AccuSights
PartnersBlogAbout
Book my 30-minute demo

Boston, Massachusetts · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

Boston wrote the first state security rule. We make sure yours is more than paper.

A 14-person CPA firm on Moody Street in Waltham with 1,100 returns open in March, a dental practice in Newton, a Route 128 supplier with CUI on a shared drive. You built it on the Pike and the Red Line. Someone in another time zone has your firm's name and a phone. We watch the other side of that, around the clock.

Chicago-based, serving Greater BostonEngineer on site for practicesPublic pricingStaff training included

Serving the Financial District and Seaport, Back Bay, Longwood Medical Area, Kendall Square and Cambridge, Waltham and Route 128, Newton and Wellesley, Burlington and Bedford and Quincy and the South Shore. Remote first, on site when it matters.

A Boston story

The Tuesday in March a CPA firm nearly installed the caller's software

the managing partner of a 14-person CPA firm on Moody Street in Waltham

It is Tuesday, March 10, and the firm on Moody Street has 1,100 returns open. The managing partner has run it for twenty-two years. Every client's Social Security number, W-2, brokerage statement and bank account lives on the tax server, and every one of them is due somewhere by April 15.

At 9:15 a senior associate takes a call from the tax software's support line. The caller has her name, the firm's EIN and the exact error code from a rejection she filed at 8:50. He is calm and helpful. There is a fix, he says, a small support tool, and he sends the link while she is still on the phone. It downloads in four seconds.

Her finger is on Run.

The tool never starts. She presses the report button while the caller is still talking, and an engineer calls her back in four minutes with the name of the campaign that has been hitting preparers all season. The number gets blocked. The firm files 1,100 returns on time, and the written information security program Massachusetts requires gets a new paragraph about a Tuesday in March.

The application allow-list on her machine refuses to run a program it has never seen, no matter how pleasant the voice on the phone.

What changes the ending

  1. Application control on every workstation, so a "support tool" from a phone call cannot run, however convincing the caller (CIS 2 Inventory and Control of Software Assets).
  2. Client data on an encrypted server behind MFA and access by name, which is also what 201 CMR 17.00 expects a WISP to say (CIS 3 Data Protection).
  3. Training that covers the phone call and the text, not just the inbox, scored per person, every March (CIS 14 Security Awareness and Skills Training).

What price are you willing to pay to let twenty-two years of building in this city go away because someone overseas tricked one person on your team into clicking a link, or taking a call? Massachusetts will ask whether you had a written program. We would rather you take the vacation you earned and land at Logan to find payroll still there and every return filed.

Sam Khan, founder. The Cyber Expert in times of peace.

Massachusetts, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$410.7M
lost to internet crime by Massachusetts victims in 2025, across 22,934 complaints, up from $338.9 million the year before
Source: FBI IC3 2025 Annual Report, Massachusetts state page; FBI Boston, 2026 and 2025
$120.3M
of that was business email compromise, the changed invoice and the changed wire, across 593 Massachusetts complaints
Source: FBI IC3 2025 Annual Report, Massachusetts state page, 2026
31%
of professional services breaches, law, accounting and consulting, involved stolen credentials
Source: Verizon 2026 Data Breach Investigations Report

The law and its clock

Massachusetts data security law (M.G.L. c. 93H) and 201 CMR 17.00

Every business that owns or licenses personal information of a Massachusetts resident must keep a written information security program (WISP). Notify the Attorney General, the Director of OCABR and affected residents as soon as practicable and without unreasonable delay, with no minimum count. Notice cannot wait for the final tally, must say whether a WISP exists, and must include 18 months of credit monitoring when Social Security numbers are involved.

Regulator: Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

The City of Lowell suffered a ransomware attack that took municipal network, server and phone systems offline for weeks; the Play group released 5 GB of city data.

April 2023 · The Lowell Sun

Anna Jaques Hospital in Newburyport was hit by ransomware on Christmas Day, taking the electronic health record offline and diverting ambulances; it later notified 316,342 patients.

December 2023 · BleepingComputer

Harvard University confirmed it was investigating a breach tied to an Oracle E-Business Suite zero-day exploited by the Clop group, which listed Harvard and leaked about 1.3 TB.

October 2025 · BleepingComputer

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Boston

Same controls, told from where it hurts for your business.

Medical and dental practices

What if the Newton office manager's inbox is the one that pays the vendors and holds the patient schedule?

Every workstation and the practice server watched around the clock, offline backups that restore charts in hours, MFA on every login, the WISP written and kept current, and a HIPAA risk analysis your license can stand on.

Education and health services is the largest sector in Greater Boston at 620,600 jobs (BLS, July 2026); Massachusetts has 34,134 active physicians and 5,583 active dentists (KFF).

CPA and bookkeeping firms

What if the caller has our EIN, the client's name and the error code, and the fix is one click?

Application control so nothing unapproved runs, client data encrypted behind MFA and access by name, a data-loss policy on returns and statements, the FTC Safeguards Rule written plan, and training that covers the phone call in March.

