The things a small business is expected to have, actually written down.
Not an enterprise security program. The specific set of policies, records, and plans that insurers, customers, and banks now ask for — built small enough that the people you already employ can keep it running.
You're probably here because of one of these.
Insurance renewal got harder
Cyber policies now come with real requirements, and answering wrong costs you the rate or the coverage.
Something almost happened
A phishing email got clicked, or a laptop went missing, and it became obvious nobody knew what to do.
You're growing
Twelve people was fine on trust. Forty is not, and nobody can say who has access to what anymore.
Everything included.
- A written information security policy, in plain language, sized for your business rather than copied from a template
- Acceptable use, password, and access rules your staff can read in ten minutes
- An access inventory — who can get into what, including the accounts nobody remembered existed
- A backup review, including actually restoring one to confirm it works
- A short incident response plan with named people and phone numbers
- A vendor list with basic due diligence on the ones touching your data
- A one-page roadmap of what to do next, prioritized by what actually reduces risk
- A training session with your team so this isn't just files on a drive
Start to finish.
A working session
Ninety minutes on how your business runs, what systems you use, and who touches what.
I write it
Policies and records drafted against your reality, mapped to CIS Controls so it lines up with what people will ask for.
You mark it up
You read it and tell me what's wrong or unworkable. It gets fixed before it's final.
Handoff session
I walk your team through it, hand over editable files, and answer questions for thirty days.
Scales with headcount and how many systems are in play. A 15-person services firm sits near the bottom; a 100-person company with multiple offices and a warehouse sits higher. Quoted before we start.
Start hereAsked often enough to write down.
Isn't this just paperwork?
Some of it is, and the paperwork is what insurers and customers ask for. But the access review and the backup restore aren't paperwork — those are the two things that most often turn out to be broken, and finding out now is the entire point.
Why CIS Controls and not NIST?
CIS Controls are ordered by what actually prevents the most damage first, which suits a business without a security team. NIST CSF is excellent and it's built for organizations with more structure than most small businesses have. If a customer specifically demands NIST, I'll map to it.
Who maintains it after you leave?
You do, and it's built for that. Editable files, plain language, and a short annual checklist. If you'd rather I come back once a year to refresh it, that's a separate small engagement, not a retainer.
We already have an IT provider. Do we need this?
Possibly not, and ask them first. Managed IT providers handle the technical controls well and the written governance almost never. If they've given you policies, an access inventory, and an incident plan, you're covered. Most haven't.
Can you just tell us what to buy?
I'll tell you what to buy and what not to. I don't resell anything and I take no commissions, so the recommendation is only about what you need.
Let's see where you actually stand.
Describe your setup on the form. I'll tell you which pieces you're missing and what it'd cost to close them.
Get in touch