Insights
Notes from the field
Plainspoken writing on compliance, security and IT for growing companies.
By topic
By industry
September 11, 2026
Choosing practice management software: the security questions that matter
The platform that will hold every client record deserves more scrutiny than the sales demo gave it. Here are the questions to ask before you sign.
September 9, 2026
Stop emailing client files: secure exchange for professional practices
Tax documents and case files still travel as email attachments. Here is how a 5 to 50 person practice standardizes one secure channel without losing clients along the way.
September 7, 2026
Your firewall is not a checkbox: what a business-grade edge actually does
The difference between the ISP router and a real firewall, what the subscriptions buy and the 5 configuration basics that matter more than brand.
September 4, 2026
The Windows 7 box running your CNC: legacy systems on the plant floor
When the controller PC cannot be upgraded and cannot be replaced, you still have 4 real options. Here is how to rank them honestly.
September 2, 2026
When the line stops: what ransomware downtime actually costs a manufacturer
The ransom is the small number. Missed ship dates, contract penalties, spoiled work in process and recovery overtime are where a plant really pays.
August 31, 2026
IT for construction firms chasing enterprise project work
GC prequalification packets now include cybersecurity sections. What a 15-50 person contractor needs to pass upstream security review and win bigger work.
August 28, 2026
Data retention and legal hold: what to keep and what to purge
Keeping every email forever feels safe and is actually liability. A plain-English guide to retention schedules and legal hold for small business.
August 26, 2026
Physical security for small and distributed offices
Companies debate $50k firewalls while the server closet is propped open with a mop bucket. A practical physical security order of operations.
August 24, 2026
Do you need a vCISO at 25 employees?
At 25 employees, security decisions are nobody's job. Here is when a fractional security leader earns their fee and when you can wait.
August 22, 2026
Dark web monitoring: real signal or scare marketing?
What dark web monitoring actually tells you, what it cannot do and how to tell a useful alert from a recycled 2019 breach dump used as a sales prop.
August 20, 2026
Still on Windows 10? The ESU runway ends in October
Extended Security Updates bought Windows 10 holdouts some time, but the runway is short and the per-device price doubles each year, so August is the month to decide.
August 18, 2026
Buying your first cyber insurance policy: a small business walkthrough
What a 10 to 30 user business needs to know before buying its first cyber policy, from coverage types to the social engineering sub-limit that decides whether a BEC loss is actually covered.
August 14, 2026
The 5-year-old laptop problem: hardware lifecycle without the drama
A staggered 4 to 5 year refresh cycle turns the surprise $30,000 hardware year into a predictable line item and quietly closes security gaps.
August 11, 2026
Microsoft does not back up your Microsoft 365 data the way you think
Retention is not backup: what Microsoft 365 natively protects, the gaps that catch businesses off guard and what real third-party M365 backup should include.
August 5, 2026
Your team is already pasting company data into AI tools
AI tool use in small businesses is already happening with or without a policy, so here is the sane setup: a sanctioned tool, plain data rules and a 1-page policy.
July 30, 2026
Wire fraud hit your business: the first 48 hours
A step-by-step response plan for the first 48 hours after a fraudulent wire transfer leaves your account, from bank recall to IC3 to preserving evidence.
July 27, 2026
What managed IT actually costs for a 10 to 30 user business
Real per-user pricing bands for managed IT with security included, what belongs in the base fee, and why the cheap quote usually is not.
July 24, 2026
Business email compromise: the scam built for 15-person companies
No malware, no hacking tools, just email and patience. How BEC actually unfolds at small businesses and the 4 controls that stop it.
July 22, 2026
Rolling out MFA without an employee revolt
The technical side of MFA takes an afternoon. The human side takes 3 weeks, and skipping it is why small business rollouts fail.
July 20, 2026
Is Microsoft 365 Business Premium worth it for a 15-person office?
What the roughly $10 per user per month jump from Business Standard to Business Premium actually buys, and when Standard is genuinely enough.
July 17, 2026
If your IT person disappeared tomorrow: the documentation test
A one-page test for whether your business actually controls its own IT, and the 7 documents that should exist before you ever need them.
July 15, 2026
Security awareness training a 20-person company will actually complete
The annual 45-minute security slideshow fails because it is designed for auditors, not employees. Short monthly training and blame-free phishing simulations work better and cost less than most owners expect.
July 13, 2026
The new hire IT onboarding checklist for a 10 to 30 person company
Rushed day-1 IT setup creates shared logins and over-permissioned accounts that last for years. A 4-phase onboarding checklist fixes it without slowing anyone down.
July 10, 2026
Personal phones, company email: a sane BYOD setup for small business
Most 10 to 30 user companies are BYOD by default, not by decision. Here is how to protect company data on personal devices without managing anyone's phone.
