RAM (memory)
  • 512GB Solid State Drive (SSD) for storage
  • Windows 11

Windows 10 and all previous versions are no longer supported or updated by Microsoft

We do not recommend non-Professional versions of Windows (sometimes referred to as Home) for business use.

Apple Mac

Where Apple Mac laptops and desktops are supported and allowed by business and software requirements and organizational policies, we recommend systems with Apple Silicon processors. Specifications will vary by intended use case.

Why?

  • Hardware warranties typically last 1–3 years.
  • After 4–5 years, performance degradation and compatibility issues with newer OS/software may become noticeable.
  • Security updates for older hardware may become limited.

Servers

Servers should be selected to be suitable for the customer's business needs and software requirements. Servers should run an operating system and applications currently under vendor support, and the life expectancy of the server should be considered when choosing an operating system to ensure support and updates are available at least through the server's expected lifetime. Servers should have active next-business-day warranties to minimize the risk of extended downtime and unexpected repair expenses.

  • Current Generation Intel Xeon Processor within 7 prior Generations (Core i5/i7/i9 or Core Ultra 5/7/9 in some circumstances)
  • 32GB RAM (memory)
  • 1TB Solid State Drive (SSD) for storage
  • Windows Server 2016 Standard* (for more than 10 computers) or Windows 11 Professional (for fewer than 10 computers)
  • RAID1 or better for storage redundancy suggested
  • Dual power supplies for power redundancy are suggested

Windows Server Support End Dates

*Please note the following Windows Server support end dates, subject to change by Microsoft:

Version Notes
Server 2025 Windows Server 2025: Mainstream support through October 9, 2029; extended security updates through October 10, 2034.
Server 2022 Windows Server 2022: Mainstream support through October 13, 2026; extended security updates through October 14, 2031.
Server 2019 Windows Server 2019: Mainstream support through January 9, 2024; extended security updates through January 9, 2029.
Server 2016 Windows Server 2016: Mainstream support was through January 11, 2022; extended security updates through January 12, 2027.
2012 R2 & older Windows Server 2012 R2 and all previous versions are no longer supported or updated by Microsoft.

Microsoft's Product and Services Lifecycle Information page is the official reference for the above determinations.

Why?

  • Server hardware lifecycles may be longer, but firmware and driver support may drop after 5–7 years.
  • Newer OS versions may not support older hardware.
  • Reliability risk increases after 5–7 years (fans, drives, power supplies).

Server Backups

We recommend that a backup hard drive or network storage device is used for local backup of the server. This device should use high-quality enterprise storage drives and should be sized to hold at minimum 3 full backups of the server(s) it is meant to protect, or more depending on the retention requirements of your organization. If possible, the local storage destination should use unique access credentials separate from the rest of the network, to reduce the likelihood of malicious tampering or deletion, and should be located on an isolated network segment with limited access.

All backups should be copied as soon as reasonable to a secured and isolated storage location physically away from the premises of the server(s) being backed up, encrypted using 128-bit or higher encryption with a strong, unique encryption key that is stored separately from the backups, and in a location inaccessible without unique credentials.

Firewall

Our recommended firewall is a Unifi Gateway sized appropriately for internet connection speed, with an active CyberSecure subscription. In some circumstances, a more robust firewall may be needed — in those cases, our recommended firewall is a Fortinet FortiGate F-Series with an active FortiGuard UTM subscription.

Firewall firmware should be periodically reviewed and updated to the latest release on a regular cadence, or more rapidly if a security issue is discovered that may be exploited externally.

Firewalls should be configured to allow the minimum inbound access necessary for the organization to operate (ideally zero, with VPN protection if required), and all administrative management should be restricted and not available from the general internet.

We will not configure nor support a firewall which directly opens Remote Desktop port 3389 (or Remote Desktop running on alternate ports) directly from the Internet to an internal network, due to extremely high security risk.

Switching

Ethernet switching fabrics should be designed for the environment. Where appropriate, quality unmanaged switches may be acceptable, but we highly recommend fully managed switches for all environments. We recommend consistent models and brands when possible to reduce the number of unusual support issues.

