Skip to main content

Articles

Practical write-ups on the security and compliance problems we run into with small businesses in regulated industries. Each one explains what is actually required and what to check at your own office.

How to Choose an IT Provider for Your Law Firm in Kansas City

A law firm's IT problems are ethics problems: confidentiality, matter-based access, breach obligations, and litigation holds. The questions that separate providers who understand that, written for Kansas City firms.

Read the write-up

How to Choose a HIPAA-Capable IT Provider in Kansas City

Every IT company says yes when asked about HIPAA. The questions that actually separate providers: the BAA, the security risk analysis, documentation, and the red flags that end the conversation, written for Kansas City practices.

Read the write-up

Can You Turn On Copilot Without Breaking HIPAA?

The free Copilot and the paid Microsoft 365 Copilot are different products under HIPAA. What the BAA actually covers, the permission problem Copilot exposes, and what to check before a medical practice turns it on.

Read the write-up

Two Weeks Down for a Fifteen-Minute Fix

A real client incident: the link between two offices went down for about two weeks, and the repair itself took fifteen minutes. Why the outage was an ownership problem rather than a technical one, and what to check at your own business.

Read the write-up

The Renewal That Never Happened

A real client incident: a 20-year-old domain expired with the bill fully paid, because the renewal depended on one person. How a one-day total shutdown got resolved, and what to check at your own business.

Read the write-up

Moving Your Microsoft 365 Away From GoDaddy: What's Actually Involved

What moving Microsoft 365 off GoDaddy's reseller arrangement actually involves: what breaks, what stays put, and the questions to answer before you start.

Read the write-up

Someone Is Sending Emails Pretending to Be Your Business. Here's What's Going On.

How to tell forged email from a genuinely compromised mailbox, what to do first in each case, and why SPF, DKIM, and DMARC only help once DMARC is set to enforce.

Read the write-up

An Employee Clicked a Phishing Link. Do These Things in This Order.

The order of operations after someone clicks a phishing link, from working out what clicked means through isolating the machine and writing the incident down.

Read the write-up

Your Cyber Insurance Renewal Is Asking Questions You Can't Answer. That's Fixable.

What cyber insurance questionnaires are actually asking, why answering yes without checking can cost you the coverage, and how to use the renewal window to close the gaps.

Read the write-up

The Security Plan Your Tax Firm Is Supposed to Have in Writing

Tax preparers fall under the FTC Safeguards Rule and need a Written Information Security Plan. What a WISP contains, and where firms fall short of the one they signed.

Read the write-up

The Risk Assessment Your Practice Signs Off On Every Year

Why a medical practice needs a current, dated HIPAA security risk analysis on file, the objections that keep it from getting done, and what to check this week.

Read the write-up

The Fake Tech Support Call That Almost Worked

A real client incident: a scam support call that landed while a bookkeeper had a genuine ticket open, how endpoint monitoring caught the software it installed, and what changed afterward.

Read the write-up

See Where Your IT Actually Stands

Free compliance and IT assessment, a $500 value. Actionable findings on where your systems stand and what, if anything, needs attention.

  • Response within 1 business day
  • Written report you can keep
  • Follow-up only if you ask
Book a 15-Minute Call