Author: J. Mesa

  • The Security Policies Every Small Business Needs

    By J. Mesa

    An auditor, an insurance underwriter, and a new enterprise customer all open with the same request: send us your security policies. Many small businesses answer with silence or with a template downloaded the night before. Written policies are where a security program starts, because you can’t train people on rules that do not exist and you can’t enforce a rule nobody wrote down.

    What is an information security policy?

    An information security policy is a written statement of the rules your business follows to protect its information and systems. It says what must happen, who is responsible, and what the rule applies to. Leadership approves it, and every employee reads and acknowledges it.

    What is the difference between a policy, a standard, and a procedure?

    • A policy states the rule. “All employees use multi-factor authentication to access company email.”
    • A standard sets the specific requirement. “Authenticator apps or security keys. No text message codes for administrators.”
    • A procedure gives the steps. “To enroll, open the security settings page, choose Add method, and scan the code.”

    A small business can combine all three in a single document per topic. Keep the rule clear and the steps current.

    Which security policies does a small business need first?

    Start with these ten.

    1. Information security policy. The master document. It states leadership’s commitment, names the person responsible for security, defines the scope, and points to the other policies.
    2. Acceptable use policy. What employees may and may not do with company computers, email, internet access, and data. Cover personal use, software installation, and AI tools.
    3. Access control and password policy. Who gets access to what, how you approve it, password length, the password manager, multi-factor authentication, and how you remove access when someone leaves.
    4. Data classification and handling policy. The categories of data you hold, such as public, internal, and restricted, and the rules for storing, sending, and sharing each one.
    5. Incident response plan. Who to call and what to do when something goes wrong. See our guide to the first 24 hours.
    6. Backup and disaster recovery policy. What you back up, how often, where the copies live, how you test them, and how fast you need to recover. See the 3-2-1 rule.
    7. Remote work and mobile device policy. Requirements for home networks, personal devices, public Wi-Fi, and lost or stolen equipment.
    8. Vendor management policy. How you vet and monitor the companies that hold your data.
    9. Security awareness training policy. Who gets trained, how often, on what, and how you record it.
    10. Data retention and disposal policy. How long you keep each type of record and how you destroy paper, drives, and devices.

    Add these as you grow: patch and vulnerability management, change management, physical security, encryption, logging and monitoring, and a payment verification procedure for wires and bank detail changes.

    What should each policy contain?

    Use the same structure for each one.

    • Purpose. One or two sentences on why the policy exists.
    • Scope. The people, systems, and data it covers.
    • Policy statements. The rules, in numbered sentences that use “must.”
    • Roles and responsibilities. Who does what.
    • Exceptions. How someone requests one and who approves it.
    • Enforcement. The consequences of a violation.
    • Review. The owner, the approval date, the version, and the next review date.

    How long should a security policy be?

    Short enough that your staff read it. Two to four pages per policy suits most small businesses. A 60-page manual that sits unread protects nobody and creates a liability, because it documents rules you do not follow.

    Can I use a security policy template?

    Yes, as a starting point. Good free sources include the SANS Institute policy templates, the Center for Internet Security, and, for tax professionals, the Written Information Security Plan template in IRS Publication 5708.

    Then customize. Replace each generic statement with what your business does. Delete the sections that do not apply. A template that requires a “Change Advisory Board” at a six-person office tells an auditor that nobody read the document. Regulators and plaintiffs’ attorneys compare your written policy against your actual practice, and a gap between the two hurts more than a shorter, honest policy would.

    What do compliance rules require in writing?

    • HIPAA requires written policies and procedures for the Security Rule, kept for six years.
    • PCI DSS requirement 12 calls for an information security policy that you publish, maintain, and review at least once a year, along with an acceptable use policy and an incident response plan.
    • The FTC Safeguards Rule requires a written information security program and, above the small-business threshold, a written risk assessment and incident response plan.
    • Cyber insurance applications ask whether you maintain written policies and an incident response plan.
    • Customer contracts and SOC 2 audits request the full set.

    Who should write and approve the policies?

    Assign one owner, usually the person responsible for security. Involve the people who know how the work happens: your IT provider, HR, the office manager, and the finance lead. Have an attorney review the policies that touch employment, privacy, and monitoring. The business owner or the board approves the final versions in writing. That approval carries weight with staff and with auditors.

    How do I get employees to follow them?

    • Explain the reason behind each rule. People follow rules they understand.
    • Make the secure way the easy way. Provide the password manager, the approved file sharing tool, and the approved AI tool, so staff have no need for workarounds.
    • Cover the policies at hiring, and collect a signed acknowledgment.
    • Reinforce them in training with examples from your own business.
    • Have leaders follow the same rules. An owner who skips multi-factor authentication has cancelled the policy for everyone.
    • Respond to violations with consistency, and thank the people who report mistakes.

    How often should I review the policies?

    Once a year at minimum. Review a policy sooner after a security incident, a new law or contract requirement, a major technology change, or a change in how the business operates. Record the review date and what changed. A policy last touched four years ago, with a former employee listed as the owner, will draw a finding.

    What are the most common policy mistakes?

    • Copying a template without changing it
    • Writing rules the business can’t or won’t follow
    • Publishing the policies and never training anyone on them
    • No named owner
    • No review dates
    • No process for exceptions, so staff invent their own
    • Storing the incident response plan only on the systems an attack would lock
    • Treating the documents as the goal and the practice as optional

    How do I start?

    1. List the regulations and contracts that apply to you.
    2. Write the information security policy and the acceptable use policy first.
    3. Add the incident response plan.
    4. Work through the rest of the ten over 90 days.
    5. Have leadership approve each one.
    6. Train the staff and collect acknowledgments.
    7. Put the next review date on the calendar.

    Your next step

    Gather every security policy your business has today and check each one for an owner, an approval, and a date within the last year. The ones that fail the check are your starting list. Policy and documentation development is one of the three core services at Cerberus Cybersecurity. We write policies that match how your business runs and that hold up in front of auditors. See our services or contact us.

  • What Is a vCISO, and Does Your Small Business Need One?

    By J. Mesa

    A customer sends you a 200-question security questionnaire. Your insurer asks who is responsible for your security program. A regulation requires you to name a qualified person to run it. Your honest answer to each: the owner, in spare time, with help from the IT company. A virtual CISO exists for businesses in that position.

    What is a vCISO?

    A vCISO, or virtual chief information security officer, is an outside security leader who runs your security program on a part-time or contract basis. You may also see the role called a fractional CISO. The vCISO sets strategy, manages risk and compliance, writes policy, and answers to the owner, without joining your payroll as a full-time executive.

    What does a CISO do?

    A chief information security officer owns the security program. The CISO decides what to protect and in what order, sets the rules, measures whether they work, answers to leadership, and takes charge when an incident occurs. Large companies employ one full time. A full-time CISO in the United States commonly earns more than $200,000 a year, which puts the role out of reach for most small businesses.

    What does a vCISO do for a small business?

    • Risk assessment. Identifies what you hold, what threatens it, and which gaps matter most.
    • Roadmap and budget. Turns the assessment into a prioritized plan with costs and dates.
    • Policies and procedures. Writes the documents that auditors, insurers, and customers ask to see, and that your staff follow.
    • Compliance. Maps your program to HIPAA, PCI DSS, the FTC Safeguards Rule, or the framework your customers require.
    • Vendor oversight. Reviews the security of the companies that hold your data.
    • Incident response planning. Writes the plan, runs the tabletop exercise, and advises during a real event.
    • Training. Sets the awareness program and often delivers it.
    • Questionnaires and audits. Completes customer security questionnaires and insurance applications with accurate answers and evidence.
    • Reporting. Briefs the owner or the board on risk in plain language, on a set schedule.
    • Technology decisions. Advises on which security tools you need and which you can skip.

    How is a vCISO different from my IT provider?

    Your managed service provider keeps the systems running: it sets up computers, resets passwords, applies patches, and operates the tools. A vCISO governs: it decides what the rules are, checks whether the IT work meets them, and reports to you on the result.

    The separation has value. An IT provider that assesses its own work has a conflict of interest. An independent vCISO reviews that work with fresh eyes, and a good IT provider welcomes the review.

    Some IT providers sell a vCISO service of their own. Ask who performs it, what security credentials and experience that person holds, and how the provider handles a finding against its own work.

    How much does a vCISO cost?

