AccuSights
PartnersBlogAbout
Book my 30-minute demo

San Diego, California · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

San Diego supplies the fleet. We keep your shop cleared for the next purchase order.

The ships are visible from the Embarcadero and the primes are in Poway, Rancho Bernardo and Kearny Mesa, which means thousands of small shops from Miramar Road to Otay Mesa hold drawings marked CUI. Add the clinics of North County and the biotech of Sorrento Valley, and this is a county where the customer asks about security before the contract. We make the answer true and watch it around the clock.

Chicago-based, serving San Diego CountyEngineer on site for practicesPublic pricingStaff training included

Serving Sorrento Valley, Kearny Mesa, Rancho Bernardo, Poway, Carlsbad, Oceanside, Escondido and Chula Vista. Remote first, on site when it matters.

A San Diego story

The Tuesday the SPRS score turned out to be a guess

the owner of a 28-person machine shop on Miramar Road that supplies a Poway prime

It is a Tuesday in May, marine layer still hanging over Miramar Road at noon, and the owner of a 28-person machine shop is reading an email from his biggest customer's supplier-quality manager. Send us your current NIST 800-171 score and your system security plan by Friday, it says, or the next purchase order goes to a shop that can. The prime is in Poway. The parts are for a Navy program.

The owner entered a score two years ago, from memory, on a Sunday. He starts walking the shop to see how true it was. The drawings marked CUI sit on a shared drive that the front office, the floor and the old cloud-sync account can all reach. The CAM workstation has not been updated since it was installed.

Then he talks to his estimator, a good man who has quoted jobs for him for nine years. The estimator explains, without a trace of guilt, that he has been emailing the drawings to his personal account for two years so he can quote from home in Escondido.

The owner opens that personal account with him and finds it was signed into last month from a city neither of them can find on a map.

What changes the ending

  1. CUI kept in one controlled place, marked, with sync accounts and personal email cut off from it, so a drawing cannot wander home (CIS 3 Data Protection)
  2. Access by role, multi-factor authentication on the shared drive and the remote tools, and a quarterly review of who can reach the Navy work (CIS 6 Access Control Management)
  3. Quoting from home solved the right way, with a company laptop and a secure connection, and staff trained on why the marking on the drawing decides the shop's next PO (CIS 14 Security Awareness and Skills Training)

What price are you willing to pay to let ten years of building go away because someone overseas tricked one person on your team into clicking a link? For a shop that supplies the fleet, the price includes the contract, not just the data. We would rather you take the week in Baja you earned, and come back over the Coronado bridge to find payroll still there.

Sam Khan, founder. The Cyber Expert in times of peace.

California, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$3,674.6M
lost by California victims across 116,423 complaints to the FBI in one year, the most of any state
Source: FBI IC3 2025 Annual Report, California state page (2026)
$61.3B
of San Diego's economy tied to the military, 22.2% of gross regional product and nearly 357,000 jobs
Source: San Diego Military Advisory Council, 2025 Military Economic Impact Report
61%
of manufacturing breaches involve a third party, the highest of any major sector, and a supplier is somebody's third party
Source: Verizon 2026 Data Breach Investigations Report

The law and its clock

California data breach notification law (Cal. Civ. Code 1798.82, as amended by SB 446)

Since January 2026, notify affected residents within 30 calendar days of discovery. Where more than 500 residents are notified, send the Attorney General a copy within 15 days after the resident notice.

Regulator: California Attorney General · source

California Consumer Privacy Act, as amended by the CPRA

New California Privacy Protection Agency regulations took effect January 2026: risk assessments begin in 2026 with attestations due April 2028, cybersecurity audit certifications phase in by revenue tier from 2028, and automated decision-making rules phase in.

Regulator: California Privacy Protection Agency and the Attorney General · source

Confidentiality of Medical Information Act (Cal. Civ. Code 56 et seq.)

California's own medical privacy statute sits on top of HIPAA for providers, with its own penalties and a private right of action for patients.

Regulator: California Attorney General and private lawsuits · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

A cyberattack on Tri-City Medical Center in Oceanside, a public hospital district, forced the hospital to declare an internal disaster and divert ambulances for days.

November 2023 · KPBS

Palomar Health Medical Group in Escondido detected unauthorized network access; notices went to patients of three affiliated groups and a $3.1 million class settlement followed.

April 2024 · California Attorney General breach report

Sharp HealthCare notified 62,777 patients after attackers reached a web server used for online bill payment.

February 2023 · The San Diego Union-Tribune

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in San Diego

Same controls, told from where it hurts for your business.

Medical and dental practices

Tri-City diverted ambulances for days. My North County practice does not have a disaster plan for a Tuesday. Should it?

The practice server and each workstation watched around the clock, backups that restore, and a HIPAA risk analysis done on site that also covers California's own medical privacy law.

Education and health services is the county's fastest-growing large sector at 284,300 jobs, up 5.1% in a year (BLS, July 2026), with a heavy independent practice base in North County.

