Risk
Security & Compliance Readiness
Close the gaps that actually get small businesses breached — and answer the security questionnaire holding up your deal.
You might need this if
- An enterprise customer sent a security questionnaire and you have no idea how to answer it.
- You handle patient, student or financial data and have never had anyone check the setup.
- Your cyber insurance renewal now asks whether MFA is enforced everywhere. You think so.
- Everyone is a local administrator and there is one shared password for the important thing.
Small businesses get breached in boring ways
Not through zero-days. Through a mailbox with no multifactor authentication, a former employee whose account was never disabled, a backup that has been silently failing for eight months, and a vendor with standing remote access nobody has reviewed since they were hired.
None of those are expensive to fix. They stay unfixed because no one owns finding them, and because security advice aimed at small businesses is usually a product pitch attached to a monthly fee.
What an assessment covers
Identity and access first, because that is where the real risk lives: who has accounts, who has administrative rights, whether MFA is genuinely enforced rather than merely available, and what happens to access when someone leaves.
Then backup and recovery — not whether backups exist, but whether a restore has ever been tested and how long a full recovery would actually take. Then endpoint and patching status, email security configuration (SPF, DKIM and DMARC are free and most small businesses have them wrong or missing), vendor and third-party access, and the data you hold that you may not realise carries a regulatory obligation.
You get findings ranked by real risk and effort, not a 90-page generic report. The first page is the handful of things worth doing this month.
Compliance and customer questionnaires
I have worked under SOX, HIPAA, CCPA and CMMC and can tell you in plain terms what a given framework actually requires of a business your size — which is usually far less than the compliance-software vendors imply, and occasionally more.
If a customer questionnaire is blocking a contract, I can help you answer it accurately and identify which gaps need closing before you sign rather than after.
To be clear about scope: this is practical readiness work, not a certified audit. Where a formal attestation is required, I will tell you plainly and help you scope the auditor engagement rather than pretending otherwise.
What you get
- Written assessment with findings ranked by risk and remediation effort
- A 30/60/90-day remediation plan with owners and cost estimates
- Core written policies — acceptable use, access control, incident response
- Onboarding and offboarding checklists your team can run without me
- Tested backup and recovery verification with documented recovery times
- Support answering customer security questionnaires accurately
A good fit when
You hold data that matters, a customer or insurer is asking questions, or you simply want to know where you stand before something forces the issue.
Not a fit when
You need a signed SOC 2 or formal HIPAA attestation today. That requires a licensed auditor — I can prepare you for one and help you scope it.
Common questions
Is this a penetration test?
No. It is a configuration and process review, which is what finds the issues that actually get small businesses breached. If a penetration test is genuinely warranted, I will say so and help you scope one.
Will you sell us security products?
Never. I take no commissions from any vendor. Most of what I recommend for small businesses is configuration of tools you already pay for, and a good number of the fixes cost nothing.
We are tiny. Is this overkill?
The assessment scales to the business. For a ten-person company it is a focused review of identity, backup and email, and the remediation list is usually short and cheap. Attackers do not skip you for being small; they target you for it.
Have a project you need to get right?
Book a free 15-minute call. No pitch, no jargon — just a straight read on whether I can help and what it would take.
Or email ryan@rmitcs.com