    Pricing follows three models.

    • Monthly retainer. A set number of hours each month. Small businesses commonly pay $2,000 to $10,000 a month, depending on scope and complexity.
    • Hourly. Often $150 to $400 an hour.
    • Project. A fixed price for a defined result, such as a risk assessment, a policy set, or readiness for an audit.

    Even at the high end of a retainer, the cost comes to a fraction of a full-time executive’s salary and benefits.

    Does my small business need a vCISO?

    You likely do if any of these describe you:

    • A regulation applies to you, and nobody on staff can interpret it.
    • Customers or partners send security questionnaires you struggle to answer.
    • A cyber insurance application asked questions you could not answer with confidence.
    • You hold sensitive data: patient records, financial records, card data, or legal files.
    • You had an incident or a near miss.
    • You are growing, adding locations, or preparing to sell the business.
    • Security decisions fall to the owner or the office manager by default.

    A vCISO retainer may be more than you need if you run a handful of computers, hold little sensitive data, and face no compliance rule. In that case, start with a one-time risk assessment and a basic policy set, then revisit the question each year.

    Does a vCISO satisfy compliance requirements?

    In several cases, yes.

    • The FTC Safeguards Rule requires covered financial businesses to designate a Qualified Individual to run the security program. The rule allows an outside provider to fill the role, as long as a senior person at your business oversees the provider. See our Safeguards Rule guide.
    • HIPAA requires a named security official. That official should be a member of your workforce, and a vCISO supplies the expertise behind that person.
    • PCI DSS requires you to assign responsibility for information security to a specific person or team.
    • Enterprise customers often require a named security leader in their vendor contracts.

    Responsibility stays with you. You can hire the expertise. You can’t hand off the accountability.

    What should I look for in a vCISO?

    • Experience with businesses your size and in your industry. A program built for a bank will bury a 15-person firm in paperwork.
    • Knowledge of your regulations.
    • Recognized credentials, such as CISSP, CISM, or CISA, backed by real work history.
    • Plain language. You should understand each report without a glossary.
    • Independence. Be cautious when the advisor also sells the products it recommends.
    • Defined deliverables. The proposal should list what you receive and when.
    • References from businesses similar to yours.
    • Availability during an incident, stated in the contract.

    What questions should I ask before hiring one?

    1. Who will do the work: the person in this meeting or someone else?
    2. How many clients does that person serve?
    3. What will the first 90 days produce?
    4. Which framework will you use to measure us?
    5. How will you work with our IT provider?
    6. How and how often will you report to us?
    7. What happens when we have an incident at 6 p.m. on a Friday?
    8. Do you earn commissions on products you recommend?
    9. Who owns the documents you create for us?
    10. How do we end the engagement?

    What happens in the first 90 days?

    A typical start looks like this.

    • Days 1 to 30. Interviews, a review of your systems and documents, an inventory of data and vendors, and a risk assessment.
    • Days 31 to 60. A prioritized roadmap with a budget. Quick fixes begin: multi-factor authentication, backup verification, and removal of old accounts.
    • Days 61 to 90. Core policies written, an incident response plan in place, staff training scheduled, and a reporting rhythm set with the owner.

    After that, the vCISO works the roadmap, measures progress, and adjusts as your business and the threats change.

    What frameworks do vCISOs use?

    A framework gives the program a structure and a way to measure progress. Common choices for small businesses:

    • NIST Cybersecurity Framework 2.0. Organizes security into six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
    • CIS Critical Security Controls. A prioritized list of safeguards. Implementation Group 1 fits small businesses.
    • Industry rules, such as HIPAA and PCI DSS, mapped onto one of the above so you do the work once.

    Can I just use software or a compliance platform?

    Compliance platforms and policy templates help with tracking and paperwork. They do not make judgment calls. Software can’t decide which risk your business should accept, explain a finding to a customer’s auditor, or lead your staff through an incident. A tool supports a security leader. It does not replace one.

    What can a vCISO not do?

    A vCISO does not guarantee you will avoid a breach. A vCISO does not replace your IT provider or your attorney. And a vCISO can’t succeed without the owner’s backing, because security decisions involve budget, staff time, and the willingness to enforce a policy when it is inconvenient.

    Your next step

    Write down the name of the person at your business who is accountable for security. If the answer is “nobody” or “me, when I have time,” you have found the gap. Cerberus Cybersecurity provides risk and compliance assessments, policy development, and training for small businesses that need security leadership without a full-time hire. Contact us to talk through what fits.

  • Employee Offboarding Security Checklist: What to Do When Someone Leaves

    By J. Mesa

    An employee gives two weeks’ notice. You plan the farewell lunch and post the job opening. Three months later, that person’s email account still works, still forwards to a personal address, and still holds the login to your customer database. Former employees with live accounts cause breaches at small businesses each year, through malice in a few cases and through neglect in most.

    Why does offboarding matter for security?

    Every account you leave active is a door nobody watches. The former employee may use it. More often, an attacker does. Dormant accounts rarely have anyone reading their alerts, their passwords never change, and nobody notices a strange login. An attacker who finds one works without interruption.

    Departing employees also carry data out. Sales staff take customer lists. Others forward files to personal email “for reference.” Some of that is theft, and some is habit. Both leave your information outside your control.

    When should I remove a departing employee’s access?

    At the moment employment ends. For a planned resignation, schedule the removal for the end of the last shift. For an involuntary termination, remove access during the termination meeting, before the person returns to a desk. Coordinate the timing with whoever handles your IT, so the accounts close while the conversation takes place.

    A delay of a day gives an angry former employee a day. Remove first, tidy up afterward.

    What goes on an offboarding security checklist?

    Accounts and access

    1. Disable the main login: Microsoft 365, Google Workspace, or your directory account. Disabling beats deleting at this stage, because it preserves the data.
    2. Sign the user out of all active sessions and revoke app tokens.
    3. Remove the user’s multi-factor authentication devices and registered phones.
    4. Disable remote access: VPN, remote desktop tools, and remote support software.
    5. Remove the person from each business application: accounting, payroll, CRM, records system, scheduling, project tools, and the website.
    6. Remove the person from the company password manager, and change each shared password the person could see.
    7. Remove access to bank accounts, credit cards, payment processors, and vendor portals. Notify the bank in writing if the person was a signer.
    8. Remove administrator rights on social media pages, advertising accounts, and the domain registrar.

    Email and files

    1. Check the mailbox for forwarding rules and inbox rules, and remove them.
    2. Decide who receives the person’s incoming email. Forward it to a manager or convert the mailbox to a shared one.
    3. Set an automatic reply that directs contacts to the right person.
    4. Transfer ownership of the person’s files and shared folders to a manager.
    5. Review the files the person shared outside the company and remove the links.

    Devices and physical access

    1. Collect the laptop, phone, tablet, security keys, and portable drives.
    2. Collect keys, badges, and parking passes. Disable the badge.
    3. Change the alarm code, door codes, and safe combination.
    4. Remove company data from the person’s personal phone.
    5. Wipe and rebuild returned devices before you assign them to anyone else.

    Phone and communications

    1. Reassign the phone extension and change the voicemail PIN.
    2. Remove the person from group chats, shared calendars, and distribution lists.

    Records

    1. Remind the person, in writing, of confidentiality duties that continue after employment.
    2. Record the date and time of each step and who performed it.

    What about shared passwords and accounts?

    Shared accounts create the largest offboarding gap. One login for the supplier portal, one for the social media page, one for the Wi-Fi, all known to the person who just left. You must change each one.

    Find them all. Ask the departing employee and the manager for a list, and review the shared vaults in your password manager. Then reduce the problem for next time: give each person an individual login wherever the service allows it, and store the few shared ones in the password manager, where you can see who had access.

    How do I handle a departing employee’s email?

    Keep the mailbox. Do not delete it on the last day. You may need its contents for customer follow-up, legal reasons, or an investigation.

    In Microsoft 365, convert the mailbox to a shared mailbox and give a manager access. In Google Workspace, transfer the data or keep the account suspended until you archive it. Set a retention period in your policy, such as 90 days for routine roles and longer for regulated records, then archive or delete on schedule.

    Check the forwarding rules first. A rule that sends a copy of every message to a personal address keeps running after the person walks out.

    What about personal devices?