July 8, 2026
DMARC, SPF and DKIM: the 3 DNS records protecting your company's name
Criminals can send email that looks exactly like it came from your domain unless 3 DNS records say otherwise. Here is what SPF, DKIM and DMARC do and how to roll them out without breaking your own mail.
July 6, 2026
Do you still need a server? The 10 to 30 user question
The aging office server is due for replacement and the quote is $12,000. Before you sign it, here is how to decide what actually still needs to live on-prem.
July 3, 2026
Form ADV cybersecurity: making the disclosure true, not just prettier
How an RIA closes the gap between what its Form ADV Part 2A brochure says about cybersecurity and the controls actually running, and why an overstated disclosure is worse than a modest accurate one.
July 2, 2026
The cybersecurity tabletop exercise that produces decisions, not a filed PDF
How to run a cybersecurity tabletop exercise that surfaces real gaps and ends with named owners and dates, instead of a 3-hour meeting that produces a PDF for the auditor and nothing else.
July 1, 2026
Shadow IT discovery and the SaaS inventory conversation nobody wants to start
A practical guide to shadow IT discovery for small businesses, covering how to find ungoverned SaaS apps and unreviewed OAuth grants, triage them by data sensitivity and build a request path so it does not just recur.
June 29, 2026
Employee offboarding security: the orphaned account nobody disabled
Employee offboarding security is an identity control, not an HR courtesy. Why ad-hoc offboarding leaves orphaned accounts live for months and what a documented, measured deprovisioning process looks like.
June 27, 2026
Managed identity for a 50-person company: when accounts become the perimeter
Managed identity for a small business means Entra ID as the control plane, MFA and conditional access as baseline, SSO to cut password sprawl, a joiner-mover-leaver lifecycle and ITDR monitoring for the Microsoft 365 tenant.
May 29, 2026
Accounting firm cybersecurity, IRS Pub 4557 and the FTC Safeguards Rule
What the IRS expects in a Written Information Security Plan, the nine elements the revised FTC Safeguards Rule actually requires and how the new 30-day breach notification rule changed the operational picture for tax preparers and accounting firms.
May 28, 2026
HIPAA breach notification, the 60-day clock and what trips it
When the 60-day breach notification clock actually starts under the HIPAA Breach Notification Rule, the four-factor Risk of Compromise analysis and the timing failures that turn an incident into an OCR enforcement action.
May 27, 2026
HIPAA risk analysis vs risk assessment, what OCR actually scores
Why HHS Office for Civil Rights settlements keep citing the same Security Rule risk analysis failure, and how the formal risk analysis differs from the general risk assessments most practices think satisfy it.
May 26, 2026
POA&M for NIST 800-171, anatomy of a defensible plan of action
What a Plan of Action and Milestones actually contains, why assessors read it before the System Security Plan and how to build one that holds up under prime contractor and DoD review.
May 25, 2026
SPRS score, what the number means and how to move it
How the DoD Supplier Performance Risk System scores NIST 800-171 compliance, why most sub-contractors come in negative the first time and how to sequence the work to climb.
May 23, 2026
FCI vs CUI: the inventory question every sub-contractor avoids
What the distinction between Federal Contract Information and Controlled Unclassified Information means in practice, and why getting the inventory right determines whether you owe 15 controls or 110.
May 21, 2026
Bakery customer audit deep dive: when the branded customer sends a 60 question security review
How small and mid-market bakeries answer a 60 question supplier security audit from a branded national customer without missing the renewal window.
May 19, 2026
Peanut and nut processing cybersecurity: FSMA, food defense and allergen segregation
Cybersecurity for peanut, tree nut and seed processors operating under FDA FSMA: allergen segregation system integrity, food defense plan IT alignment and customer-audit readiness.
May 16, 2026
Meat and poultry processing cybersecurity under USDA FSIS
Cybersecurity for meat and poultry processors operating under USDA FSIS continuous inspection: OT segmentation, FSIS reporting, recall posture and customer-audit readiness.
May 14, 2026
Dairy processing cybersecurity: OT, cold chain and USDA reporting
What dairy processors should expect from a cybersecurity program: OT segmentation, cold-chain monitoring resilience, USDA FSIS reporting and customer-audit readiness.
May 12, 2026
PE diligence in food processing: what sponsors look for
The 10 cybersecurity diligence items that move price or kill deals in food processing PE transactions. Where dairy, meat and nut processors typically fail.
May 5, 2026
When the customer security audit visit lands, a manufacturer's prep playbook
What changes when an enterprise customer's security team books an on-site or remote audit visit at a mid-market manufacturer, and how to be ready before the calendar invite arrives.