Our preferred brands of switches are Unifi and Fortinet.

Wireless

To a greater extent than even switching, wireless needs to be designed for the environment. In all cases, we do not recommend using any wireless provided by an ISP modem or other equipment.

Our preferred brands of wireless equipment are Unifi and Fortinet.

Staff and guest networks should be segmented for security, and staff or other internal wireless networks should be secured with WPA2 security or higher, with a long, random, unique passphrase if not using Enterprise authentication.

Internet Service

We recommend at bare minimum a business-class broadband Internet connection, but this may not be suitable for all purposes. If Internet is required for primary business operations, we recommend at minimum redundant broadband services with one being a business fiber circuit and the other being a cellular connection.

Battery Backup (UPS)

We recommend all servers and critical network infrastructure have appropriately sized battery backups that are regularly tested and maintained.

Security

We recommend all authentication used in the business comply with Current NIST Guidelines for Password Management. For convenience, the key guidelines are summarized below.

Password Creation & Complexity

  • Minimum length of 8 characters for user-created passwords
  • Allow passwords up to 64 characters (longer passphrases are encouraged)
  • Do not require character complexity rules (e.g., uppercase, numbers, symbols)
  • Allow all printable ASCII characters, including spaces and special characters
  • Do not impose periodic password changes unless there is evidence of compromise

Prohibited Practices

  • Do not use password hints or knowledge-based security questions
  • Do not allow context-specific words (e.g., company name, username) in passwords
  • Do not restrict password copy-paste or visibility during entry (to support password managers)

Blocklist Enforcement

  • Check passwords against a blocklist of commonly used, expected, or compromised passwords
  • Reject passwords found in known breach corpuses or dictionary-based lists

Storage & Protection

  • Store passwords using salted, hashed algorithms (e.g., PBKDF2, bcrypt, or scrypt)
  • Use secure, computationally expensive hashing functions to resist offline attacks

Rate Limiting & Throttling

  • Implement rate limiting to prevent brute-force and guessing attacks
  • Lock accounts or introduce delays after a defined number of failed login attempts

Authentication Alternatives

  • Encourage multi-factor authentication (MFA) wherever possible
  • Support passwordless authentication methods (e.g., biometrics, hardware tokens) when feasible

We recommend periodic security awareness training for anyone who has access to critical business systems.

Other Standards

  • All Server and Desktop Software must be Genuine, Licensed, and Vendor-Supported.
  • The environment must have a currently licensed, up-to-date, and Vendor-Supported Antivirus Solution protecting all Servers, Desktops, Notebooks/Laptops, and Email.
  • The environment must have a currently licensed, Vendor-Supported Server-based Backup Solution that can be monitored and send notifications on job failures and successes.
  • The environment must have a currently licensed, Vendor-Supported Hardware Firewall between the Internal Network and the Internet.
  • All Wireless data traffic in the environment must be securely encrypted.
  • Local Admin access is strictly prohibited on all devices and systems.
  • All cabling must be properly labeled and documented.

Costs required to bring a Client's environment up to these Minimum Standards are not included in the service agreement.

Recommended Vendor Partners

The platforms we trust and actively deploy for clients — vetted for reliability, security, and small-business fit.

Security & Threat Protection

Layered defenses against ransomware, phishing, and intrusion.

Field Effect

Field Effect

Our go-to cybersecurity platform for clients who need real protection without a dedicated security team. We deploy and manage Field Effect's EDR, DNS filtering, email security, and identity monitoring — backed by their 24/7 SOC when threats need escalation.

Fortinet

Fortinet

We deploy FortiGate firewalls with active FortiGuard UTM subscriptions for clients who need more than a standard gateway. Our go-to when an environment calls for advanced threat prevention, segmentation, or VPN at scale.

Check Point

Check Point

We use Check Point Harmony Email & Collaboration (formerly Avanan) to protect client Microsoft 365 and Google Workspace environments from phishing, malware, and account takeover — especially for clients where email is the highest-risk attack surface.

