Pass the audit. Keep the customer. Renew the policy.
The controls, the evidence, and the paperwork, without the panic.
Compliance pressure now reaches small companies: a defense customer asking for CMMC, a clinic bound by HIPAA, a tax practice under the FTC Safeguards Rule, or an insurer that will not renew without MFA and tested backups. We put the controls in place, keep the evidence, and answer the questionnaire with you.
Compliance & Cyber Insurance, in four parts
Gap assessment first
We map what the framework or insurer actually requires against what you have, and give you the list in priority order.
Controls that hold up
MFA, endpoint detection, encryption, access reviews, tested backups, logging. Deployed on the platforms we run, not promised.
Evidence, kept for you
Policies, screenshots, reports and reviews filed as you go, so an audit or a renewal is a folder, not a scramble.
Questionnaires answered with you
Cyber-insurance applications and customer security questionnaires completed accurately. A wrong answer can void a claim.
Does any of this sound familiar?
A customer sent a security questionnaire.
Forty questions, a deadline, and nobody sure what half of them mean.
The insurer wants MFA and EDR by renewal.
The policy is the condition of the bank loan, and the renewal is in six weeks.
CMMC is coming and the contract depends on it.
The prime asked for a self-assessment score and an SPRS submission.
You are not sure what you already have.
Some controls exist, some are half done, and there is no evidence either way.
We turn all of it into a list, a plan and a folder of evidence.
What's actually included
Specific deliverables and cadences, so you can hold us to them.
Frameworks we work in
- CMMC 2.0 Level 1 and Level 2 readiness for defense-supply-chain manufacturers, including NIST SP 800-171 gap assessment, SSP and POA&M, and SPRS scoring support
- HIPAA Security Rule for clinics, dental practices and business associates: risk analysis, safeguards, policies and workforce training
- FTC Safeguards Rule for tax preparers, accountants and finance offices: the written information security plan (WISP) and the controls behind it
- Cyber-insurance requirements: MFA, endpoint detection and response, backup testing, email security, security awareness training
Controls we implement
- Multi-factor authentication enforced across Microsoft 365, VPN and remote access
- Managed endpoint detection and response on every workstation and server
- Encryption at rest on laptops and mobile devices, with recovery keys escrowed
- Quarterly access reviews, same-day offboarding, least-privilege administration
- Backups with documented, tested restores and an offline copy
- Centralised logging and alerting with retention that satisfies your framework
Paperwork and proof
- Policy set written for your size: acceptable use, access control, incident response, backup, vendor management
- Evidence library maintained continuously: reports, screenshots, training records, review minutes
- Cyber-insurance applications and renewals completed with you, answer by answer
- Customer and prime-contractor questionnaires answered from the evidence library
- Annual review and re-assessment so the posture does not drift between audits
How fast we respond
The same published targets that cover every managed IT client.
P1You're down and nobody can work.
Critical outage — total business stop
First response30 minutes
Resolution goal2 hours
P2Something important is broken or crawling.
High impact — major degradation
First response1 hour
Resolution goal4 hours
P3One person needs something sorted.
Standard — individual request
First response2 hours
Resolution goal8 hours
Targets apply during business hours, Monday–Friday, 8:00am–5:00pm CT. Initial response is when a human has your ticket and has replied — not an autoresponder. Resolution goal is our target, not a guarantee; complex work sometimes runs longer, and we tell you when it will.
The phone is answered around the clock.
Call at 2am and a person picks up — not voicemail, not an offshore queue. We triage it on the spot.
- A genuine emergency gets a technician engaged that night. After-hours and emergency rates apply.
- Anything that can wait goes into the queue for the next business day, and you'll be told which it is.
- Round-the-clock coverage is available as an add-on for businesses that can't wait until morning — several of our clients run it.
Know exactly where you stand before the questionnaire or the auditor arrives.
- The framework or insurer requirements that apply to you, in plain English
- What you already have, what is missing, and what it will take
- Help with the questionnaire sitting in your inbox
- 1.We read every message the day it comes in.
- 2.A real person replies within one business day.
- 3.A quick, no-pitch call — you decide what's next.
What owners ask us first
No, and be wary of anyone who says they do. Certification is done by an accredited third-party assessor. We get you ready: the gap assessment, the controls, the System Security Plan, the plan of action, and the evidence an assessor will ask for.
If you handle Federal Contract Information or Controlled Unclassified Information for a defense prime, yes, and the primes are already asking their suppliers for scores. Level 1 is 17 practices most well-run shops can meet; Level 2 is 110 and takes planning. We will tell you which one applies.
We complete it with you, from evidence, and we will not answer yes to a control you do not have. Inaccurate applications are the most common reason claims are denied. If a control is missing, we put it in place first.
A written information security plan with a named person responsible, a risk assessment, access controls, encryption, MFA, staff training, vendor oversight, an incident response plan and periodic review. We build and maintain the plan and the controls behind it.
A cyber-insurance readiness project is usually a few weeks. HIPAA and Safeguards programs take one to three months to stand up. CMMC Level 2 readiness is typically three to nine months depending on where you start. The gap assessment gives you the real number.
Know exactly where you stand before the questionnaire or the auditor arrives.
CMMC, HIPAA, the FTC Safeguards Rule and cyber-insurance questionnaires, handled: the controls put in place, the evidence kept, the forms answered truthfully.
No obligation. No sales pressure. Just an honest conversation.