AccuSights
PartnersBlogAbout
Book my 30-minute demo

San Francisco, California · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

San Francisco sells trust to enterprises. We give you the log that proves it.

A 40-person software company in SoMa three weeks from its first enterprise customer, a law firm on the Embarcadero, a practice in Pacific Heights, a dual-use startup in Mountain View with its first DoD contract. You built it on Caltrain and the Bay Bridge. Someone in another time zone still has a contractor's password. We watch the other side of that, around the clock.

Chicago-based, serving the Bay AreaEngineer on site for practicesPublic pricingStaff training included

Serving SoMa and Mission Bay, the Financial District and Embarcadero, Pacific Heights and the Marina, Oakland and Berkeley, Walnut Creek, San Mateo and Redwood City, Palo Alto and Mountain View and South San Francisco. Remote first, on site when it matters.

A San Francisco story

The Tuesday the enterprise deal almost died at 2 a.m.

the co-founder of a 40-person software company in SoMa, three weeks from closing its first enterprise customer

It is a Tuesday in May, Karl the Fog still sitting on Twin Peaks, and the co-founder has a security questionnaire due Friday. The company is 40 people on Townsend Street, four years of work, and the enterprise customer that would double revenue wants question 14 answered: describe how you detect and respond to unauthorized access.

A contractor left in January. He was good, and busy, and nobody remembered that his console account had read access to the production database. His password turned up in a breach dump in April. At 2:07 on Tuesday morning someone in another time zone tries it.

The login succeeds.

The engineer on watch sees a January departure logging in from a country he has never worked from, disables the account at 2:10 and pages the co-founder with a summary, not a panic. No query ran. On Wednesday question 14 gets answered with Tuesday's log, timestamps and all. The customer's security team reads it, and the deal closes in three weeks.

A contractor who left in January is inside the cloud console, and the account still holds read access to every customer record.

What changes the ending

  1. Every departure closes every account the same day, and a quarterly review catches the ones it missed (CIS 5 Account Management).
  2. MFA on the cloud console and the production database with no exceptions for contractors, so a password from a breach dump is not a key (CIS 6 Access Control Management).
  3. Someone watching logins at 2 a.m. who can disable an account in minutes, which is also the honest answer to question 14 (CIS 13 Network Monitoring and Defense).

What price are you willing to pay to let four years of building in this city go away because someone overseas tricked one person on your team into clicking a link, or found a password nobody retired? The enterprise customer will not wait for a second chance. We would rather you take the vacation you earned and land at SFO to find payroll still there and the deal still open.

Sam Khan, founder. The Cyber Expert in times of peace.

California, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$3.67B
lost to internet crime by California victims in 2025, across 116,423 complaints, the most of any state on both counts
Source: FBI IC3 2025 Annual Report, California state page, 2026
$430.7M
of that was business email compromise, the changed invoice and the changed wire, across 3,444 California complaints
Source: FBI IC3 2025 Annual Report, California state page, 2026
48%
of breaches involve a third party, a 60% jump in one year: your vendors, your software suppliers, your cloud accounts
Source: Verizon 2026 Data Breach Investigations Report

The law and its clock

California breach notification, Civil Code 1798.82 as amended by SB 446

Notify affected California residents within 30 calendar days of discovery (effective January 1, 2026). When more than 500 residents are notified, a sample notice goes to the Attorney General within 15 calendar days after resident notice.

Regulator: California Attorney General · source

CCPA/CPRA and the 2026 CPPA regulations

Risk assessments required from 2026 for covered businesses, with pre-2026 processing assessed by December 31, 2027 and first attestations due April 1, 2028. Cybersecurity audit certifications first due April 1, 2028 for revenue above $100 million, April 1, 2029 for $50 million to $100 million, and April 1, 2030 below $50 million.

Regulator: California Privacy Protection Agency · source

Confidentiality of Medical Information Act (Civil Code 56)

Applies to every provider regardless of size. Private right of action with $1,000 nominal damages per violation and administrative penalties up to $2,500 for a negligent disclosure, on top of HIPAA.

Regulator: California courts and the Attorney General · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

A ransomware attack on the City of Oakland led the city to declare a local state of emergency; the Play group claimed it and later published stolen data.

February 2023 · The Oaklandside

Kaiser Permanente notified 13.4 million members that online tracking technologies may have sent personal information to third parties; it later agreed to pay up to $47.5 million to settle class actions.

April 2024 · Los Angeles Times

Stanford University's Department of Public Safety network was compromised by Akira ransomware; about 27,000 people were notified.

September 2023 · Stanford Report

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in San Francisco

Same controls, told from where it hurts for your business.

Medical, dental and specialty practices

What if one phishing email at the Pacific Heights front desk exposes every chart, and the CMIA lawsuit arrives before the HIPAA letter?

Every workstation and the practice server watched around the clock, offline backups that restore charts in hours, MFA on every login, and a HIPAA risk analysis that also answers California's 30-day clock and the CMIA.

Education and health services employ 439,000 people in the San Francisco metro, growing 3.0% a year (BLS, July 2026), with independent practices concentrated on the Peninsula and in the East Bay.