Defense suppliers

General Atomics, Northrop and NASSCO all want a score in SPRS. Which CMMC level does a 20-person shop actually need?

An honest NIST 800-171 score, a system security plan and the controls kept running between assessments, so the next PO is not the one you lose.

The military supports nearly 357,000 local jobs and $61.3 billion in economic activity, 22.2% of the region's economy (SDMAC, 2025), and the primes in Poway, Rancho Bernardo and Barrio Logan buy from hundreds of small shops.

Machine shops and manufacturers

Our estimator quotes from home. Our CAM machine has never been patched. Which one gets us dropped by the prime first?

CUI in one controlled place, the plant network separated from the office, internet-facing systems patched, and an engineer watching around the clock.

Manufacturing employs 110,200 people in the county (BLS, July 2026), and the 2026 DBIR found 61% of manufacturing breaches involve a third party.

Software, biotech and technology firms

Our first enterprise customer sent a 200-question security questionnaire. Do we need SOC 2 to close?

The controls SOC 2 expects, in place and producing evidence, so the questionnaire is answered from a console and the audit, when you choose to do it, is a formality.

Professional and business services employ 263,500 people in the county (BLS, July 2026), across Sorrento Valley, UTC and Carlsbad, and the 2026 DBIR found 48% of breaches involve a third party.

Hotels, restaurants and tourism

Our reservation system and our card terminals share a network with the front-desk PC that reads email. Is that a problem?

Card terminals on their own network, vendor remote access locked down and logged, and monitoring that catches a foreign login before the processor calls you.

Tourism and hospitality is one of the county's core sectors (research desk, 2026), and the 2026 DBIR found 68% of retail breaches involve a third party such as a payment or point-of-sale vendor.

Medical, dental and other healthcare practices

In San Diego an AccuSights cybersecurity engineer comes to the practice, from Carlsbad to Chula Vista, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: Naval Base San Diego, North Island, Point Loma, Miramar and Camp Pendleton, with General Atomics in Poway, Northrop Grumman in Rancho Bernardo, NASSCO and BAE Systems Ship Repair in Barrio Logan and Cubic in Kearny Mesa, sit above hundreds of small ship-repair, electronics and machining subcontractors. We get a shop to a true NIST 800-171 score and a system security plan, and keep the controls running, because the DoD paused the assessment mandate in July 2026 but the primes did not pause their questionnaires.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your machinists in Kearny Mesa and your front desk in Carlsbad get the same short monthly training, built around the lures hitting San Diego inboxes and phones this month, and each person is scored so you know who needs a hand. The report button sits in the mail client; one press protects the whole shop and the contract with it. We do not charge per module or per test.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a San Diego business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions San Diego owners ask

What people in San Diego search for, answered straight.

Which CMMC level does a San Diego subcontractor need?
If you only handle federal contract information, Level 1 and its 15 basic practices. If drawings, specifications or technical data marked CUI reach your shop, Level 2, which is the 110 controls of NIST 800-171. Most machine shops supplying a Poway or Rancho Bernardo prime on a Navy program are Level 2 whether they know it yet or not.
What is an SPRS score and why is the prime asking for it?
It is your self-reported NIST 800-171 score, from minus 203 to 110, posted in the DoD's Supplier Performance Risk System. Primes check it before awarding work, and a score entered from memory is a false statement to the government. We assess the 110 controls, fix what is missing, and post a number you can defend.
What does California law require after a data breach?
Since January 2026, 30 calendar days from discovery to notify affected residents, and a copy to the Attorney General within 15 days after that when more than 500 residents are notified. Providers also answer to the Confidentiality of Medical Information Act, which carries a private right of action.
Does my North County medical practice need a HIPAA risk analysis?
Yes. The HIPAA Security Rule requires a documented risk analysis for any practice that holds electronic patient records, and it is the first document an investigator asks for after a breach. We do it on site in Oceanside, Escondido or Carlsbad, alongside the controls, so it reflects the practice as it runs.
Does the CCPA apply to a small business?
The core thresholds are $25 million or more in revenue, or personal data on 100,000 or more consumers or households, or half of revenue from selling personal data. Many small firms sit outside them, but the new 2026 regulations on risk assessments and cybersecurity audits reach the ones that qualify. We tell you plainly which side of the line you are on.
How much does a cybersecurity assessment cost in San Diego?
Our pricing is public on the site, and a 30-minute demo scopes it to your shop or practice. The Cyber and Data Protection Assessment is priced by size and by the rules that apply to you, CMMC, HIPAA, CCPA or none. You get a scored report and the ten fixes that matter first.

Sources: FBI IC3 2025, California · SDMAC 2025 Military Economic Impact Report · UC San Diego on the SDMAC report · SB 446 breach law amendment · CPPA regulation updates · CMIA overview · BLS San Diego economy at a glance · Verizon 2026 DBIR · KPBS on Tri-City Medical Center · California AG report on Palomar Health Medical Group · Union-Tribune on Sharp HealthCare · FBI San Diego · CISA Region 9

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our San Diego practice replies within one business day.

3-min test