May 5, 2026
Detroit, PE portfolio cybersecurity in the sponsor-office corridor
Why the Detroit metro's sponsor-office density makes portfolio-company cybersecurity a different operating problem than it is in lower-density PE markets, and what works.
May 5, 2026
Walking through a customer security questionnaire, section by section
What enterprise customers are actually measuring when they send a vendor security questionnaire, and how to answer each section without overpromising or underselling.
April 20, 2026
Medical practice IT, HIPAA safeguards in 60 to 90 days
A practical 60 to 90 day plan for medical practices to bring HIPAA Security Rule safeguards to a defensible baseline, from risk analysis to access controls to incident response.
April 20, 2026
Application allowlisting for the small-business reality
A practical view of application allowlisting at the mid-market — what it protects against, why most mid-market firms don't need it yet and when the calculation actually flips.
April 20, 2026
Endpoint privilege management without breaking your users
A practical approach to removing local admin rights from workstations at mid-market firms, with just-in-time elevation, approval workflows and rollout sequencing that users will actually tolerate.
April 20, 2026
The IT transition from 25 users to 75 users
A practical playbook for the IT and cybersecurity transitions a small business has to navigate as it grows from 25 users to 75, with what breaks and what to build at each milestone.
April 20, 2026
Cybersecurity and enterprise valuation, how much it actually matters
A practical view of how cybersecurity posture affects transaction outcomes, deal multipliers and retrade risk at mid-market PE exits, with honest ranges for the magnitude of impact.
April 20, 2026
Security marketing vs. security evidence
Why enterprise buyers, auditors and cyber insurance underwriters discount marketing language in security questionnaires, and what audit-grade evidence actually looks like.
April 20, 2026
Post-incident review, what to document, what to change
A practical format for the post-incident review that produces operational improvements instead of blame, scar-tissue over-correction or a forgotten document nobody reads again.
April 20, 2026
How to build a cybersecurity program document your customers accept
The contents, structure and maintenance cadence for a cybersecurity program document that holds up to customer audits, cyber insurance renewals and SOC 2 readiness assessments.
April 20, 2026
Microsoft 365 security baselines, the 10 settings that matter most
The 10 Microsoft 365 security configuration changes that reduce risk most at the mid-market level, with honest notes on which require E5 and which work on E3 or Business Premium.
April 20, 2026
SIEM at the mid-market, when it's worth it, when it's overkill
A practical read on SIEM for mid-market firms — what the technology actually does, when the cost is justified and the three alternatives most firms should evaluate first.
April 20, 2026
Incident response when you don't have an in-house team
How small and mid-market firms actually respond to cybersecurity incidents without a dedicated security team, from MDR coverage to IR-firm retainers to executive decision-making during the first 4 hours.
April 20, 2026
Breaking free from break-fix, what changes with managed IT
A practical look at what changes when a small business moves from break-fix IT to a managed services engagement, from cost predictability to security posture to the 3 AM call.
April 20, 2026
Vendor risk management at 40 employees, without a GRC tool
A practical vendor-risk program for small and mid-market firms that cannot justify a GRC platform, built around a maintained spreadsheet, a tiered review cadence and a clear escalation path.
April 20, 2026
Network segmentation, when a flat network becomes a liability
A practical view of network segmentation for small and mid-market firms, what it actually means at this scale, what it protects against and how to phase the implementation without disrupting operations.
April 20, 2026
Your first ransomware tabletop, a sample script
A working sample script for a mid-market firm's first ransomware tabletop exercise, including agenda, scenario, injects, decision points and the artifacts it should produce.
April 20, 2026
Cybersecurity for community banks and credit unions, the examiner's list
What FDIC, OCC, NCUA and state examiners actually look at when they review a community bank or credit union's cybersecurity posture, and what a credible program looks like at the mid-market asset level.
April 20, 2026
CIS Controls v8, the practical prioritization most MSPs skip
A working guide to the CIS Controls v8 Implementation Groups, why most MSPs ignore the prioritization and how a mid-market firm should actually sequence the 153 safeguards.
April 20, 2026
MDR vs SOC-as-a-service vs running it yourself
A practical decision framework for mid-market firms choosing between managed detection and response, SOC-as-a-service and building an in-house SOC.
April 20, 2026
Law firm data protection, matter segregation and encryption practices
The practical data protection obligations a modern law firm carries, from client confidentiality and matter segregation to encryption, access controls and the new wave of enterprise-client security requirements.
April 20, 2026
Insurance agency IT, what your carrier expects from YOU
The cybersecurity and IT expectations insurance carriers, E&O underwriters and state regulators increasingly place on independent insurance agencies, and how an agency should actually comply.
April 20, 2026
Carve-out IT, separating systems from a Fortune 1000 parent
The practical IT and cybersecurity workload of a PE carve-out from a Fortune 1000 parent, from TSA planning to standalone environment build to post-close operation.
