AccuSights
PartnersBlogAbout
Book my 30-minute demo

Washington, District of Columbia · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

Washington runs on trust and clearances. We keep your data inside both.

A 28-person association on Connecticut Avenue with 41,000 donors in one file, a GovCon firm in Tysons with CUI on a shared drive, a practice in Bethesda a mile from NIH. You built it on the Beltway and the Red Line. Someone overseas is working tonight on the December giving season. We watch the other side of that, around the clock.

Chicago-based, serving DC, Maryland and Northern VirginiaEngineer on site for practicesPublic pricingStaff training included

Serving K Street and Downtown, Dupont Circle, Capitol Hill and Navy Yard, Arlington and Crystal City, Tysons and McLean, Reston and Herndon, Bethesda and Chevy Chase and Silver Spring and Columbia. Remote first, on site when it matters.

A Washington story

The Tuesday the donor file almost went out with the year-end appeal

the executive director of a 28-person association on Connecticut Avenue near Dupont Circle

It is a Tuesday in December, the second week of the year-end appeal, and the executive director has run the association for nine years. The donor file holds 41,000 names, giving histories and the notes that explain why a member in Reston gives every November and one in Bethesda never does. It is the association.

At 10:40 the finance manager gets an email from the audit firm's real domain, referencing the real engagement, asking her to view the draft management letter in a shared workspace. The link asks her to grant an app permission to read her mailbox and files so the letter can load. She does, because the audit is real and the letter is due.

The app is not the audit firm's. By 10:52 it is asking for the donor file.

The engineer sees the consent grant at 10:53, revokes it and calls. The finance manager gets a thank-you, not a lecture. The audit firm gets a call about the mailbox someone borrowed on their side. The appeal goes out Thursday, to 41,000 people who never find out how close it came.

The request dies at the door: bulk downloads from that library need a second approval, and nobody gave one.

What changes the ending

  1. The donor file in one protected library with bulk-download limits and a second approval, not on a shared drive next to the newsletter templates (CIS 3 Data Protection).
  2. Third-party app consent restricted to an allow list, so a "view the audit letter" click cannot hand a stranger your mailbox (CIS 4 Secure Configuration of Enterprise Assets and Software).
  3. Training that treats December as phishing season, scored per person, with a report button that reaches an engineer (CIS 14 Security Awareness and Skills Training).

What price are you willing to pay to let nine years of building in this city go away because someone overseas tricked one person on your team into clicking a link? Your donors, your members, your clearance, gone in a morning. We would rather you take the vacation you earned and land at National to find payroll still there and the donor file where you left it.

Sam Khan, founder. The Cyber Expert in times of peace.

District of Columbia, by the numbers

What the FBI, the state and the researchers counted, not what a vendor guessed.

$97.4M
lost to internet crime by District of Columbia victims in 2025, across 3,113 complaints, with Maryland at $390.2 million and Virginia at $475.9 million
Source: FBI IC3 2025 Annual Report, DC, Maryland and Virginia state pages, 2026
448.8
complaints per 100,000 residents, the highest per-capita rate in the country
Source: ELACA snapshot of the FBI IC3 2025 report, 2026
7,152
confirmed breaches at small and medium businesses in one year: 100% external attackers, 100% financially motivated
Source: Verizon 2026 Data Breach Investigations Report

The law and its clock

DC Security Breach Protection Amendment Act (D.C. Code 28-3851 et seq.)

Notify affected DC residents in the most expedient time possible and without unreasonable delay. Notify the Office of the Attorney General when 50 or more DC residents are affected, no later than resident notice. 18 months of identity-theft protection when Social Security or taxpayer numbers are involved, and a standing duty to keep reasonable security safeguards.

Regulator: DC Office of the Attorney General · source

Maryland Personal Information Protection Act (Com. Law 14-3501 et seq.)

Notify affected residents within 45 days after the investigation concludes, and notify the Maryland Attorney General before residents. Vendors tell the data owner within 10 days.