    If the employee used a personal phone or computer for work, you need a way to remove company data from it. With mobile device management or app protection policies, you can wipe the work apps and leave the personal content alone. Without those tools, you depend on the employee’s cooperation. Sit down together on the last day, remove the work accounts from the device, and confirm that company files are gone from personal cloud storage.

    A written device policy that the employee signed at hiring gives you the right to do this. See our post on smartphone security.

    What about contractors and vendors?

    Apply the same checklist. Contractors, temporary staff, interns, and vendor technicians often hold access with no end date. Set an expiration date on each account at the time you create it. When a vendor’s technician leaves that vendor, ask the vendor to confirm that the technician’s access to your systems ended. Our guide to vendor risk management covers the contract terms.

    How do I handle an IT administrator who leaves?

    With extra care. An administrator knows where everything is and may hold access that appears on no list.

    • Change the passwords on every administrator and service account, including the firewall, the router, the backup system, the domain registrar, and the cloud admin consoles.
    • Search for accounts the administrator created, and disable the ones you can’t explain.
    • Check for remote access tools installed on servers and workstations.
    • Review scheduled tasks, automation scripts, and API keys.
    • Confirm that the company, and not the individual, owns the domain name, the cloud tenant, and the software licenses.
    • Have a second administrator or an outside firm review the environment.

    Avoid a single point of knowledge. At least two people should hold administrator access, and the documentation should live where the owner can reach it.

    Does compliance require an offboarding process?

    Yes.

    • HIPAA requires procedures for ending access to patient information when employment ends.
    • PCI DSS requires you to revoke access for terminated users at once.
    • The FTC Safeguards Rule requires access controls with periodic review.
    • Cyber insurers ask how you remove access for former employees.

    Keep the completed checklist for each departure. It is your evidence.

    How do I make offboarding easier?

    Start at hiring.

    • Keep an access record for each person. List the accounts, devices, keys, and shared passwords you issue, as you issue them.
    • Use single sign-on where you can. One disabled login then closes many applications.
    • Assign access by role. A standard set for each job simplifies both granting and removing.
    • Give HR and IT one shared process. HR tells IT about each departure in advance, in writing.
    • Review access every quarter. Compare the active account list against the current staff list. Remove the accounts that match nobody.
    • Use company-owned accounts. Register social media, domains, and software under a company email address, never an employee’s personal one.

    What are the most common offboarding mistakes?

    • Waiting days or weeks to disable accounts
    • Forgetting the applications that sit outside single sign-on
    • Leaving shared passwords unchanged
    • Letting email forward to a personal address
    • Deleting the mailbox and losing the records
    • Forgetting the door code and the alarm code
    • Skipping contractors and interns
    • Keeping no record of what you did

    Your next step

    Print the checklist above and run it against the last person who left your business. Each account you find still active is a gap to close today. Cerberus Cybersecurity writes access control and offboarding procedures and reviews account hygiene in our risk and compliance assessments. Contact us for help building yours.

  • Smartphone Security: How to Protect the Phone That Runs Your Business

    By J. Mesa

    Your phone receives your bank’s security codes. It holds your work email, your customer texts, your authenticator app, and your saved passwords. A thief who gets into it gets into nearly everything else. Summer travel season raises the odds of a lost or stolen phone, so spend fifteen minutes on the settings below before your next trip.

    Why do criminals target phones?

    A phone is the key ring for your digital life. Password resets go to its email. Verification codes go to its text messages. Banking apps live on its home screen. Criminals pursue phones in four ways: stealing the device, hijacking the phone number, tricking you with a text message, and planting a malicious app.

    What are the most important phone security settings?

    Work through this list.

    1. Set a strong passcode. Use six digits at minimum. A longer alphanumeric passcode is better. Skip birthdays and repeated numbers.
    2. Use Face ID or fingerprint unlock. Biometrics keep you from typing the passcode in public, where a thief can watch.
    3. Set the screen to lock after 30 seconds to one minute.
    4. Turn on automatic updates for the operating system and for apps.
    5. Turn on the theft protections. On an iPhone, enable Stolen Device Protection. On Android, enable Theft Detection Lock and Identity Check where available. These features demand a biometric check, and sometimes a delay, before anyone changes your account password or security settings.
    6. Turn on Find My on iPhone or Find Hub on Android, so you can locate, lock, and erase a missing phone.
    7. Hide message previews on the lock screen. A thief should not be able to read a verification code without unlocking the phone.
    8. Back up the phone to iCloud or your Google account, with a strong password and multi-factor authentication on that account.
    9. Limit what works from the lock screen: wallet, control center, voice assistant, and USB accessories.

    Thieves in bars and on transit watch a victim type a passcode, then grab the phone. With the passcode, they change the account password within minutes and lock the owner out. The theft protection features in step 5 exist to stop that attack.

    What is SIM swapping, and how do I prevent it?

    SIM swapping is a fraud in which a criminal convinces your mobile carrier to move your phone number to a SIM card or eSIM the criminal controls. Your phone loses service. The criminal receives your calls and texts, including the codes your bank and email provider send.

    Protect the number:

    • Add a port-out or number transfer PIN with your carrier.
    • Turn on the carrier’s SIM protection or number lock feature. AT&T, Verizon, and T-Mobile each offer one in their apps.
    • Set a unique password and multi-factor authentication on your carrier account.
    • Move your important accounts away from text message codes. Use an authenticator app, a security key, or a passkey.

    If your phone shows “No service” or “SOS only” in a place where it normally works, call your carrier from another phone at once, then check your bank and email accounts.

    What is smishing?

    Smishing is phishing by text message. Common versions claim an unpaid toll, a package that could not be delivered, a bank fraud alert, or a message from your boss asking for gift cards. The link leads to a fake page that collects your card number or password.

    Do not tap links in unexpected texts. Do not reply. Open the company’s app or type its address yourself. Forward the text to 7726, which spells SPAM, and delete it.

    Are iPhones more secure than Android phones?

    Both are secure when you keep them updated and install apps only from the official store. The differences that matter:

    • Apple controls the hardware and the software, so iPhones receive updates for many years on one schedule.
    • Android update support depends on the maker. Google Pixel and recent Samsung Galaxy phones receive up to seven years. Low-cost models may receive two or three.
    • Android allows app installs from outside the Play Store. Leave that setting off.

    An old, unpatched phone of either type is the real risk. Check your model’s support end date, and replace the phone when updates stop.

    How do I spot a dangerous app?

    • Install apps only from the App Store or Google Play.
    • Read the developer name and the reviews. Fake apps copy the icons of real ones.
    • Question the permissions. A flashlight app has no need for your contacts, microphone, or location.
    • Review app permissions twice a year and remove apps you no longer use.
    • Decline any request to install a configuration profile or enable accessibility access unless your own IT team asked for it.
    • Leave Play Protect on.

    Is public Wi-Fi safe on a phone?

    Mostly, for everyday use. Apps and websites encrypt their traffic. The remaining risks are fake networks that imitate the hotel or airport name and login pages that ask for personal details. Use cellular data or your own hotspot for banking and work. Turn off automatic joining of open networks.

    Should I worry about public USB charging stations?

    The risk is low on a current phone, which asks before it allows a data connection over USB. Carry your own charger and cable or a power bank, and tap “Do not allow” or “Charge only” if the prompt appears.

    Should employees use personal phones for work?

    Many small businesses rely on personal phones. That arrangement is called bring your own device, or BYOD. It works when you set rules in a written policy.

    • Minimum requirements. A passcode, automatic lock, encryption, a supported operating system, and automatic updates.
    • Approved apps. Staff reach company email and files through approved apps, such as Outlook or the Google Workspace apps, and not through whatever mail app came with the phone.
    • Company control of company data. State that the business may remove its data from the phone when the employee leaves or the phone goes missing.
    • Reporting. Require staff to report a lost or stolen phone within hours.
    • Privacy. State what the company can and can’t see on a personal device.
    • Offboarding. Remove company accounts on the employee’s last day.

    Businesses that handle patient, card, or financial data should issue company-owned phones to the staff who handle it, or manage the personal ones.

    What is mobile device management?

    Mobile device management, or MDM, is software that lets a business enforce security settings on phones and tablets, push required apps, and erase company data from a distance. Microsoft Intune comes with Microsoft 365 Business Premium. Google Workspace includes endpoint management. For personal phones, app protection policies let you control and wipe the work apps while leaving personal photos and messages untouched.

    What should I do if my phone is lost or stolen?

