Cybersecurity for small businesses
Most of my work is HIPAA risk assessments for medical and dental practices. The same approach works for any small business that holds information worth protecting: law firms, accounting and tax offices, financial advisors, nonprofits and professional services firms.
Services
Fixed scope and published prices, the same as my healthcare work. You get the final price in writing before anything starts.
Security risk assessment
A documented review of where your sensitive information lives, what could go wrong with it, and what to fix first, delivered as a plain-English report with a review meeting. Tax preparers, mortgage brokers and many other financial firms need this for the FTC Safeguards Rule, which requires a written security program based on a risk assessment.
Microsoft 365 security review
Most small businesses run on Microsoft 365, and most break-ins start there. I review sign-in security, admin accounts, mailbox forwarding rules, third-party app permissions, and the protections you're already paying for but may not have turned on. You get a prioritized fix list your IT provider can work through.
Email account compromise review
Messages you didn't send, strange forwarding rules, or a "vendor" asking to update their bank details? I'll work out whether an account was taken over, what the attacker could see, and how to close the door, with a written summary you can give your insurer or attorney.
This isn't a 24/7 emergency service. If money is moving right now, call your bank first, then your IT provider.
Staff security training
A live 45-minute session for your team, in person or by video: how to spot phishing, fake invoices and payment-change scams, and what to do after someone clicks. Plain language, no scare tactics.
Written security policies
Security policies and an incident response plan written to match how your business actually works, not a generic template.
Why work with me
I bring more than six years of cyber defense experience, including two years leading a threat hunting team that investigates and contains real-world intrusions. That work includes the attacks small practices face most often, such as compromised Microsoft 365 email accounts.
Every engagement is done by me personally. I don't resell hardware or software, and I don't replace your IT provider. I tell you and them what to fix and in what order.
Not sure which you need?
Tell me what's going on in a 15-minute call. You'll get an honest recommendation, even if it's that you don't need me.