Cybersecurity Insights

Practical guidance for small businesses, veterans transitioning to cybersecurity, and healthcare organizations.

Your HIPAA Risk Analysis Was Never the Finish Line

HIPAA enforcement is reported to be widening from risk analysis to risk management. The evidence regulators want is no longer that you found a risk, but that you closed it. What 45 CFR 164.308(a)(1)(ii)(A) and (B) require, and the four columns that turn a risk analysis into a record.

Read Full Article →

Attackers Know When Your Office Is Closed

Ransomware crews pick holidays and long weekends on purpose, because that is when staffing is thinnest and nobody is reading alerts. Five things that cost nothing before the office closes, and the short review worth running when you come back.

Read Full Article →

An AI Agent Is a User You Forgot to Offboard

The Artificial Intelligence tools and agents you added this year hold logins to your systems. An agent is a non-human identity, and it needs the oldest security discipline: least privilege. Why it matters now, and where it maps to NIST 800-171 and CMMC.

Read Full Article →

Need Direct Help with What You Read?

If anything in these posts mirrors what you are dealing with at your business or in your career transition, the next step is a 30-minute conversation.

Schedule a Consultation   Call (619) 289-8064