    1. Use Find My or Find Hub from another device to mark the phone as lost and lock it.
    2. Call your carrier to suspend service and block the SIM.
    3. Change the password for your Apple or Google account, then for email and banking.
    4. Tell your employer or your IT provider so they can remove company data and end active sessions.
    5. Erase the phone from a distance if you do not expect to recover it.
    6. Report the theft to the police, and give them the serial or IMEI number.
    7. Watch for texts or emails that claim your phone was found and ask you to sign in. Thieves send them to capture your account password and unlock the device.
    8. Move your authenticator app and passkeys to the replacement phone, and remove the old device from each account.

    Plan for step 8 before you travel. Save backup codes for your important accounts and store them on paper at home.

    How do I prepare an old phone for sale or disposal?

    Back it up. Sign out of your Apple or Google account. Remove the SIM card and erase the eSIM. Run the factory reset from the settings menu. For a company phone, record the serial number and the date in your asset inventory.

    What about travel?

    Update the phone before you leave. Confirm that Find My and the theft protections are on. Carry a power bank. Keep the phone in a front pocket or a zipped bag in crowds, and avoid typing your passcode where others can watch. Know your carrier’s number for reporting a lost phone from abroad.

    Your next step

    Check three settings tonight: the theft protection feature, the SIM lock with your carrier, and lock screen previews. Then ask how many personal phones carry your company’s email. Cerberus Cybersecurity writes mobile device and remote work policies and covers phone threats in our cybersecurity training. See our services or contact us.

  • Using AI Chatbots at Work: The Security Policy Every Small Business Needs

    By J. Mesa

    Your employees use AI chatbots at work. Some use tools you bought. Others use free personal accounts you have never seen. They paste in emails to polish, contracts to summarize, and spreadsheets to analyze. Most mean well. Few of them stop to ask where that text goes. A short written policy fixes the problem without banning a useful tool.

    Is it safe to use AI chatbots at work?

    Yes, with rules. The tools themselves are legitimate products from large companies. The risk comes from what your staff type into them, which account they use, and how much they trust the output.

    What are the risks of using AI at work?

    • Data exposure. Text pasted into a chatbot leaves your control. On many free and personal plans, the provider may keep the conversation and use it to train future models.
    • Confidentiality and compliance. Patient details, card numbers, and client financial records carry legal duties. A free chatbot account comes with no contract that covers them.
    • Wrong answers. AI tools produce confident text that contains errors, invented citations, and made-up numbers. Lawyers have been sanctioned for filing briefs with cases an AI tool invented.
    • Account compromise. A chat history holds everything an employee ever pasted. A stolen password hands that history to a criminal.
    • Prompt injection. A document, email, or web page can hide instructions that an AI assistant follows. An assistant connected to your inbox could be told to forward messages to a stranger.
    • Fake tools. Criminals publish look-alike AI apps and browser extensions that steal data.
    • Shadow AI. Staff adopt tools on their own, and you lose track of where company data lives.

    Does the AI provider train on my data?

    It depends on the product and the plan. As a general pattern:

    • Free and personal plans often allow training on your conversations by default. Most offer a setting to turn that off.
    • Business, team, and enterprise plans from the major providers state that they do not train on your business data by default, and they offer administrator controls, single sign-on, and data processing agreements.
    • API access follows separate terms, usually with no training by default.

    Terms change. Read the current privacy policy and data terms for the exact product and plan before you approve it, and record the date you checked.

    What should employees never put into an AI chatbot?

    Unless the company approved the tool for that kind of data, keep these out:

    • Passwords, API keys, and security codes
    • Social Security numbers, driver’s license numbers, and dates of birth
    • Payment card and bank account numbers
    • Patient health information
    • Client tax returns and financial records
    • Employee records and performance matters
    • Contracts and documents under a confidentiality agreement
    • Legal advice and privileged communications
    • Unreleased financial results and pricing
    • Proprietary source code and trade secrets
    • Network diagrams, firewall rules, and security reports

    A simple test for staff: if you would not post it on a public website, do not paste it into an unapproved AI tool.

    What is shadow AI?

    Shadow AI is the use of AI tools at work without the company’s knowledge or approval. It includes personal chatbot accounts, AI browser extensions, meeting note-takers that join calls, and AI features that appear inside software you already use.

    Banning AI does not end shadow AI. It pushes the use onto personal phones and personal accounts, where you see nothing. Offering an approved tool and clear rules works better.

    How do I write an AI acceptable use policy?

    Keep it to one or two pages. Cover these points.

    1. Approved tools. List the AI tools and plans staff may use for work. Everything else needs approval first.
    2. Accounts. Staff use company accounts for work. No personal accounts for company data.
    3. Data rules. Sort your data into three groups: public, internal, and restricted. State which groups may go into which tools. Restricted data goes only into tools approved for it in writing.
    4. Human review. A person checks all AI output for accuracy before it reaches a customer, a regulator, or a decision. The employee who sends it owns it.
    5. Prohibited uses. No AI for final decisions on hiring, firing, lending, or medical care without human judgment. No impersonation. No use that breaks a law or a client contract.
    6. Disclosure. State when staff must tell a client or a supervisor that AI helped produce the work.
    7. New tool requests. Name the person who reviews requests and how fast.
    8. Meeting recorders. Require consent from all participants and approval for the tool.
    9. Security. Require multi-factor authentication on AI accounts.
    10. Reporting. Tell staff to report a mistake, such as pasting restricted data, right away and without fear of punishment.
    11. Review date. Revisit the policy every six months. This field changes fast.

    How do I choose a safe AI tool for my business?

    Run it through your vendor review.

    • Does the business plan exclude your data from training?
    • How long does the provider keep conversations, and can you delete them?
    • Does it offer administrator controls, single sign-on, and audit logs?
    • Does it hold a SOC 2 Type II report or ISO 27001 certification?
    • Will it sign the agreement your industry requires, such as a business associate agreement for HIPAA?
    • Where does it store data?

    Paying for a business plan for ten employees costs far less than one disclosure of client records through a free account.

    What about AI built into the software I already use?

    Microsoft 365 Copilot, Google Gemini in Workspace, and AI features in accounting, CRM, and records software work inside your existing accounts. That brings a specific risk: the assistant can reach whatever the user can reach.

    Many small businesses share folders more widely than they realize. An assistant makes that visible. An employee who asks about salaries may get an answer drawn from an HR folder that was open to everyone all along. Before you turn these features on, clean up file permissions and confirm that sensitive folders are limited to the people who need them.

    What are AI agents, and why do they raise the stakes?

    An AI agent does more than answer questions. It takes actions: it reads your email, books meetings, browses websites, fills in forms, and runs tasks across your accounts. An agent that reads untrusted content can be tricked by hidden instructions in that content.

    Set limits before you deploy one.

    • Give the agent the lowest level of access the task requires.
    • Require a human to approve payments, deletions, outgoing messages to customers, and changes to settings.
    • Keep agents away from banking and administrator accounts.
    • Review the logs of what the agent did.

    Can I use AI with patient, card, or financial data?

    Only with a tool approved for it and a contract that covers it.

    • HIPAA. You need a signed business associate agreement with the AI provider before any patient information goes in. Free consumer tools offer none.
    • PCI DSS. Keep card numbers out of AI tools.
    • FTC Safeguards Rule. An AI provider that receives customer financial information is a service provider. Assess it, and put security terms in the contract.

    How do I train employees on AI?

    Add a short module to your security awareness training. Show real examples: a prompt that is fine, a prompt that leaks client data, and an AI answer that contains an invented fact. Teach staff to remove names and identifying details before they paste. Explain how to verify output. Repeat the training when the tools change.

    What should I do if someone pasted sensitive data into a chatbot?

    1. Thank the employee for reporting it.
    2. Delete the conversation and check the account’s data settings.
    3. Change any password or key that was exposed.
    4. Record what data, which tool, which account, and when.
    5. Ask your attorney whether the event triggers a notification duty.
    6. Use the event to improve the policy and the training.

    Your next step

    Ask your staff one question at the next meeting: which AI tools do you use for work? Listen without judgment and write down the answers. That list is the starting point for your policy. Cerberus Cybersecurity writes AI acceptable use policies and trains teams to follow them. See our services or contact us.

