AccuSights
PartnersBlogAbout
Book my 30-minute demo

Minneapolis, Minnesota · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

Minneapolis shows up in January. We watch your business through the nights you cannot.

A clinic in Maple Grove, a nonprofit in the North Loop, a contract manufacturer off 494 in Eden Prairie with a BAE drawing on the server: the Twin Cities run on businesses that keep going at fourteen below. We keep them going at 3 a.m. too, with an engineer who answers, so the week at the cabin up north is a real week off.

Chicago-based, serving the Twin CitiesEngineer on site for practicesPublic pricingStaff training included

Serving the North Loop, Downtown Minneapolis, Saint Paul, Bloomington, Edina, Eden Prairie, Plymouth and Maple Grove. Remote first, on site when it matters.

A Minneapolis story

The Tuesday the donor list almost went out by text

the executive director of a 12-person nonprofit in the North Loop

It is a Tuesday in January, fourteen below at the bus stop, and the executive director of a North Loop nonprofit is at a funder's office in Saint Paul with her phone on silent. Back at the office the development director is finishing the year-end donor file: 4,800 names, home addresses, giving history, and the card numbers from the gala that never got deleted. It lives in a spreadsheet.

At 10:52 a text arrives on the development director's phone. It uses the executive director's name and reads the way she writes: in the funder meeting, need the full donor list for the board packet, send as attachment, thanks so much. There is a heart at the end, which she does sometimes.

The development director is loyal, quick and proud of the file. She attaches the spreadsheet to a reply. Downtown, the skyways are full of people who have not been outside since Sunday, and nobody is watching her screen.

Her thumb is on send when she notices the message came from a number, not from the name in her contacts, and she walks two blocks of skyway to the funder's office to ask in person.

What changes the ending

  1. Donor data kept in the donor system, with card numbers never stored and exports limited and logged, so the file cannot leave in a text reply (CIS 3 Data Protection)
  2. Training that covers the phone as well as the inbox, because the 2026 DBIR found mobile lures get clicked 40% more often than email, and a report button that works from a phone (CIS 14 Security Awareness and Skills Training)
  3. Multi-factor authentication and named roles on email and the donor system, so even a stolen password does not open the list (CIS 6 Access Control Management)

What price are you willing to pay to let ten years of building go away because someone overseas tricked one person on your team into clicking a link? For a nonprofit it is the donors' trust; for a clinic it is the license. We would rather you take the week at the cabin you earned, and drive back down 35 on Sunday to find payroll still there.

Sam Khan, founder. The Cyber Expert in times of peace.

Minnesota, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$248.9M
lost by Minnesota victims across 13,593 complaints to the FBI in one year
Source: FBI IC3 2025 Annual Report, Minnesota state page (2026)
$203M
in Minnesota cybercrime losses reported to the FBI in 2024, up from about $39 million in 2019
Source: Minnesota House committee document citing FBI IC3 figures (2025)
$36.9M
lost to business email compromise in Minnesota across 376 complaints, the fraud that reroutes payroll, wires and donor files
Source: FBI IC3 2025 Annual Report, Minnesota state page (2026)

The law and its clock

Minnesota data breach notification law (Minn. Stat. 325E.61)

Notify affected Minnesota residents in the most expedient time possible and without unreasonable delay. If more than 500 people are affected, notify all nationwide consumer reporting agencies within 48 hours. The statute has no Attorney General notice requirement; the Attorney General enforces it.

Regulator: Minnesota Attorney General · source

Minnesota Consumer Data Privacy Act (MCDPA)

In force since July 31, 2025. The 30-day cure period expired January 31, 2026, so the Attorney General can now sue without prior notice. Civil penalties reach $7,500 per violation.

Regulator: Minnesota Attorney General · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

Minneapolis Public Schools declined to pay a $1 million ransomware demand; stolen student and staff records were published and the district later notified more than 100,000 people.

March 2023 · The Record

The University of Minnesota disclosed a breach in which a hacker claimed access to about 7 million Social Security numbers from records dating to 1989; class actions followed.

August 2023 · MPR News

The City of Saint Paul shut down many digital services after a cyberattack; the Governor activated the Minnesota National Guard's cyber team and a ransomware group claimed responsibility; the city refused to pay.

July 2025 · BleepingComputer

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Minneapolis

Same controls, told from where it hurts for your business.

Clinics, dental and specialty practices

Minnesota's Health Records Act is stricter than HIPAA on consent. If a chart leaks from my Edina clinic, which law am I answering to first?

The practice server and each workstation watched around the clock, backups that restore, and a HIPAA risk analysis done on site that accounts for Minnesota's own rules.

Education and health services is the metro's largest sector at 398,700 jobs and growing 3.6% a year (BLS, July 2026), with Medical Alley and a large base of independent clinics; Minnesota has 3,404 active dentists (KFF, 2024).

Nonprofits and foundations

Our donor list is a spreadsheet that three people email around. What happens when one of those three gets a convincing text?

Donor data kept in one controlled system with exports logged, multi-factor authentication on email, and staff trained on the phone lures as well as the inbox.