Professional services breaches involved stolen credentials 31% of the time (Verizon 2026 DBIR), and 201 CMR 17.00 requires every firm holding a resident's Social Security number to have a written program.

Biotech, software and life sciences

What if the pharma partner wants SOC 2 and the HIPAA controls, and our evidence is a folder of screenshots?

One control set mapped to SOC 2, HIPAA and the partner questionnaire, evidence collected continuously by the agent, and a named engineer who answers the question about detecting intrusions with a log.

Kendall Square, the Seaport and the Route 128 and 495 belt hold a life sciences base that sells to partners who ask for proof before they sign.

Defense suppliers along Route 128

What if the prime in Waltham asks for our NIST 800-171 score on Friday and we do not have one?

CUI in one controlled enclave, the 110 NIST SP 800-171 practices assessed and scored, a System Security Plan you can hand over, and an engineer watching logins so the prime hears about an attempt from you.

Hanscom Air Force Base in Bedford is one of the most contractor-dense bases in the country, and the primes in Waltham, Andover, Tewksbury, Burlington and Wilmington run supplier chains through the 128 and 495 belt.

RIAs, family offices and asset managers

What if the custodian's questionnaire asks how we detect an intrusion and the honest answer is that we do not?

The questionnaire answered from evidence the agent collects, client data encrypted behind access by name, MFA everywhere, and a written program that satisfies the FTC Safeguards Rule and 201 CMR 17.00 at once.

Financial activities employ 177,500 people in Greater Boston (BLS, July 2026), and business email compromise cost Massachusetts $120.3 million in 2025 (FBI IC3).

Medical, dental and other healthcare practices

In Boston an AccuSights cybersecurity engineer comes to the practice, from Longwood to Newton and out along Route 128, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: Hanscom Air Force Base, MIT Lincoln Laboratory, the Army's Soldier Center in Natick and the primes in Waltham, Andover and Burlington make the 128 and 495 belt one of the densest defense supplier corridors in the country. The July 2026 pause of the C3PAO mandate is not a pardon: NIST SP 800-171 stays in the contract, and we score you against its 110 practices before the prime asks.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your Waltham associates and your Longwood front desk get the same short, scored training every month, built around what we see in Boston inboxes and on Boston phones that month, including the support-line calls that hit preparers every March. Phishing tests teach one habit above all: press the report button, and an engineer sees it. No per-module charges and no shaming for a click.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a Boston business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions Boston owners ask

What people in Boston search for, answered straight.

What is a WISP and does my Massachusetts business need one?
A written information security program is required by 201 CMR 17.00 for any business that holds personal information of a Massachusetts resident: a name plus a Social Security, license, bank or card number. That covers every practice, firm and shop with a payroll. Ours is written from the assessment, so it describes controls that exist, which is what the Attorney General checks after a breach.
What does Massachusetts require after a data breach?
Notice to the Attorney General, to OCABR and to affected residents as soon as practicable and without unreasonable delay, with no minimum number of residents. The notice must say whether you had a WISP, and if Social Security numbers were involved you owe 18 months of credit monitoring. HIPAA adds its own 60-day clock for patient data.
How much does HIPAA compliance cost for a Boston practice?
Our pricing is public: the risk analysis and the on-site setup are a fixed fee, and protection is priced per employee. A 30-minute demo scopes it for your practice, from Longwood to Newton, and the engineer who does the visit is the one you talk to afterward.
We supply a prime near Hanscom. What CMMC level do we need?
If you handle controlled unclassified information you are a Level 2 supplier, and NIST SP 800-171 has been in your contract since 2017. The July 2026 pause of the C3PAO mandate does not change that. We assess the 110 practices, score you, write the System Security Plan and fix the gaps before the prime asks.
How much does SOC 2 readiness cost for a Kendall Square biotech or software company?
The auditor's fee is separate from the readiness work, and the readiness work is where the time goes. Our pricing is public, per employee for protection and a fixed fee for the assessment. A 30-minute demo scopes it, and the same agent that protects you collects the evidence the auditor wants.
What does a cybersecurity company in Boston do for a 15-person firm?
An assessment that finds where the money and the records live and the ten fixes that matter first. Compliance kept current: the WISP, HIPAA, CMMC or SOC 2. And 24/7 protection: an agent on every device and a named engineer watching it, so the caller with your EIN meets a control instead of a click.

Sources: FBI IC3 2025 Annual Report, Massachusetts · FBI Boston, 2024 Internet Crime Report release · M.G.L. c. 93H · 201 CMR 17.00 · Mass.gov data breach reporting · BLS, Boston-Cambridge-Newton Economy at a Glance · KFF, professionally active physicians · KFF, professionally active dentists · The Lowell Sun, City of Lowell · BleepingComputer, Anna Jaques Hospital · BleepingComputer, Harvard · Hanscom Air Force Base · FBI Boston Field Office · CISA Region 1 · Verizon 2026 DBIR

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our Boston practice replies within one business day.

3-min test