  • Vendor Risk Management: How to Vet the Companies That Hold Your Data

    By J. Mesa

    Your payroll provider holds your employees’ Social Security numbers. Your IT company holds an administrator password to every computer you own. Your billing service holds your customers’ records. You chose each vendor for price and service. An attacker chooses them for a different reason: one break-in at a vendor opens the door to every one of its clients.

    What is vendor risk management?

    Vendor risk management is the process of identifying which outside companies can reach your data or systems, checking how well they protect them, setting security terms in the contract, and reviewing them over time. You may also see it called third-party risk management.

    Why do vendors matter to a small business?

    Because you can outsource the work and still own the responsibility. When a vendor loses your customers’ data, the customers and the regulators come to you.

    The record backs this up:

    • In 2013, attackers reached Target’s payment systems with credentials stolen from a heating and air conditioning contractor.
    • In 2021, criminals pushed ransomware through Kaseya’s remote management software to the clients of dozens of IT providers. Many victims were dental offices, accounting firms, and other small businesses.
    • In 2023, a flaw in the MOVEit file transfer tool exposed data from thousands of organizations, many of which had never heard of MOVEit. Their vendors used it.
    • In 2024, the attack on Change Healthcare froze billing for medical practices across the country for weeks.

    Verizon’s 2025 Data Breach Investigations Report found a third party involved in 30 percent of breaches, double the share from the year before.

    Which vendors should I worry about?

    Sort your vendors by what they can touch.

    • High risk. Vendors that hold sensitive data or have administrator access to your systems: IT providers, cloud email and file storage, payroll and HR platforms, accounting and tax software, billing services, records systems, backup providers, and payment processors.
    • Medium risk. Vendors with limited data or limited access: marketing platforms with customer email lists, website developers, scheduling tools, phone systems.
    • Low risk. Vendors with no data and no access: office supplies, landscaping, the coffee service.

    Spend your time on the high-risk group. A typical small business has 5 to 15 vendors in it.

    How do I build a vendor inventory?

    Open a spreadsheet and add a row for each vendor. Record:

    • Vendor name and what it does for you
    • The data it can reach
    • The system access it holds
    • The risk tier
    • The person at your business who owns the relationship
    • Contract start and renewal dates
    • Whether you have a security review and a signed agreement on file

    To find the vendors you forgot, review a year of bank and credit card statements, the list of applications connected to your Microsoft 365 or Google Workspace account, and the software your staff signed up for without asking. That last group, called shadow IT, often holds more company data than anyone realized.

    What should I ask a vendor about security?

    For a high-risk vendor, ask these questions before you sign and again at renewal.

    1. Do you hold a current independent security report or certification, such as SOC 2 Type II or ISO 27001? May we see it?
    2. Do you require multi-factor authentication for your staff and offer it to us?
    3. Do you encrypt our data in transit and at rest?
    4. Who at your company can see our data, and how do you control that access?
    5. Where do you store our data, and which subcontractors can reach it?
    6. Have you had a breach in the last three years? What changed afterward?
    7. How quickly will you notify us of an incident involving our data?
    8. How often do you back up our data, and have you tested a restore?
    9. Do you carry cyber insurance?
    10. What happens to our data when the contract ends?

    A vendor that refuses to answer, or answers with marketing copy, has told you something.

    What is a SOC 2 report?

    A SOC 2 report is an independent auditor’s examination of a service company’s controls for security, availability, confidentiality, processing integrity, and privacy. A Type I report describes the controls at one point in time. A Type II report tests whether the controls worked over a period, commonly 6 to 12 months. Ask for Type II.

    Read three parts: the auditor’s opinion, the list of exceptions, and the section on what the vendor expects you to do. A SOC 2 report shows that an auditor looked. It does not guarantee the vendor will avoid a breach.

    Small vendors often lack a SOC 2 report. In that case, rely on the questions above and on the contract.

    What should the contract say?

    Put the security terms in writing. Look for these clauses, or ask to add them:

    • A duty to protect your data with reasonable, specified safeguards
    • Breach notification within a set time, such as 72 hours
    • Limits on using your data for anything beyond the service
    • Disclosure of subcontractors, and the same duties passed down to them
    • Return or deletion of your data at termination, with written confirmation
    • A right to request security documentation each year
    • A cyber insurance requirement
    • Allocation of costs if the vendor’s failure causes a breach

    A large vendor will not negotiate its standard terms with a ten-person business. Read them anyway. You need to know what you agreed to, and the terms may decide which vendor you choose.

    Does compliance require vendor oversight?

    Yes, in each of the major rules.

    • HIPAA requires a signed business associate agreement with every vendor that handles patient information.
    • The FTC Safeguards Rule requires you to select capable service providers, set security expectations by contract, and assess them on a schedule.
    • PCI DSS requires a list of the service providers that touch card data, written agreements, and a yearly check of their compliance status.
    • Cyber insurance applications ask how you manage vendors.

    How do I limit the access a vendor has?

    Assume that a vendor will suffer a breach at some point, and reduce what the attacker gains.

    • Give each vendor its own named account. No shared logins.
    • Grant the lowest level of access that lets the vendor do the job.
    • Require multi-factor authentication on every vendor account.
    • Turn remote access on when the vendor needs it and off when the work ends.
    • Send the vendor only the data it needs. A marketing firm does not need dates of birth.
    • Review the logs of what vendor accounts did.
    • Review connected third-party applications in your cloud accounts twice a year and remove the ones you do not use.

    What about my IT provider?

    Your managed service provider holds more access than any other vendor, so it deserves the hardest questions. Ask how it protects its own remote management tools, whether every technician uses multi-factor authentication, how it stores your passwords, whether it separates one client’s access from another’s, and what it will do for you during an incident. Ask for its incident response plan and proof of insurance. A good provider welcomes these questions.

    What should I do when a vendor has a breach?

    1. Get the facts in writing: what data, which dates, how many of your records.
    2. Change the passwords and API keys tied to that vendor, and cut off its access until it confirms containment.
    3. Call your attorney and your cyber insurance carrier. You may have notification duties even though the vendor caused the event.
    4. Follow your incident response plan.
    5. Watch for phishing that uses the stolen data to target your staff and customers.
    6. Decide whether the vendor keeps your business.

    How do I end a vendor relationship securely?

    Offboard a vendor the way you offboard an employee. Disable its accounts and remote access tools. Change any shared passwords. Retrieve your data, then get written confirmation that the vendor deleted its copies. Remove its software from your systems. Update the inventory.

    How often should I review vendors?

    Review high-risk vendors once a year and at each contract renewal. Review any vendor right away when it has a breach, changes ownership, or changes what it does for you.

    Your next step

    List your top five vendors by the sensitivity of the data they hold. Send each one the ten questions above. Cerberus Cybersecurity builds vendor management policies and reviews third-party risk as part of our risk and compliance assessments. Contact us to start your inventory.

  • The FTC Safeguards Rule Explained: Does It Apply to Your Business?

    By J. Mesa

    Tax season puts thousands of Social Security numbers and bank account details into the hands of small firms. If you prepare tax returns, the federal government classifies you as a financial institution, and the FTC Safeguards Rule applies to you. The same holds for car dealers, mortgage brokers, and a long list of businesses that never thought of themselves as banks.

    What is the FTC Safeguards Rule?

    The Safeguards Rule is a federal regulation that requires certain businesses to build and maintain a written information security program that protects customer information. The Federal Trade Commission issued it under the Gramm-Leach-Bliley Act, or GLBA. The FTC updated the rule with detailed technical requirements that took effect on June 9, 2023.

    Banks and credit unions answer to their own regulators. The FTC’s rule covers the non-bank financial institutions.

    Who has to comply?

    The rule applies to businesses that are “significantly engaged” in financial activities. Examples include:

    • Tax preparers and accounting firms that prepare returns
    • Mortgage brokers and lenders
    • Auto dealers that arrange financing or leasing
    • Payday and title lenders
    • Finance companies
    • Check cashers and wire transfer services
    • Collection agencies
    • Credit counselors and financial advisors not registered with the SEC
    • Real estate settlement and appraisal services
    • Businesses that connect borrowers with lenders, which the rule calls finders

    A retailer that only accepts credit cards issued by others is not covered. A retailer that issues its own credit card is.

    What counts as customer information?

    Customer information means any record containing nonpublic personal information about a customer that you or your service providers handle, on paper or in electronic form. For a tax firm that means returns, W-2s, Social Security numbers, dates of birth, bank account and routing numbers, and income details. For a dealership it means credit applications, credit reports, driver’s license copies, and financing documents.

