SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

How can I help?

It's your business. What do you need to know? What do you want to do? How much can your afford to spend (not on me, but on the problem) on a recurring monthly basis? My fees will be as minimal as it takes for you to decide, and then I can go away. I don't have recurring charges just because I helped you. I only charge per appointment at an agreed upon rate. But the tools you decide to use will have monthly or yearly costs.

What does an engagement look like?

I will begin by signing a non-disclosure agreement that protects you and your business information. I have no intention to talk about or leak anything I learn about you and your business to anyone else, but it should help to put your mind at ease that I will sign may name to such a promise.

Next, I will ask you what your business does. What services does it offer? What type of competition does it face? What regulations must it comply with? What standards and frameworks apply to your business? I will ask how you use technology. If technology is really that important to the business model. How you support that technology and if you feel it necessary to have a recovery plan for it. I will want to understand any protections or protective measures that you use today. I will then ask some size and budget questions because that matters to how far you can or should go with information security. You should never spend more than the value of the data, and what the fines and the lawsuits will cost you, prorated over the timeframe in question.

With that information provided, I can help you decide how far you want to go. It is not my money that will be spent. It is not my money that might be lost to an event, should one occur. I will be sensitive that exactly that as this first meeting progresses.

Now for the $1,000 question: do you have any business, employee or customer information in hard copy, stored in a file cabinet, in a box, laying loose on your desk, or flying around through your truck when you drive around with the window open? Did you think you were immune because you don't use computers? You are not, but your requirements will be much smaller, the less you have in a computer, on a network or connected to the Internet, and the fewer people who have access to all of that. But, you still have to do something.

One more thing to remember, no matter what the regulations say today, no matter if you think you do or do not have information in any form worth protecting, you should have a plan, a program and some processes to protect it all, at least a little. I am here to help coach you through the information security maze at the level you need and want; no more. It will take some thought, some work and some time, but not as much as you think.

Is it worth the price?

I am reasonable. My fees are reasonable. I charge USD $150 per hour for every type of work that I do for you. I also have volume discounts if you buy a 10 hour service contract for USD $1,000, good for one year.

An initial phone call for you to evaluate me is not work. I will not charge for that. When it gets into learning about, evaluating and reporting on your business risk profile, along with recommendations or the creation of a program for you, that is the work I do. I can also do much of the setup and configurations necessary to set things up for you, but I'd rather teach and train one of your own employees to do that so that you can be self sufficient at a lower cost, because that is what this is all about: making your business related information, systems and people are more secure without you losing more money than you would lose if you did nothing.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your information (oops...I mean cyber) security.