AccuSights
PartnersBlogAbout
Book my 30-minute demo

Cybersecurity and Data Protection Assessment (CDPA)

Find out what would actually hurt, and fix that first.

The same key security controls every time, scoped from what your kind of business stands to lose: the drawings, the client list, the card terminals, the patient records, the closing wire. An engineer looks from the inside, tests what matters, and hands you a ranked plan in plain English with a fixed fee for the fixes.

Take the 3-minute Cyber Hygiene Test first
Fixed fee, quoted on the callTwo to three weeksCIS Controls v8.1 IG1Our team can do the fixes

Scoped for your business

Pick your industry. This is what we look at.

Cybersecurity and Data Protection Assessment for Healthcare

Built on the CIS Controls v8.1 IG1 and the HIPAA Security Rule, scoped from what a practice stands to lose: patient records, the schedule and the license. The output is the risk analysis OCR asks for first, the safeguards set up rather than recommended, and a plan an owner can read in ten minutes.

  • HIPAA security risk analysis documented to the HHS guidance, naming every system, vendor and business associate (CIS Controls 1, 2 and 15)
  • On-site engineer visit in major cities to set up the critical controls (MFA, encryption, email and endpoint protection, backups) and install the protection agent
  • Account audit: shared front-desk logins, ex-staff access, MFA on the EHR, email and the patient portal (CIS Controls 5 and 6)
  • Backup and restore test for the EHR extract, imaging and practice-management data (CIS Control 11)
  • Vendor and BAA review for billing, imaging, transcription and IT providers, with access limits set (CIS Control 15)
  • Breach response plan rehearsed with the practice, plus a ranked remediation plan and a cyber health score

What you hold, and why someone wants it

Patient records in the EHR, imaging and billing

Worth more than card data on the criminal market and the trigger for OCR, the state and your license. Encryption, access limits, MFA and a current risk analysis protect them.

Front-desk and billing inboxes

The door for the fake vendor invoice and the diverted insurance payment. Email protection, MFA and monitoring protect them.

Laptops and the imaging server in the closet

Unencrypted devices and an unpatched server are the two findings OCR sees most. Encryption, patching and offline backups protect them.

Vendors and business associates

Billing, transcription, imaging and IT vendors with access to patient data; a third of healthcare breaches start there. BAAs, access review and monitoring protect you.

Card payments at the front desk

Copays and balances under PCI DSS v4.0.1. Segmented terminals and hardened payment pages protect them.

Everything for healthcare →

How it runs

Four steps. No consulting army.

1Thirty minutes to scope

Locations, people, systems, what you hold. You get a fixed fee on the call, never a surprise after.

2Two to three weeks of looking

We inventory what you own, test what matters (backups, MFA, the terminals, the file share), interview the people who run it, and check the cloud apps.

3A plan you can read

A cyber health score, the top gaps in plain English with the statistic that says why each one matters, quick wins separated from projects, and what it costs to close them.

4We can do the fixes

Our team implements the controls at a reasonable rate, from DLP to scanning to protection of the assets, or your IT provider does with our plan. Then Protect keeps it that way.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

What is a Cybersecurity and Data Protection Assessment?
A structured look at what your business owns, what it holds, and how it would be attacked, scored against the CIS Controls v8.1 Implementation Group 1, the safeguards the CIS Community Defense Model shows stop 77% of attack techniques. It ends in a ranked plan, not a hundred-page report.
We have no regulator. Why would we need this?
Because the attacker does not check for one. The DBIR counted small and mid-size businesses as 96% of ransomware victims where size was known. The assessment tells you the three things that would hurt most and the fixes that close them, and gives your insurer and your customers something to read.
How is it different from a free scan?
A free scan looks at your website from the outside for ten seconds. The assessment looks at your inboxes, devices, server, backups, accounts, vendors and people from the inside, with an engineer, and tests the things that matter instead of listing them.
What does it cost?
A fixed fee scoped in a 30-minute call around locations, people and systems. Most small businesses land in a range that costs less than one diverted payment.

Never too big or too small

Thirty minutes with an engineer. Then a fixed fee, or nothing.

3-min test