Regulator: Maryland Attorney General · source

Virginia breach notification (Va. Code 18.2-186.6)

Notify the Office of the Attorney General and affected residents without unreasonable delay; consumer reporting agencies when more than 1,000 residents are affected. The Virginia Consumer Data Protection Act has applied since January 1, 2023.

Regulator: Virginia Attorney General · source

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

It happened here

DC Health Link, the District's health-insurance exchange, disclosed a breach exposing data of 56,415 customers, including 17 members of Congress and 585 congressional staffers, later traced to a misconfigured server.

March 2023 · The New York Times

The DC Board of Elections confirmed that a hosting vendor's server held a copy of the full voter roll after a threat actor claimed access to 600,000 lines of voter data.

October 2023 · SecurityWeek

Frederick Health Medical Group in Maryland detected a ransomware attack that forced IT systems offline; it later reported 934,326 people affected.

January 2025 · BleepingComputer

We list public incidents to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Washington

Same controls, told from where it hurts for your business.

Medical and dental practices

What if the Bethesda office manager's inbox is the one that pays the vendors and holds the patient schedule?

Every workstation and the practice server watched around the clock, offline backups that restore charts in hours, MFA on every login, and a HIPAA risk analysis your license can stand on, in DC, Maryland or Virginia.

The NIH and Walter Reed corridor anchors dense specialty practices in Bethesda, Chevy Chase, McLean and Silver Spring; DC, Maryland and Virginia together have 57,174 active physicians and 10,606 active dentists (KFF).

Government contractors and defense suppliers

What if the contracting officer asks for our SPRS score and the honest number is negative?

CUI in one controlled enclave, the 110 NIST SP 800-171 practices assessed and scored, a System Security Plan and plan of action you can submit, and an engineer watching logins so the prime hears about an attempt from you.

Virginia is the number-one state in the DoD Defense Spending by State series and Maryland is top ten (OLDCC), and the thousands of small GovCon firms in Tysons, Reston, Herndon, Chantilly and Columbia hold the CUI.

Associations and nonprofits

What if the donor file is on the same shared drive as the newsletter templates, and December is the busiest month for both?

The member and donor file in one protected library with download limits and a second approval, third-party app consent restricted, MFA on every mailbox, and training that treats giving season as phishing season.

DC hosts more trade and professional associations than any other US city, and membership and donor data is what the bad guy is there for.

Law firms and public-affairs shops

What if a client's privileged file leaves through a paralegal's mailbox that has had a stranger in it since the fiscal-year-end rush?

Lookalike-domain filtering, MFA on every mailbox, a data-loss policy on client files, and an engineer who sees the login from the wrong country before the file moves.

Professional and business services is the largest private sector in the DC-Maryland division at 207,800 jobs (BLS, July 2026), and professional services breaches saw credentials stolen 31% of the time (Verizon 2026 DBIR).

Software, data and AI companies

What if the federal customer wants FedRAMP evidence and the commercial customer wants SOC 2, and we have neither?

One control set mapped to SOC 2 and NIST 800-53, evidence collected continuously by the agent, and a named engineer who answers the questionnaire with a log, not a paragraph.

The Dulles corridor and Crystal City hold software firms selling to both government and enterprise, and both now ask for proof before they sign.

Medical, dental and other healthcare practices

In Washington an AccuSights cybersecurity engineer comes to the practice, from Dupont Circle to Bethesda and out to McLean and Fairfax, and sets up the critical controls and the protection agent the same week.

The critical security controls set up in the office, the protection agent on every workstation and the server, the staff trained the same week, and a HIPAA risk analysis that holds up. We work at your speed and we do not bill you per module.

Defense suppliers: The Pentagon, Fort Belvoir, Quantico, Fort Meade and the Navy Yard sit inside the metro, and the primes headquartered in Bethesda, Reston, Falls Church and Arlington run the largest subcontractor base in the country. The July 2026 pause of the C3PAO mandate is not a pardon: NIST SP 800-171 stays in the contract, and we score you against its 110 practices before the prime asks.

Your staff, trained and scored

It is fine to skip the new Nigerian prince's email. Next time, press the report button too.

