Articles
Practical write-ups on the security and compliance problems we run into with small businesses in regulated industries. Each one explains what is actually required and what to check at your own office.
The Risk Assessment Your Practice Signs Off On Every Year
Why a medical practice needs a current, dated HIPAA security risk analysis on file, the objections that keep it from getting done, and what to check this week.
Read the write-upThe Security Plan Your Tax Firm Is Supposed to Have in Writing
Tax preparers fall under the FTC Safeguards Rule and need a Written Information Security Plan. What a WISP contains, and where firms fall short of the one they signed.
Read the write-upYour Cyber Insurance Renewal Is Asking Questions You Can't Answer. That's Fixable.
What cyber insurance questionnaires are actually asking, why answering yes without checking can cost you the coverage, and how to use the renewal window to close the gaps.
Read the write-upAn Employee Clicked a Phishing Link. Do These Things in This Order.
The order of operations after someone clicks a phishing link, from working out what clicked means through isolating the machine and writing the incident down.
Read the write-upSomeone Is Sending Emails Pretending to Be Your Business. Here's What's Going On.
How to tell forged email from a genuinely compromised mailbox, what to do first in each case, and why SPF, DKIM, and DMARC only help once DMARC is set to enforce.
Read the write-upMoving Your Microsoft 365 Away From GoDaddy: What's Actually Involved
What moving Microsoft 365 off GoDaddy's reseller arrangement actually involves: what breaks, what stays put, and the questions to answer before you start.
Read the write-upSee Where Your IT Actually Stands
Free compliance and IT assessment, a $500 value. Actionable findings on where your systems stand and what, if anything, needs attention.
- Response within 1 business day
- Written report you can keep
- Follow-up only if you ask