Field notes
Useful, occasional, and never a sales pitch
We publish when we have something worth saying — usually after handling a situation that other firms are about to walk into. No gated downloads, no newsletter wall.
- 6 min read
The client security questionnaire nobody warned you about
A corporate client sends forty questions about your technology, due in a fortnight, written for a company a hundred times your size. Here is how to answer it without either lying or losing the work.
Written for: Law firms, and any firm serving larger organisations
- 5 min read
The HIPAA document your practice is most likely missing
It is not a policy binder and it is not a staff training certificate. It is the security risk analysis, and it is the thing that gets asked for first.
Written for: Medical and dental practices of any size
- 5 min read
Nothing broke. You just hired four people.
Small professional firms rarely outgrow their technology in a way anyone notices. It degrades one hire at a time, and the symptoms look like unrelated annoyances.
Written for: Professional offices, consultancies and advisory firms
- 5 min read
The technology budget most non-profits are leaving on the table
A meaningful share of what small charities spend on software is avoidable through donation and discount programmes. Finding it is a morning's work, and it funds most of the security you have been putting off.
Written for: Non-profits, associations and charitable organisations
- 5 min read
The first hour of a payment-redirection attempt
Invoice and wire fraud is rarely a technical failure. It is a process failure with a technical opening, and the first hour decides how much of it is recoverable.
Written for: Law firms, accounting practices, anyone who moves client money
- 4 min read
Your backups are running. That is not the question.
Green ticks on a backup dashboard measure whether a job completed, not whether your firm can get back to work. Two numbers matter more.
Written for: Any owner who has been told backups are handled
- 6 min read
What a written security plan looks like for a firm of twelve
Regulators increasingly expect a document, not a description. It does not need to be long — it needs to be true, current and specific to what you run.
Written for: CPAs, attorneys, clinics and anyone facing a client questionnaire
Working through something specific?
If you are dealing with a regulation, an incident or a control question right now, send it over. It often becomes the next note — and you get an answer either way.
Or call 1-855-966-2967