Your Dupont Circle finance manager and your Tysons engineers get the same short, scored training every month, built around what we see in Washington inboxes and on Washington phones that month, including the fake audit letters and the government-impersonation calls that cost victims more than $833 million nationally in 2025. Phishing tests teach one habit above all: press the report button, and an engineer sees it. No per-module charges and no shaming for a click.

  • Short monthly training tied to the threats we are seeing this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand and nobody gets nickel-and-dimed for a module.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade software, engineers who did this for the largest institutions, and a team that actually picks up the phone. We built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a Washington business

Assess it, keep it compliant, protect it around the clock.

Assess

Cybersecurity and Data Protection Assessment (CDPA)

Where the money, the records and the drawings actually live, what would stop the business, and the ten fixes that matter first. Scored against the CIS Controls and whatever rules apply to you.

Details →

Comply

Compliance, kept current

HIPAA, CMMC, SOC 2, PCI, the FTC Safeguards Rule, state privacy law: one control set, evidence produced once, ready the day a regulator, a prime or a customer asks.

Details →

Protect

24/7 protection for every employee, endpoint, server and website

An AI security agent that contains a threat in seconds and a named human engineer who watches it, day and night. Think of it as a per-employee service, like payroll, except that cutting this corner is the one that can empty the account.

Details →
Or start with the 3-minute test

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions Washington owners ask

What people in Washington search for, answered straight.

What CMMC level does a Northern Virginia subcontractor need?
If your contract includes controlled unclassified information, you are a Level 2 supplier and NIST SP 800-171 has applied since 2017. The July 2026 pause of the C3PAO mandate does not remove that. We assess the 110 practices, score you, write the System Security Plan and the plan of action, and fix the gaps.
What does DC law require after a data breach, and what about Maryland and Virginia?
DC requires notice to residents without unreasonable delay and to the Attorney General when 50 or more DC residents are affected. Maryland gives you 45 days after the investigation concludes and requires notice to its Attorney General first. Virginia requires notice to its Attorney General and residents without unreasonable delay. Most firms here hold data from all three, so we plan for all three.
How should a DC association protect its member and donor data?
Put the file in one protected library with download limits and a second approval, restrict which third-party apps can be granted access to mailboxes, turn on MFA everywhere, and train the finance team on the December pretext. That is the difference between a bad Tuesday and a letter to 41,000 people.
How much does managed security cost for a 30-person GovCon firm in Tysons?
Our pricing is public and per employee, with the NIST SP 800-171 assessment priced as a fixed fee. A 30-minute demo scopes it, and the engineer assigned to you is the one who writes the System Security Plan.
What is NIST 800-171 and do we still need an assessment now that CMMC is paused?
NIST SP 800-171 is the set of 110 security practices the Defense Department requires for anyone handling controlled unclassified information, and the DFARS clause requiring it has been in contracts since 2017. CMMC is the audit of it. The pause delays the audit, not the requirement, and primes are still asking for scores.
Can you come to our practice in Bethesda or McLean?
Yes. Our engineers work on site across DC, Montgomery County and Northern Virginia, and remotely for the rest. The critical controls and the protection agent go in the same week as the risk analysis.

Sources: FBI IC3 2025 Annual Report, District of Columbia · FBI IC3 2025 Annual Report, Maryland · FBI IC3 2025 Annual Report, Virginia · ELACA, 2025 IC3 report snapshot · Scam Complaints, government impersonation 2025 · D.C. Code 28-3851 · Maryland Attorney General, business guidance · Va. Code 18.2-186.6 · Virginia Consumer Data Protection Act · BLS, Washington DC-MD Economy at a Glance · DoD OLDCC, Defense Spending by State · KFF, professionally active physicians · KFF, professionally active dentists · The New York Times, DC Health Link · SecurityWeek, DC Board of Elections · BleepingComputer, Frederick Health · FBI Washington Field Office · CISA Region 3 · Verizon 2026 DBIR

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes, an engineer, no pitch deck.

Book the demo and see how the console watches a business like yours. Or leave your details and an engineer in our Washington practice replies within one business day.

3-min test