Associated KonsultantsCybersecurity & Risk Consulting Better Business Bureau Accredited Business (opens in a new tab)

Find your situation.

The assessment is the same for everyone. What changes is which findings turn out to matter, and what a regulator would say about them.

What actually differs by industry, and what doesn’t

Most of security doesn’t care what business you’re in. Accounts get shared, backups go untested, and somebody clicks a convincing attachment in every industry there has ever been. That is why the assessment scores every client against the same published standard — the 18 CIS Critical Security Controls — rather than against a checklist invented for their sector.

Three things do change.

What a breach would cost you. Not the recovery bill — the second-order damage. For a medical practice it’s a regulator. For a law firm it’s the privilege. For a non-profit it’s the board and the donors. For a contractor it’s the payment that goes to the wrong account and can’t come back.

Which findings get flagged as mandatory. Every recommendation in your out-brief is sorted short, mid and long term — and any driven by regulation rather than preference is marked as such. HIPAA, PCI DSS and personal-information rules move items into that category, and it is the one place where “we’ll get to it” is not a decision available to you.

How exposed the individuals are. In some professions the owner is a target personally, not just the business. More on that below.

Healthcare practices

What’s actually at stake: patient records, a regulator with published penalties, and a practice whose entire operation stops when the system does.

Most practices we see have bought security products and have no idea whether they work together or leave gaps. The assessment tells you which of the 18 controls you’re actually meeting, at what maturity, with the HIPAA-driven items flagged separately — so the conversation with your compliance obligations stops being a guess.

The physical half matters more here than almost anywhere. Who walks into your waiting room. What’s visible on a screen at the front desk. Where records sit when the office is closed. Who has keys, and who used to.

Physicians are also targeted personally. Home addresses, family details and financial records published by data brokers are the starting point for attacks on the practice — and for harassment that has nothing to do with technology at all. Removing that exposure is part of what we do for retained clients.

Anthony spent part of his career as Vice President and Chief Information Officer of a global medical diagnostics company — this sector’s regulatory environment is not new ground.

Law firms

What’s actually at stake: privilege, and a professional obligation to protect client confidences that predates every technology on this page.

A firm that loses client files hasn’t just had an incident. It has a problem with its obligations, its insurer, and every client whose matter was in that system. Increasingly it also has a problem with its clients’ own security requirements — corporate clients now audit their outside counsel, and firms are losing work over the answers.

The assessment gives you a scored position against a standard those clients recognize, and an out-brief you can show them.

And attorneys and judges are personally exposed. Names, home addresses and family details are published by data brokers and are trivially findable by anyone with a grievance about a case. Removing that exposure is part of the ongoing work.

A note about the two sections above

You’ll see that the healthcare and legal sections carry no client quotes, while the ones below do. That isn’t an oversight.

Our clients in those two fields prefer not to publicly endorse any outside services used, and that is a reasonable position for a practice or a firm to take. So there are no quotes here. The businesses quoted elsewhere on this site chose to be.

Being quoted would be your choice too, and the default is no.

Non-profits

What’s actually at stake: donor data, restricted funds, and a board that has to be told.

Non-profits get attacked precisely because attackers assume there is no security team. Usually there isn’t — there’s a director doing four jobs and a volunteer who is good with computers. That isn’t a criticism; it’s the funding model.

What we can do about it is give you a scored, evidenced picture of where you stand and a prioritized list with costs attached — which is also the document that lets you ask a board or a funder for money with something more than a worried feeling behind it.

“I was experiencing significant problems with my computer system. It had become locked up, and I was concerned that the system and connected devices were not properly secured. I needed a trusted professional who could evaluate the situation, identify the security risks and recommend the right solution. I would tell anyone not to wait when it comes to protecting their technology and data. Having a knowledgeable and trustworthy professional evaluate the problem can prevent a small issue from becoming a much larger one.”

Walter HillExecutive Director, SEBA

Trades and contractors

What’s actually at stake: the payment. Almost always the payment.

Contractors, HVAC companies, flooring firms, builders — the pattern is consistent and it is not sophisticated. A convincing email arrives from a supplier or a customer you are genuinely expecting to hear from, with an attachment you were genuinely expecting to receive. One click and something is installing. Or the invoice is real and only the bank details have been changed.

This is the sector where the gap between “we have antivirus” and “we would survive Tuesday” is widest, because the money moves fast and the margins are thin.

“A very official-looking email from one of our contractors, with a PDF contract we were expecting, turned out to be malicious — and before we knew it there were files downloading and installing. We immediately shut down the computer and called Anthony. We got an immediate response.”

Jeff & Rhonda StoweOwners, Foothills Floor Covering, LLC

The physical half matters here too, for different reasons than a medical practice: yards, vehicles, equipment, keys, and staff turnover that is faster than anyone’s offboarding process.

A full assessment for a heating and cooling company →

Everyone else

Accounting practices, insurance agencies, professional services firms, retailers, small manufacturers, member organizations. The sections above exist because those four come up most often, not because the work is different.

If you employ somewhere between a handful and a few hundred people, hold information that would hurt you to lose, and have nobody whose actual job is to worry about it — you’re in the right place, whatever the sector is called.

Twenty minutes.

No cost, no presentation. We work out whether there’s a fit — and if there isn’t, I’ll say so and point you somewhere better.

Book a 20-minute call

(844) 219-3418 · ClientServices@akonsultants.com · Tucson-based — clients nationwide