    What does the Safeguards Rule require?

    Your information security program must contain nine elements.

    1. Designate a Qualified Individual to run the program. This can be an employee or an outside provider. If you outsource the role, a senior person at your business still oversees it.
    2. Conduct a written risk assessment that identifies the risks to customer information and judges the safeguards you have.
    3. Design and implement safeguards to control those risks. The rule names specific ones, listed below.
    4. Monitor and test the safeguards on a regular schedule.
    5. Train your staff in security awareness.
    6. Oversee your service providers. Choose vendors that can protect the data, put security terms in the contract, and reassess them.
    7. Keep the program current as your business, your risks, and your test results change.
    8. Write an incident response plan.
    9. Report to the board or governing body in writing at least once a year. In a small firm, the Qualified Individual reports to the owner or senior officer.

    What specific safeguards does the rule name?

    • Access controls that limit customer information to people who need it, with periodic review
    • An inventory of your data, devices, systems, and where the information lives
    • Encryption of customer information at rest and in transit
    • Secure development practices for any applications you build or use to handle the data
    • Multi-factor authentication for anyone accessing customer information on your systems
    • Secure disposal of customer information no later than two years after you last used it to serve the customer, unless a law or a business need requires you to keep it
    • Change management procedures
    • Logging and monitoring of user activity to detect unauthorized access

    Is there an exemption for small businesses?

    A partial one. If you maintain customer information on fewer than 5,000 consumers, you are exempt from four items:

    • The written risk assessment
    • Continuous monitoring, or the annual penetration test and twice-yearly vulnerability assessments
    • The written incident response plan
    • The annual written report to the board

    Everything else still applies: the Qualified Individual, the safeguards, encryption, multi-factor authentication, training, vendor oversight, and secure disposal. You must still assess your risks. The exemption removes the requirement to write the assessment in the prescribed form. Writing it anyway gives you proof that you did the work.

    Count carefully. The 5,000 figure covers every consumer whose information you hold, including former customers still in your files.

    Who can serve as the Qualified Individual?

    The rule sets no degree or certification requirement. The person needs enough real-world security knowledge to fit the size and complexity of your business. A small firm can appoint a capable office manager supported by an outside security provider, or hire a provider to fill the role. You keep the responsibility in either case.

    What testing does the rule require?

    Businesses above the 5,000-consumer threshold must either monitor their systems continuously or perform:

    • A penetration test once a year
    • Vulnerability assessments every six months, and after material changes

    Our post on vulnerability assessments and penetration tests explains what each one involves and what it costs.

    What is the breach notification requirement?

    Since May 13, 2024, covered businesses must notify the FTC of a “notification event.” That means the unauthorized acquisition of unencrypted customer information involving 500 or more consumers. Report through the FTC’s online form as soon as possible, and no later than 30 days after discovery. The FTC publishes these reports.

    Encrypted data counts as unencrypted if the attacker also obtained the key. State breach laws and the IRS add their own reporting duties.

    What do tax preparers need to know?

    The IRS ties directly into this rule.

    • Each paid preparer confirms a data security plan when renewing a Preparer Tax Identification Number.
    • That plan is a Written Information Security Plan, or WISP.
    • IRS Publication 5708 provides a WISP template built for small firms. Publication 4557 covers safeguarding taxpayer data.
    • Report client data theft to your IRS Stakeholder Liaison right away.

    A WISP built from the IRS template and filled in with your real practices goes a long way toward meeting the Safeguards Rule. A template with only your firm’s name typed at the top does not.

    What are the penalties for non-compliance?

    The FTC can bring an enforcement action that ends in a consent order. Those orders commonly last 20 years and require outside security assessments at your expense. Violating an order brings civil penalties of more than $50,000 per violation. Individuals who run the business can be named. Beyond the FTC, you face state regulators, lawsuits from customers, and the loss of clients who trusted you with their finances.

    How do I comply?

    1. Name your Qualified Individual in writing.
    2. Inventory the customer information you hold: systems, paper files, devices, and vendors.
    3. Perform and document a risk assessment.
    4. Turn on multi-factor authentication for email, tax or lending software, remote access, and cloud storage.
    5. Encrypt laptops, phones, backups, and portable drives.
    6. Limit access by role and remove former employees.
    7. Set a retention schedule and dispose of old records on time.
    8. Review vendor contracts for security terms.
    9. Train your staff, with attention to phishing aimed at tax and finance professionals.
    10. Write your incident response plan.
    11. Test, review, and report to ownership each year.

    Your next step

    Count the consumers in your files, current and former. That number tells you which requirements apply. Then check whether you have a written security program that matches what your office does each day. Cerberus Cybersecurity assesses small businesses against GLBA and the Safeguards Rule and writes the program documents the rule requires. See our services or contact us.

  • PCI DSS Compliance for Small Businesses: A Plain-English Guide

    By J. Mesa

    If your business accepts one credit card payment a year, PCI DSS applies to you. The standard covers the corner cafe and the national retailer alike. Small merchants carry a lighter paperwork load, but the duty to protect card data is the same, and criminals favor small merchants because their defenses tend to be thinner.

    What is PCI DSS?

    PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security requirements for any organization that stores, processes, or transmits payment card data. Visa, Mastercard, American Express, Discover, and JCB founded the PCI Security Standards Council, which writes the standard. The current version is 4.0.1.

    Is PCI DSS a law?

    No. PCI DSS is a contractual obligation. Your merchant agreement with your payment processor or acquiring bank requires you to comply. The card brands enforce it through the banks, and the banks enforce it on you. A few states reference the standard in their laws, but your contract is what binds you.

    Who has to comply?

    Every merchant that accepts payment cards, at any volume, through any channel: in person, online, by phone, or by mail. Service providers that handle card data for merchants must comply as well.

    Using a third-party processor such as Square, Stripe, or Clover reduces your work. It does not remove your responsibility.

    What are the PCI merchant levels?

    The card brands sort merchants by annual transaction volume. Visa’s levels are typical:

    • Level 1: more than 6 million transactions a year. Requires an on-site audit by a Qualified Security Assessor.
    • Level 2: 1 million to 6 million.
    • Level 3: 20,000 to 1 million e-commerce transactions.
    • Level 4: fewer than 20,000 e-commerce transactions, or up to 1 million total.

    Most small businesses sit at Level 4. Level 4 merchants validate compliance with a Self-Assessment Questionnaire each year and, in some cases, quarterly network scans.

    What are the 12 PCI DSS requirements?

    1. Install and maintain network security controls, such as firewalls.
    2. Apply secure configurations to all system components. Change vendor default passwords.
    3. Protect stored account data.
    4. Encrypt cardholder data sent across open, public networks.
    5. Protect all systems and networks from malicious software.
    6. Develop and maintain secure systems and software. Install security patches.
    7. Restrict access to cardholder data to people whose jobs require it.
    8. Identify users and authenticate their access. Use unique IDs and multi-factor authentication.
    9. Restrict physical access to cardholder data.
    10. Log and monitor all access to system components and cardholder data.
    11. Test the security of systems and networks on a regular schedule.
    12. Support information security with organizational policies and programs.

    What is a Self-Assessment Questionnaire, and which one do I need?

    A Self-Assessment Questionnaire, or SAQ, is a form on which you attest to meeting the requirements that apply to your way of taking cards. The right SAQ depends on how card data moves through your business.

    • SAQ A. You outsource all card handling. Customers pay on a page hosted by your payment provider, and no card data touches your systems.
    • SAQ A-EP. Your website does not receive card data, but it controls how customers reach the payment page.
    • SAQ B. You use standalone dial-out terminals or imprint machines, with no electronic storage.
    • SAQ B-IP. You use standalone, approved payment terminals connected over the internet.
    • SAQ C-VT. You key transactions by hand into a web-based virtual terminal on a dedicated computer.
    • SAQ C. Your payment application connects to the internet, with no electronic storage of card data.
    • SAQ P2PE. You use only a validated point-to-point encryption solution.
    • SAQ D. Everything else, including any merchant that stores card data electronically. SAQ D covers every requirement.

    SAQ A asks a few dozen questions. SAQ D asks hundreds. Your processor or bank tells you which form it expects. If you take cards more than one way, you may need to cover each method.

    What card data am I allowed to store?

