Skip to main content
CY6Check Your Six

Who we help

Small firms with obligations that do not scale down

A twelve-person practice answers to the same rules as a two-hundred-person one, without the budget or the head count. That gap is the work.

  • Law firms

    Confidentiality obligations that outlast any single matter

    • ABA Model Rules 1.1 & 1.6
    • Outside counsel guidelines
    • Trust and escrow wire controls
    • Practice management support
  • Accounting and CPA firms

    A written security plan is no longer optional

    • IRS Pub. 4557
    • FTC Safeguards Rule
    • Written information security plan
    • Busy-season capacity planning
  • Medical and dental clinics

    HIPAA controls without a hospital-sized budget

    • HIPAA Security Rule
    • Business associate agreement
    • Clinical device segmentation
    • Imaging and PACS support
  • Professional offices

    For firms whose product is judgement and whose asset is trust

    • NIST Cybersecurity Framework
    • Client contract security terms
    • Cyber insurance questionnaires
    • Advisory firm evidence and retention
  • Real estate, title and escrow

    The industry criminals target most, because the money is already moving

    • ALTA Best Practices
    • Wire verification procedure
    • Lookalike domain monitoring
    • Underwriter requirements
  • Non-profits and associations

    Donor trust, restricted budgets, and a lot of volunteers

    • Donor data protection
    • Volunteer access control
    • Grant conditions
    • PCI DSS for donations

Your industry is not on that list. That is not a reason to close the tab.

Those six are where we are asked for most often, not a list of who qualifies. The test that actually matters is simpler: does your work run on computers, and would a bad week offline hurt? If the answer to both is yes, the conversation is the same one we have with every firm on this page.

It is also worth a call if nothing is wrong and you simply suspect you are paying for more technology than you use, or getting less from it than you should. Worst case, we spend twenty minutes on it and both leave the call knowing something we did not.

If we are not the right people for your firm, we will say so on that call rather than after you have signed something.

Common ground

Standards we build and evidence against

  • HIPAA
  • NIST CSF
  • PCI DSS
  • FTC Safeguards Rule
  • IRS Pub. 4557
  • ISO 27001
  • GDPR / CCPA

We build and evidence controls against these frameworks. Where a formal certification or attestation is required, we will tell you exactly what we hold and what we do not.

Not sure where you stand?

Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.

Or call 1-855-966-2967