Who we help
Small firms with obligations that do not scale down
A twelve-person practice answers to the same rules as a two-hundred-person one, without the budget or the head count. That gap is the work.
Law firms
Confidentiality obligations that outlast any single matter
- ABA Model Rules 1.1 & 1.6
- Outside counsel guidelines
- Trust and escrow wire controls
- Practice management support
Accounting and CPA firms
A written security plan is no longer optional
- IRS Pub. 4557
- FTC Safeguards Rule
- Written information security plan
- Busy-season capacity planning
Medical and dental clinics
HIPAA controls without a hospital-sized budget
- HIPAA Security Rule
- Business associate agreement
- Clinical device segmentation
- Imaging and PACS support
Professional offices
For firms whose product is judgement and whose asset is trust
- NIST Cybersecurity Framework
- Client contract security terms
- Cyber insurance questionnaires
- Advisory firm evidence and retention
Real estate, title and escrow
The industry criminals target most, because the money is already moving
- ALTA Best Practices
- Wire verification procedure
- Lookalike domain monitoring
- Underwriter requirements
Non-profits and associations
Donor trust, restricted budgets, and a lot of volunteers
- Donor data protection
- Volunteer access control
- Grant conditions
- PCI DSS for donations
Your industry is not on that list. That is not a reason to close the tab.
Those six are where we are asked for most often, not a list of who qualifies. The test that actually matters is simpler: does your work run on computers, and would a bad week offline hurt? If the answer to both is yes, the conversation is the same one we have with every firm on this page.
It is also worth a call if nothing is wrong and you simply suspect you are paying for more technology than you use, or getting less from it than you should. Worst case, we spend twenty minutes on it and both leave the call knowing something we did not.
If we are not the right people for your firm, we will say so on that call rather than after you have signed something.
Common ground
Standards we build and evidence against
- HIPAA
- NIST CSF
- PCI DSS
- FTC Safeguards Rule
- IRS Pub. 4557
- ISO 27001
- GDPR / CCPA
We build and evidence controls against these frameworks. Where a formal certification or attestation is required, we will tell you exactly what we hold and what we do not.
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967