    The best answer for a small business: none.

    You may store the card number, cardholder name, and expiration date if you have a business need and you protect them, with the card number rendered unreadable. You may never store sensitive authentication data after authorization. That includes:

    • The full contents of the magnetic stripe or chip
    • The three- or four-digit security code
    • The PIN or PIN block

    Look for card data hiding in plain sight: paper order forms, call recordings, spreadsheets, old emails, notes in the customer database, and photos of cards on a phone. Shred the paper and delete the files.

    How do I reduce my PCI scope?

    Scope means the people, processes, and systems that touch card data or connect to systems that do. Smaller scope means fewer requirements and lower risk.

    • Outsource the payment page. Use a hosted checkout or an embedded payment form from your processor, so card data never reaches your website’s server.
    • Use validated P2PE terminals. They encrypt the card at the moment of the swipe, tap, or dip.
    • Stop storing card numbers. Use your processor’s tokenization and card-on-file features for repeat billing.
    • Segment the network. Put payment terminals on their own network, apart from office computers and guest Wi-Fi.
    • Stop taking card numbers by email or text. Send a payment link.

    What changed in PCI DSS version 4?

    Version 3.2.1 retired in March 2024. A group of new requirements in version 4 became mandatory on March 31, 2025. The ones small merchants notice most:

    • Multi-factor authentication for all access into the cardholder data environment, not just for administrators
    • Passwords of at least 12 characters, or 8 where a system cannot support 12
    • Protections against phishing, with training that covers phishing and social engineering
    • For e-commerce: an inventory of the scripts running on payment pages, with authorization for each one and detection of unauthorized changes
    • Authenticated internal vulnerability scans
    • Formal, documented risk analyses for certain decisions

    In early 2025 the Council revised SAQ A. Merchants who use it must confirm that their site is not susceptible to attacks from scripts that could affect the e-commerce system. Ask your web developer and your payment provider how your site meets this.

    Do I need vulnerability scans?

    It depends on your SAQ. Merchants with internet-facing systems in scope need external scans each quarter from an Approved Scanning Vendor, plus scans after significant changes. Under version 4, this now includes e-commerce merchants on SAQ A. SAQ D merchants also need internal scans and penetration tests. Our post on vulnerability assessments and penetration tests explains the difference.

    What happens if I do not comply?

    • Monthly non-compliance fees. Many processors charge $20 to $100 or more a month until you submit your SAQ.
    • Breach costs. After a card data breach, a non-compliant merchant can face a mandatory forensic investigation, card brand assessments, the cost of reissuing cards, and fraud losses passed down through the bank.
    • Higher rates or termination. The bank can raise your fees, require a Level 1 audit, or end your ability to accept cards.

    How do I become PCI compliant?

    1. Map how you take cards: each terminal, website, phone order process, and vendor.
    2. Reduce your scope with the steps above.
    3. Ask your processor which SAQ applies.
    4. Complete the SAQ with honest answers, and fix each “no.”
    5. Run the required scans.
    6. Sign the Attestation of Compliance and submit it to your processor.
    7. Write the security policy that requirement 12 calls for, and train the staff who handle cards.
    8. Repeat each year, and maintain the controls in between.

    What are the common mistakes?

    • Treating the SAQ as a form to click through
    • Writing card numbers on paper or keeping them in a spreadsheet
    • Running the point-of-sale system on the same network as guest Wi-Fi
    • Leaving default passwords on terminals and routers
    • Never inspecting terminals for skimmers or tampering
    • Assuming the processor makes you compliant
    • Forgetting the web developer and hosting company in the scope

    Your next step

    Log in to your processor’s compliance portal and check the date of your last SAQ. If it is overdue, or you do not know which one applies, start with a map of how cards move through your business. Cerberus Cybersecurity measures small businesses against PCI DSS as part of our risk and compliance assessments and writes the policies the standard requires. Contact us to begin.

  • HIPAA Security Rule Basics for Small Practices

    By J. Mesa

    A two-dentist office and a 500-bed hospital answer to the same HIPAA Security Rule. The rule scales to your size, but it does not excuse you for being small. Regulators have fined solo practitioners and small clinics, and the most common finding in those cases is the same: nobody performed a risk analysis. A new year is a good time to check where your practice stands.

    What is the HIPAA Security Rule?

    The HIPAA Security Rule is a federal regulation that sets standards for protecting electronic protected health information, or ePHI. It requires you to keep that information confidential, accurate, and available. The Office for Civil Rights at the Department of Health and Human Services enforces it.

    The Privacy Rule governs who may use and disclose patient information in any form. The Security Rule covers how you protect the electronic version.

    Who has to comply?

    Two groups.

    • Covered entities. Health plans, clearinghouses, and health care providers who send information electronically for standard transactions, such as billing insurance. That includes medical and dental practices, chiropractors, optometrists, therapists, pharmacies, and clinics.
    • Business associates. Companies that handle ePHI on behalf of a covered entity: billing services, IT providers, cloud hosting and backup vendors, transcription services, shredding companies, and consultants.

    What is ePHI?

    ePHI is health information that identifies a patient and that you create, store, or send in electronic form. Examples:

    • Electronic health records and practice management data
    • Digital X-rays and images
    • Appointment schedules that list names and reasons for visits
    • Billing and insurance records
    • Emails and text messages about patients
    • Voicemail recordings stored on a phone system
    • Scanned intake forms on a copier’s hard drive

    What does the Security Rule require?

    The rule groups its requirements into three sets of safeguards.

    Administrative safeguards cover how you manage security:

    • Perform a risk analysis and manage the risks you find
    • Name a security official
    • Control who gets access to ePHI and remove access when people leave
    • Train the workforce
    • Plan for incidents and report them
    • Keep a contingency plan: backups, disaster recovery, and emergency operations
    • Sign business associate agreements

    Physical safeguards cover buildings and equipment:

    • Limit physical access to servers and workstations
    • Position screens away from public view and lock unattended computers
    • Track, wipe, and dispose of devices and media that hold ePHI

    Technical safeguards cover the technology:

    • Give each user a unique login
    • Log off idle sessions
    • Encrypt ePHI where reasonable
    • Record and review system activity
    • Protect data from improper changes
    • Verify the identity of users
    • Protect data sent over networks

    What is a HIPAA risk analysis?

    A risk analysis is a documented review of where your ePHI lives, what could go wrong with it, how likely each problem is, and how much damage it would cause. Follow these steps:

    1. List every system, device, and vendor that stores or touches ePHI.
    2. Identify the threats to each: theft, ransomware, employee error, fire, flood, vendor failure.
    3. Record the protections you already have.
    4. Rate the likelihood and the impact of each threat.
    5. Rank the risks.
    6. Write a plan to reduce the high ones, with owners and dates.

    Update the analysis each year and after major changes, such as a new records system, a move, or a new office. The Department of Health and Human Services offers a free Security Risk Assessment Tool for small practices.

    A vulnerability scan is not a risk analysis. A checklist from your records vendor is not a risk analysis. Regulators ask for the document described above, and they ask for it first.

    What do “required” and “addressable” mean?

    The rule labels each specification as required or addressable. Required means you must implement it. Addressable does not mean optional. For an addressable item, you assess whether it is reasonable for your practice. Then you implement it, implement an equivalent alternative, or document why neither is reasonable.

    Encryption is addressable. In practice, a laptop with unencrypted patient data is a reportable breach the moment it gets stolen. Encrypt the laptops, the phones, and the backups.

    Do I need a business associate agreement?

    Yes, with each vendor that creates, receives, stores, or transmits ePHI for you. The agreement binds the vendor to protect the data and to report breaches to you. Common vendors that need one:

    • Your IT company
    • Cloud backup and file storage providers
    • Email and messaging providers
    • Billing and collections services
    • Your records software vendor
    • Answering services and appointment reminder services

    A free email account or a consumer file-sharing plan comes with no agreement. Use the business versions that offer one, and sign it before you send patient data.

    What training does HIPAA require?

    You must train every workforce member on security, including owners, clinicians, front desk staff, and part-time employees. Train new hires at the start, repeat the training each year, and send reminders between sessions. Cover phishing, passwords, device handling, and how to report an incident. Keep attendance records. Our cybersecurity training covers these topics for health care teams.

    What are the most common HIPAA security mistakes in small practices?

