Frequently Asked Questions
Get clear answers about managed IT, cybersecurity, compliance, and technology funding, from a team that has supported nonprofits for more than 35 years.
About PCS
-
PCS primarily serves nonprofits with 50 to 200 employees: healthcare and recovery, housing, disability services, education, and workforce development organizations. We also support commercial businesses, and you can view the full list of industries we serve here. Nonprofit work shapes how we operate; our team serves on nonprofit boards and runs digital equity programs across the Bay Area.
-
PCS is based in the San Francisco Bay Area and supports organizations throughout California. Our help desk assists remote, hybrid, and in-office employees wherever they work, while local field technicians provide on-site support when hands-on help is needed.
For organizations with multiple offices or employees in different locations, we manage technology as one connected environment. Your team receives consistent support, security, and strategic guidance without having to coordinate separate providers for every location.
-
Founder Dan Hernandez built PCS around Bay Area nonprofit work, and that focus still defines the company. We plan technology around mission priorities, grant cycles, and lean budgets, and we explain every decision without jargon.
We also stage improvements over time. Competitors often push a full overhaul in month one; we start with free and low-cost fixes and schedule the rest across your budget cycles. -
Yes. In a co-managed arrangement, your internal team keeps day-to-day coverage while PCS adds security tooling, monitoring, and planning support. We can also manage everything directly. Either way, you decide the division of responsibilities.
Managed IT Support
-
An agreement covers help desk support for every employee, device and network management, security monitoring, Microsoft 365 and cloud administration, and quarterly planning reviews. At onboarding, we list what the agreement covers and what would be a separate project, so costs stay predictable.
-
Yes — every employee can contact the help desk, not only a designated IT contact. We introduce ourselves to your whole staff during onboarding. A ticket stays open until the person who reported it confirms the fix.
For after-hours emergencies, call the support line and press option 4 to reach the on-call technician.
-
Yes. PCS plans and runs projects such as office moves, server migrations, phone system upgrades, and hardware replacement. When we deploy new equipment, we build the devices, migrate your data, and hold the old hardware for 45 to 60 days before secure destruction, in case anything was missed.
Cybersecurity & Risk
-
Every agreement includes core protections: endpoint security (protective software on each device), patch updates, monitoring, and backups. Organizations with higher risk or compliance requirements add layers such as the Advanced Security Stack, quarterly CyberWatch™ security assessments, and policy documentation. We help you decide which layers fit your risk and budget.
-
Nonprofits hold client records, donor information, and health data, and they often have weaker defenses than businesses of the same size. Attackers look for that combination. Organizations serving vulnerable people face some of the highest data risk, which is why PCS focuses on protecting them.
-
Security is built in layers, and most organizations add them in this order:
Managed, patched equipment with documented processes for granting and removing access
Protective tools against phishing, ransomware, and other current threats
Ongoing monitoring, with quarterly assessments to find and fix weaknesses
Written security policies and staff training
Virtual security leadership, for organizations with compliance obligations
PCS helps you add each layer at a pace your budget supports.
-
Yes. We can run structured security awareness training that teaches staff to recognize phishing and other common attacks. We document completion for every employee, a record insurers and auditors increasingly ask to see.
Compliance & Cyber Insurance
-
Yes. Insurers now ask for evidence: written security policies, employee training records, and multi-factor authentication (a second verification step at login). PCS builds and maintains that documentation through Cyber Liability Essentials, so the evidence exists before a renewal or claim requires it.
-
Your services and data determine your obligations. Organizations handling protected health information fall under HIPAA, the federal health-privacy law. Others face requirements from funders, state privacy law, or cyber insurance policies.
PCS reviews your obligations with you and structures quarterly reviews around them, including your compliance contacts when useful.
-
Yes. We create and maintain the core documents: an acceptable use policy with tracked approvals, records of critical data assets, training documentation, and incident response plans. Everything is stored in a repository your leadership can reach even if your systems are down.
Grants & Technology Funding
-
Every agreement includes core protections: endpoint security (protective software on each device), patch updates, monitoring, and backups. Organizations with higher risk or compliance requirements add layers such as the Advanced Security Stack, quarterly CyberWatch™ security assessments, and policy documentation. We help you decide which layers fit your risk and budget.
-
Nonprofits hold client records, donor information, and health data, and they often have weaker defenses than businesses of the same size. Attackers look for that combination. Organizations serving vulnerable people face some of the highest data risk, which is why PCS focuses on protecting them.
-
Security is built in layers, and most organizations add them in this order:
Managed, patched equipment with documented processes for granting and removing access
Protective tools against phishing, ransomware, and other current threats
Ongoing monitoring, with quarterly assessments to find and fix weaknesses
Written security policies and staff training
Virtual security leadership, for organizations with compliance obligations
PCS helps you add each layer at a pace your budget supports.
-
Yes. We can run structured security awareness training that teaches staff to recognize phishing and other common attacks. We document completion for every employee, a record insurers and auditors increasingly ask to see.
Secure AI
-
Yes. Public AI tools can expose donor and client data, so we manage AI in two parts.
We write usage policies for tools like ChatGPT and Microsoft Copilot that define what staff may enter. For deeper use, we provide Hatz AI, a platform with SOC 2 Type 2 certification (an independent audit of data-security controls) that restricts each user's data access by role.
Switching to PCS
-
No, a technology transition should bring relief, not disruption. We schedule changes around your operations and communicate each step in advance. If records from your previous provider are incomplete, which is common, our engineers document your environment themselves.
-
We set 30-, 60-, and 90-day milestones. Engineers document your environment, identify gaps, and build a prioritized improvement plan that starts with free and low-cost fixes. After the first 90 days, you move to quarterly reviews with a dedicated account team.
-
Watch for these signs:
Staff stop calling the help desk because they expect slow answers
The same problems recur without a root-cause fix
Security questions get vague answers
Nobody reviews technology plans with leadership
If you recognize these, don’t hesitate to schedule a call.
Pricing & Getting Started
-
Monthly cost depends on your employee count, devices, systems, and security requirements, so we quote after a conversation rather than before. Improvements are staged across your budget cycles in a prioritized plan. You will always see what an agreement covers before you sign.
-
Projects and equipment purchases are separate from the monthly agreement, and you will always know which is which. At onboarding we define what the retainer covers and what counts as a project, so no invoice comes as a surprise.