Startups, SaaS and AI companies

What if the enterprise customer wants SOC 2 before the round closes and question 14 is about the 2 a.m. login we would never have seen?

A control set mapped once to SOC 2 and the questionnaire, evidence collected continuously by the agent, every departure closed the same day, and a named engineer who answers question 14 with a log, not a paragraph.

Professional and business services is the largest private sector in the metro at 471,900 jobs and the information sector adds 128,500 (BLS, July 2026); 48% of breaches now involve a third party (Verizon 2026 DBIR).

Law firms

What if the wire instructions for the Embarcadero closing came from a mailbox with a stranger in it?

Lookalike-domain filtering, a callback rule your staff practices, MFA on partner mailboxes, and an engineer who sees the login from the wrong country before the money moves.

Business email compromise cost California $430.7 million across 3,444 complaints in 2025 (FBI IC3), and professional services breaches saw credentials stolen 31% of the time (Verizon 2026 DBIR).

Venture firms, fintech and wealth managers

What if the LP portal, the capital-call emails and the wire approvals all sit behind one office manager's password?

MFA on every account, a callback rule on every capital call and wire, a data-loss policy on the LP list, and 24/7 watching so a login from the wrong country meets a human in minutes.

Financial activities employ 121,800 people in the metro (BLS, July 2026), and capital-call fraud is business email compromise with a bigger number on it.

Dual-use and defense tech startups

What if the first DoD contract arrives with a DFARS clause and nobody here has read NIST 800-171?

CUI in one controlled enclave, the 110 NIST SP 800-171 practices assessed and scored, a System Security Plan you can submit, and an engineer watching logins so the contracting officer hears about an attempt from you.

The Defense Innovation Unit in Mountain View funnels dual-use startups into DoD contracts, and the Lawrence Livermore supply chain runs through the Tri-Valley.

Medical, dental and other healthcare practices

In San Francisco an AccuSights cybersecurity engineer comes to the practice, from Pacific Heights to Walnut Creek and down the Peninsula to Palo Alto, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: Travis Air Force Base, Moffett Field and the Defense Innovation Unit in Mountain View, and the Lawrence Livermore supply chain in the Tri-Valley give the Bay Area a growing dual-use base whose first DoD contract arrives with a DFARS clause. The July 2026 pause of the C3PAO mandate is not a pardon: NIST SP 800-171 stays in the contract, and we score you against its 110 practices before the contracting officer asks.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your SoMa engineers and your Peninsula front desk get the same short, scored training every month, built around what we see in Bay Area inboxes and on Bay Area phones that month, where fake texts now land 40% more often than email. Phishing tests teach one habit above all: press the report button, and an engineer sees it. No per-module charges and no shaming for a click.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a San Francisco business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions San Francisco owners ask

What people in San Francisco search for, answered straight.

How much does SOC 2 cost for a San Francisco startup?
The auditor's fee is separate from the readiness work, and the readiness work is where the time goes. Our pricing is public, per employee for protection and a fixed fee for the assessment. A 30-minute demo scopes it, and the same agent that protects you collects the evidence the auditor wants.
Do we need SOC 2 Type 1 or Type 2 first?
Type 1 says the controls existed on a date; Type 2 says they operated over a period, usually six to twelve months. Most enterprise buyers accept a Type 1 with a Type 2 in progress. Start the controls now, because the Type 2 clock only runs once they are on.
What changed in California's data breach law in 2026?
SB 446 took effect January 1, 2026 and set a hard 30-calendar-day deadline from discovery to notify affected residents, with a sample notice to the Attorney General within 15 days after that when more than 500 Californians are notified. A company that finds out on a Tuesday now has a calendar, not a judgment call.
What are the CPPA cybersecurity audit deadlines?
Certifications are first due April 1, 2028 for businesses above $100 million in revenue, April 1, 2029 for $50 million to $100 million, and April 1, 2030 below $50 million. Risk assessments start in 2026 with first attestations due April 1, 2028. Many Bay Area SaaS firms hit the top tier first, and the controls the audit checks are the ones we put in now.
What does HIPAA require for a Bay Area medical practice?
A documented risk analysis kept current, the safeguards it points to, staff training with a record, and business associate agreements with every vendor that touches patient data. California adds the CMIA and the 30-day breach clock. Our engineer does the analysis on site, from the Marina to Palo Alto, and puts the controls in the same week.
Do we need CMMC as a dual-use startup in Mountain View?
If the contract includes controlled unclassified information, yes, at Level 2, and the NIST SP 800-171 clause has applied since 2017. The July 2026 pause of the C3PAO mandate delays the audit, not the requirement. We assess the 110 practices, score you, write the System Security Plan and fix the gaps.

Sources: FBI IC3 2025 Annual Report, California · SB 446 (2025) · CPPA regulations · Skadden on the CPPA regulations, 2025 · CMIA overview (MIEC) · BLS, San Francisco-Oakland-Fremont Economy at a Glance · The Oaklandside, City of Oakland · Los Angeles Times, Kaiser Permanente · Stanford Report, Department of Public Safety incident · FBI San Francisco Field Office · CISA Region 9 · Verizon 2026 DBIR

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our San Francisco practice replies within one business day.

3-min test