    • No risk analysis, or one from years ago
    • Shared logins at the front desk
    • No multi-factor authentication on email and remote access
    • Unencrypted laptops and phones
    • Texting patient details from personal phones
    • No signed business associate agreements
    • Former employees with active accounts
    • Unsupported operating systems on imaging and front desk computers
    • Backups that nobody tested
    • No written policies, or policies downloaded once and never read
    • Old computers and copiers discarded with patient data on the drives

    What happens after a breach?

    The Breach Notification Rule sets the duties.

    • Notify each affected patient without unreasonable delay, and no later than 60 days after you discover the breach.
    • For a breach affecting 500 or more people, notify the Department of Health and Human Services within the same 60 days. When the breach affects more than 500 residents of one state, notify prominent media outlets in that state as well.
    • For a breach affecting fewer than 500 people, log it and report it to the Department within 60 days after the end of the calendar year.

    A ransomware attack on systems that hold ePHI counts as a breach unless you can show a low probability that the data was compromised. State laws may add shorter deadlines. Follow your incident response plan and call an attorney early.

    What are the penalties?

    Civil penalties rise with the level of fault, from cases in which the practice did not know about a violation up to willful neglect left uncorrected. The amounts range from about a hundred dollars to tens of thousands of dollars per violation, with annual caps that adjust for inflation. Settlements usually add a corrective action plan with years of government monitoring. State attorneys general can bring their own cases.

    The Office for Civil Rights runs an enforcement initiative focused on risk analysis, and it has settled with small practices under that initiative.

    How do I get started?

    1. Name your security official in writing.
    2. Complete a risk analysis.
    3. Fix the highest risks first: multi-factor authentication, encryption, backups, and patching.
    4. Write or update your policies and procedures.
    5. Collect signed business associate agreements.
    6. Train the staff and record it.
    7. Write an incident response and breach notification procedure.
    8. Keep all documentation for six years.
    9. Review the program each year.

    Your next step

    Find your last risk analysis and read the date on it. If it is more than a year old, or you can’t find one, start there. Cerberus Cybersecurity performs HIPAA risk assessments, writes the required policies, and trains health care staff. See our services or contact us.

  • How to Secure Your Home or Office Router and Wi-Fi

    By J. Mesa

    New laptops, smart speakers, cameras, and game consoles will join your network this month. Each one connects through the same small box: the router. Most people plug it in once and never look at it again. Attackers look at it often. Twenty minutes of setup closes the gaps they use.

    Why does router security matter?

    Your router sits between the internet and every device you own. A criminal who controls it can watch your traffic, send you to fake websites, attack the devices behind it, or rent your connection to other criminals who want to hide their location.

    The FBI warned in 2025 that criminals target older routers that no longer receive updates and install malware that turns them into proxies for hire. The owners saw nothing wrong. Their internet kept working while strangers committed crimes through their address.

    How do I log in to my router?

    Use one of two methods.

    • The app. Most routers sold in the last several years come with a phone app from the maker or from your internet provider.
    • The web page. Connect to your network, open a browser, and type the router’s address. Common addresses are 192.168.0.1 and 192.168.1.1. The label on the router lists the address and the default login.

    What settings should I change first?

    Work through this list in order.

    1. Change the administrator password. This is the password for the router’s settings, separate from the Wi-Fi password. Default admin passwords appear in public lists. Create a long, unique one and save it in your password manager.
    2. Update the firmware. Firmware is the router’s built-in software. Find the update option in the app or the settings page and install what it offers.
    3. Turn on automatic updates if the router supports them.
    4. Set the Wi-Fi security to WPA3. If some of your devices can’t connect, choose the WPA2/WPA3 mixed mode. Never use WEP or an open network.
    5. Set a strong Wi-Fi password. Use at least 16 characters. A phrase of four random words works.
    6. Turn off WPS. Wi-Fi Protected Setup lets devices join with a button or a PIN, and the PIN method has a known weakness.
    7. Turn off remote management. Nobody needs to reach your router’s settings from the internet.
    8. Turn off UPnP unless a specific device requires it. Universal Plug and Play lets devices open ports to the internet without asking you.
    9. Rename the network. Remove the router brand and your family or business name from the network name. Do not put your address or unit number in it.

    What is WPA3, and do I need it?

    WPA3 is the current standard for Wi-Fi encryption. It replaced WPA2 and resists the password-guessing attacks that work against WPA2 networks with weak passwords. Devices made since about 2020 support it. Use WPA3 where you can, and use WPA2 with a long password where you can’t.

    Should I hide my network name?

    No. Hiding the name does not stop an attacker, because free tools reveal hidden networks in seconds. It also makes your own devices broadcast the name wherever they go while they search for it. Leave the name visible and rely on strong encryption and a strong password.

    How do I update router firmware?

    Open the app or the settings page and look for “Firmware,” “Software update,” or “Router update.” Install the update and let the router restart. Check again every few months if the router lacks automatic updates.

    If your internet provider supplied the router, the provider usually pushes updates. Restarting the router once a month helps it pick them up and clears some kinds of malware that live only in memory.

    When should I replace my router?

    Replace it when the maker stops releasing security updates. Search the model number plus “end of life” on the maker’s support site. As a rule of thumb, a router older than five or six years has reached that point or soon will.

    An unsupported router keeps its known flaws for the rest of its life. No setting fixes that. A new router costs $80 to $250 and brings WPA3, automatic updates, and better speed.

    What is a guest network, and why should I use one?

    A guest network is a second Wi-Fi network that reaches the internet but can’t reach the devices on your main network. Use it for:

    • Visitors and customers
    • Smart TVs, speakers, cameras, doorbells, thermostats, and other smart home devices
    • Children’s game consoles and tablets

    Smart devices receive few updates and get hacked often. On the guest network, a hacked camera can’t reach the laptop that holds your tax returns or your customer files. Give the guest network its own password, and change that password a few times a year.

    How do I secure an office network?

    A business needs more than a consumer router from a big-box store.

    • Buy business-grade equipment. A firewall or router built for business use receives longer support and offers logging and network separation.
    • Separate the networks. Keep staff computers, guest Wi-Fi, payment terminals, cameras, and phones on separate segments. PCI DSS requires you to isolate the systems that handle card data.
    • Lock up the hardware. Put the router and switches in a locked room or cabinet. A visitor with thirty seconds and a paperclip can reset a router that sits on the front counter.
    • Change every default. That includes the admin passwords on cameras, printers, and network storage devices.
    • Stop sharing one Wi-Fi password forever. Change it when an employee leaves, or use a system that gives each person a login.
    • Record the setup. Document the model, firmware version, admin account, and settings. Export a backup of the configuration.
    • Review the logs or have your IT provider do so.

    What about employees who work from home?

    A home router is part of your business network the moment an employee opens company email on it. Set expectations in a remote work policy:

    • Change the default admin password and use WPA2 or WPA3.
    • Keep the router’s firmware current and replace unsupported models.
    • Put work devices on the main network and smart home devices on the guest network.
    • Use the company VPN or secure access tool where you require it.

    Share this article with remote staff and add the topic to your training.

    Do I need a VPN on my home Wi-Fi?

    For most people, no. Websites and apps already encrypt their traffic, and your own secured network is a trusted place. A VPN makes sense for reaching company systems that require one and for using public Wi-Fi in airports, hotels, and coffee shops.

    How can I tell whether my router has been hacked?

    Look for these signs:

    • Settings you did not change, such as a new admin password or different DNS servers
    • Websites that redirect to strange pages, or security warnings on sites you trust
    • Unknown devices in the router’s list of connected devices
    • A connection that slows down for no clear reason
    • Remote management turned on when you turned it off

    If you suspect a problem:

    1. Reset the router to factory settings with the button on the back.
    2. Update the firmware before you do anything else.
    3. Set a new admin password and a new Wi-Fi password.
    4. Walk through the settings list above again.
    5. Change the passwords for your email and banking accounts from a device you trust.
    6. Replace the router if the maker no longer supports it.

    How often should I check my router?

    Twice a year. Tie it to the clock changes or to the start of each school term. Confirm the firmware is current, review the list of connected devices, and remove anything you do not recognize.

    Your next step

    Find the label on your router tonight, log in, and change the admin password. Then check for a firmware update. For an office network, Cerberus Cybersecurity reviews network setup, segmentation, and remote work practices as part of our risk and compliance assessments. Contact us to schedule one for the new year.