April 20, 2026
What a ransomware incident actually costs
The real cost categories of a modern ransomware incident, why the ransom is usually the smallest line item and how mid-market CFOs should frame the exposure.
April 20, 2026
IT for senior-care operators, HIPAA, multi-site and the state inspection
The practical IT and cybersecurity workload a multi-site senior-care operator carries, from HIPAA safeguards to the state inspection readiness the corporate office rarely thinks about.
April 20, 2026
What actually lowers your cyber insurance premium
The specific control changes, evidence artifacts and broker moves that actually lower cyber insurance premium at renewal, and what does not.
April 19, 2026
Tested restores, how to verify your backup strategy is real
A working runbook for backup restore testing, what each cadence should cover and why a backup that has never been restored is not a backup.
April 19, 2026
OT cybersecurity for mid-market manufacturers
Why operational technology needs a cybersecurity program distinct from corporate IT, what the IEC 62443 framework expects and how a mid-market manufacturer should sequence the work.
April 19, 2026
HIPAA for business associates, what's in a BAA and what's not
What a Business Associate Agreement actually commits a vendor to, where the common misreadings surface and how a BA should build the program the BAA promises.
April 19, 2026
MFA, EDR and offline backups, the cyber insurance triage list
The three controls that carry the most weight in modern cyber insurance underwriting, why they became the triage list and how to confirm yours are actually operating.
April 19, 2026
Zero Trust for small and mid-market: what to do first
A practical Zero Trust sequence for companies of 50 to 500 employees, honest about what is achievable without an enterprise identity team and what is not.
April 19, 2026
SOC 2 readiness vs. audit and why your MSP doesn't do audits
Why SOC 2 readiness and the SOC 2 audit are distinct engagements, why one firm cannot do both and how to sequence the two without burning budget or credibility.
April 19, 2026
3-2-1-1-0: the new backup baseline
The updated 3-2-1-1-0 backup rule, what each digit actually requires and why the classic 3-2-1 guidance is no longer enough for modern ransomware threat models.
April 19, 2026
Your cyber insurance renewal questionnaire is getting harder, a walkthrough
A walkthrough of the modern cyber insurance renewal process, why the questionnaire has doubled in length since 2022 and what the underwriter is actually measuring behind each section.
April 19, 2026
The 25 questions you'll fail on your next cyber insurance renewal
The 25 cyber insurance renewal questions most mid-market firms answer weakly, what each one is really measuring and how to close the gap before your carrier notices.
April 19, 2026
The 100-day cybersecurity plan for a newly acquired portfolio company
A practical 100-day cybersecurity playbook for PE operating partners and portfolio-company CFOs, covering the assess, stabilize and execute phases of post-close.
April 19, 2026
Your first enterprise customer security questionnaire, what to expect
A practical walkthrough of the enterprise customer security questionnaire, what the buyer is actually measuring and how to respond without burning the deal.
April 19, 2026
SOC 2 Type I vs Type II: what your enterprise customer actually wants
A practical breakdown of SOC 2 Type I and Type II reports, what each one proves, and how to decide which to pursue for your first enterprise customer review.
April 19, 2026
Cybersecurity diligence for a PE sale: what buyers actually check
A practical field guide to the cybersecurity evidence buyers, operating partners and lenders review during a lower-middle-market PE transaction.
April 19, 2026
Phishing-resistant MFA: FIDO2, passkeys and what's coming next
SMS codes and push notifications are no longer enough MFA for serious cyber insurance or customer review programs. The move to FIDO2 security keys and passkeys is underway, here's how it works and what to deploy.
April 19, 2026
Ransomware-hardened backup: what 'immutable' actually means
Your backup strategy is only as good as your last documented successful restore. A practical explanation of immutability, the 3-2-1-1-0 rule and what ransomware-hardened actually requires.
April 19, 2026
NIST 800-171: the 110 controls and which ones eat the budget
A practical breakdown of the NIST 800-171 control families, which controls take the most effort for small and mid-market organizations and how to sequence the 90-120 day compliance arc.
April 19, 2026
EDR vs antivirus: what actually changed and what still matters
Your cyber insurance carrier is asking about EDR because traditional antivirus stopped being enough around 2017. Here's the practical difference and what to deploy.
April 19, 2026
NIST CSF 2.0 in plain English: what changed and why it matters
NIST CSF 2.0 added Govern as a sixth function and reorganized how small and mid-market organizations should think about cybersecurity. A practitioner's translation.
April 19, 2026
Password managers for small business: why, which and how to roll one out
A 25-person firm can deploy a business password manager in under two weeks and eliminate the worst category of credential risk. Here's the plan.