Minnesota businesses and organizations lost $36.9 million to business email compromise in 2025 (FBI IC3, 2026), and the 2026 DBIR found mobile lures are clicked 40% more often than email.

Manufacturers and defense subcontractors

We machine parts for BAE in Fridley and Polaris in Medina. Which one asks for CMMC first, and what happens when we say we do not have it?

CUI in one controlled place, an honest NIST 800-171 score, a system security plan, and the plant network separated from the office and watched around the clock.

Manufacturing employs 203,000 people in the metro and grew 2.4% in a year (BLS, July 2026); BAE Systems in Fridley, Honeywell Aerospace, Polaris Defense and General Dynamics OTS in Anoka anchor the defense supplier base (research desk, 2026).

Financial firms and advisors

A client says we emailed them new wiring instructions. We did not. What happened?

Mailboxes with multi-factor authentication, lookalike-domain filtering, callback rules for any payment change, and monitoring that catches a login from the wrong continent.

The metro holds 141,500 financial activities jobs around U.S. Bank, Ameriprise, Thrivent and Securian (BLS, July 2026), and the 2026 DBIR counted 3,809 incidents in financial services, the most of any sector.

Law firms

If a wire leaves our trust account on a forged instruction, is that our malpractice carrier's problem or mine?

Partner mailboxes with multi-factor authentication, lookalike-domain filtering, and a wire-verification rule trained into the bookkeeper and paralegals before the settlement lands.

Professional and business services employ 291,000 people in the metro (BLS, July 2026), and the 2026 DBIR counted 2,558 confirmed breaches in professional services, with credentials stolen in 31% of them.

Medical, dental and other healthcare practices

In Minneapolis an AccuSights cybersecurity engineer comes to the practice, from Edina to Maple Grove, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: BAE Systems in Fridley, Honeywell Aerospace in Plymouth and Golden Valley, Polaris Defense in Medina and General Dynamics OTS in Anoka buy from contract manufacturers across the 494 corridor and the northern suburbs. We get a shop to a true NIST 800-171 score and a system security plan, and keep the controls running, because the DoD paused the assessment mandate in July 2026 but the primes did not pause their questionnaires.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your development team in the North Loop and your front desk in Woodbury get the same short monthly training, built around the lures hitting Minnesota inboxes and phones this month, and each person is scored so you know who needs a hand. The report button sits in the mail client and on the phone; one press protects the whole organization. We do not charge per module or per test.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a Minneapolis business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions Minneapolis owners ask

What people in Minneapolis search for, answered straight.

How much does a cybersecurity assessment cost in Minneapolis?
Our pricing is public on the site, and a 30-minute demo scopes it to your clinic, nonprofit or shop. The Cyber and Data Protection Assessment is priced by size and by the rules that apply to you, HIPAA, CMMC, the MCDPA or none. You get a scored report and the ten fixes that matter first.
What does Minnesota law require after a data breach?
Minn. Stat. 325E.61 requires notice to affected residents in the most expedient time possible and without unreasonable delay. If more than 500 people are affected, the nationwide consumer reporting agencies must be told within 48 hours. There is no Attorney General filing in the statute, but the Attorney General enforces it, and HIPAA adds its own clock for practices.
Does the Minnesota Consumer Data Privacy Act apply to my small business?
It applies to businesses that control or process the personal data of 100,000 or more Minnesota consumers, or 25,000 with more than a quarter of revenue from selling data, and small businesses as defined by the SBA are largely exempt except for selling sensitive data without consent. The cure period ended January 31, 2026, so enforcement no longer comes with a warning. We tell you plainly which side of the line you are on.
We machine parts for BAE in Fridley or a Medical Alley device maker. Do we need CMMC?
If drawings or specifications marked CUI reach your shop, your DoD contract already requires NIST 800-171 and a score posted in SPRS. The DoD paused the third-party assessment mandate in July 2026, but the primes did not pause their questionnaires. Device makers ask for similar evidence under FDA cybersecurity expectations.
Do you come on site for a dental practice in Edina or Maple Grove?
Yes. An engineer comes to the office, from Bloomington to Woodbury, sets up the critical controls and the protection agent on each workstation and the server, and trains the staff the same week. The HIPAA risk analysis is done there, so it reflects the practice as it runs.
What should a nonprofit do about its donor list?
Keep it in the donor system rather than a spreadsheet, never store card numbers, log and limit exports, and put multi-factor authentication on email. Then train staff on the text-message version of the con, because that is where it now arrives. Minneapolis Public Schools refused a $1 million ransom in 2023 and still had 100,000 people to notify.

Sources: FBI IC3 2025, Minnesota · Minnesota House committee document on IC3 losses · Minn. Stat. 325E.61 · Minnesota AG on the MCDPA · BLS Minneapolis economy at a glance · KFF active dentists · Verizon 2026 DBIR · The Record on Minneapolis Public Schools · MPR News on the University of Minnesota breach · BleepingComputer on the Saint Paul attack · FBI Minneapolis · CISA Region 5

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our Minneapolis practice replies within one business day.

3-min test