Backup & Disaster Recovery

Automated, encrypted, and tested — so recovery is never a question mark.

Opti9

Opti9

Opti9 is the backend platform that powers our Veeam deployments — supplying licensing, cloud storage, and support infrastructure so we can deliver a fully managed Veeam backup solution for clients running on-premises or hybrid workloads.

Veeam

Veeam

We deploy Veeam for clients running on-premises or hybrid workloads, with Opti9 supplying the licensing, cloud storage, and backend infrastructure. Together they deliver a fully managed backup solution with proven protection across virtual, physical, and cloud environments — and restores we actually test.

Networking & Access Control

Reliable, segmented, and secure network infrastructure.

Ubiquiti UniFi

Ubiquiti UniFi

Our preferred networking stack for most small business environments. We design, install, and manage Unifi switches, access points, and gateways — centrally monitored from a single dashboard we control on behalf of clients.

ControlD

ControlD

We use Control D for DNS-layer filtering across client networks and endpoints — blocking malware, phishing domains, and unwanted content before it ever reaches a device. Lightweight to deploy, meaningful reduction in threat exposure.

NordLayer

NordLayer

We deploy NordLayer for clients who need secure remote access without the complexity of managing their own VPN infrastructure. Clean to set up, easy for non-technical staff to use, and reliably keeps remote traffic encrypted.

Splashtop

Splashtop

Our go-to remote access platform — we use Splashtop to securely connect to client devices for support and management, and we deploy it for clients who need reliable Work From Home access to their office computers from anywhere.

Identity & Privilege Management

Control who has access to what — and when.

1Password

1Password

The password manager we recommend and set up for client teams. 1Password makes it practical for non-technical staff to stop reusing passwords and start sharing credentials securely — which is often one of the fastest wins for reducing breach risk.

AutoElevate

AutoElevate

We use AutoElevate to enforce least-privilege access on client workstations — users get the rights they need for specific tasks without running as local admins, which is one of the most effective controls against ransomware and malware execution.

Productivity & Cloud

The tools your team needs to communicate, collaborate, and get work done.

Microsoft 365

Microsoft 365

The productivity platform we manage for the majority of our clients. We handle licensing, configuration, security hardening, and ongoing administration — so clients get the full value of Microsoft 365 without the IT overhead of managing it themselves.

DreamHost

DreamHost

The hosting infrastructure we use to deliver our website hosting and admin service — reliable cloud hosting, managed WordPress, and VPS solutions we operate and support directly for clients.

Hardware & Procurement

Pre-configured, warranted business hardware sourced and deployed by Geekpoint.

Carbon Systems

Carbon Systems

Our preferred source for business computers — Carbon Systems builds Geekpoint-branded machines that arrive pre-configured, tested, and ready to deploy. Strong warranties, reliable hardware, and a procurement process that removes the guesswork from buying the right equipment for each client.

Lenovo

Lenovo

Our preferred hardware brand for workstation and server procurement — business-class laptops, desktops, and servers with strong manufacturer warranties and the build quality we trust for client deployments.

How We Choose Our Technology

Every platform on this page has gone through our internal vetting process. We evaluate tools on security posture, reliability, ease of management, vendor support quality, and total cost of ownership for small business environments.

01

Security Posture

We evaluate how a vendor handles vulnerabilities, patch cadence, and incident response — not just what their marketing says about protection.

02

Real-World Testing

Every tool we recommend has been deployed and stress-tested in live client environments. We don't recommend anything we haven't personally operated under real conditions.

03

SMB Fit

We assess licensing costs, management overhead, and whether a non-technical staff member can reasonably use it — enterprise tools that require a dedicated team don't make the list.

We don't take vendor commissions or referral fees in exchange for recommendations. If a tool makes this list, it's because it genuinely performs — and because we'd be comfortable staking our reputation on it for your business.

Want to Know What's Right for Your Business?

Every business is different. Let's talk about which of these platforms fits your environment, budget, and goals.

Schedule a FREE Consultation