The AccuSights blog
Stories, threats and plain-English fixes from the Cyber Expert and Dr. Kash
Every post opens with what a breach looks like from the inside, gives you the 2026 numbers behind it, and ends with the handful of moves that decide how it turns out. Written for the owner who built something real, by people who ran security inside the largest institutions.
Agencies and Staffing Firms: The Shared Drive, the SOC 2 Question, and What to Answer Before You Have a Report
Agency and staffing SOC 2 questions arrive with your biggest deal. What client data in shared drives exposes, and the answer that keeps the deal alive.
US complianceThe NYDFS Annual Certification: What to Have Ready in March So the 15 April Filing Takes an Afternoon
The NYDFS annual certification is due 15 April. The evidence a covered entity should collect in March for Part 500, from asset inventory to MFA and logs.
ThreatsAuto Repair and the Trades: When Your Own Invoice Reaches the Customer With Someone Else's Bank Details
Invoice fraud in auto repair and the trades: how a shop's email gets read for weeks, why the customer pays a stranger, and the ten-minute fix that ends it.
Practical controlsRestaurants and Hotels: The Point-of-Sale Network, the Guest Wi-Fi and the PCI Question Your Bank Will Eventually Ask
Restaurant and hotel PCI compliance starts with one cable: how the point-of-sale network, guest Wi-Fi and the SAQ your bank asks for actually fit together.
ThreatsTax Season Phishing at CPA Firms: The Fake IRS Notice, the Cloned Portal Link, and the Four Minutes That Cost a Filing Season
Tax season phishing peaks in February at CPA firms. How the fake IRS e-Services notice and the cloned client portal work, and the reply that stops both.
US complianceCMMC Watch: What the Return of Phase 2 Would Change, and Why None of the Readiness Work Is Wasted
CMMC Phase 2 return readiness: what changes when third-party assessment comes back, what conditional status at 88 means, and the work that counts either way.
The data you holdPrivate Schools, Tutoring Centers and the Shared Link: Student Data When IT Is One Person Who Also Teaches Robotics
Private school student data and FERPA: what schools hold, which rules apply when you take no federal funds, and the 56 safeguards one IT person can run.
US complianceThe 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About
A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.
US complianceThe WISP a CPA Firm Can Write in a Week, Before the January Rush Starts
A CPA WISP for tax season: what the FTC Safeguards Rule and IRS Publication 4557 expect, the Security Six, and the PTIN attestation you already signed.
Practical controlsRenewal Season: Answer the MFA, EDR and Backup Questions Before the Broker Asks Twice
Cyber insurance renewal questions on MFA, EDR and backups: the eight-item evidence pack that shortens the form, sharpens the quote and protects the claim.
US complianceThe HIPAA Security Rule Rewrite: The Dates to Budget Around and the Controls That Stop Being Optional
HIPAA Security Rule update timeline: the proposal is not final and HHS projects July 2027, so here are the controls to budget for and the dates to plan around.
US complianceRegulation S-P Six Months In: The 30-Day Clock Runs While You Wait for the Mailbox Export
Regulation S-P six months in: where the 30-day customer notice actually goes wrong for smaller advisers, and the four records that shorten the clock.
The data you holdThe Donor File Is Your Most Sensitive Record, and It Is Wide Open Until Thursday
Nonprofit donor data security before the year-end appeal: what sits in the CRM, who can reach it, and the six checks a Washington DC nonprofit makes first.
ThreatsOpen Enrollment Is Phishing Season: The Benefits Email That Costs a Practice a Payroll Run
Open enrollment phishing hits HR and benefits data every November: the four emails a practice will get, and the check that stops the direct deposit change.
US complianceNine Terminals, Five Stores, One Holiday Peak: PCI DSS 4.0.1 for Atlanta Retail
PCI DSS for multi-location retail in Atlanta: what 4.0.1 asks of nine terminals across five stores, and the six checks to finish before the holiday peak.
ThreatsWire Fraud at a Miami Closing Table: How the Payoff Email Changes Banks
Wire fraud in a Miami real estate closing: how the payoff email changes banks, the three signals that catch it, and the callback rule that ends the argument.
Practical controlsCybersecurity Awareness Month for a 30-Person Business: Four Controls, in Order
Cybersecurity Awareness Month, done properly by a 30-person business: four controls in the order that removes the most risk per hour of work, not a poster.
US complianceCMMC in the Phase 2 Pause: What a Dallas Machine Shop Still Owes This Quarter
The CMMC Phase 2 pause suspended the C3PAO mandate on 13 July 2026. What a Dallas machine shop still owes on SPRS, DFARS 7012 and Phase 1 this quarter.
Practical controlsHow to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It
Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.
Practical controlsA Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs
A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
AI and new risksAI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill
An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.
AI and new risksAI Inside Your Vendors: Prompt Injection, Agent Permissions and the Questions to Ask Before You Connect Anything
AI agent security for a small business: how prompt injection turns a helpful assistant against you, what permissions to give it, and what to ask the vendor.
Practical controlsAudit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door
Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.
ThreatsBusiness Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank
Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.
The data you holdCard Data: The Safest Way to Store It Is to Never Touch It
PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.
The data you holdClient Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding
Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.
US complianceCMMC in 2026: The Pause Is Not a Pardon
CMMC 2026 status: Phase 2 certification is suspended, but Phase 1 self-assessments, SPRS scores and DFARS 7012 are still in force. What to do now.
The data you holdCUI for the Shop Floor: What It Is, Where It Hides, and Why 'We Only Make Brackets' Is Not a Defense
What is controlled unclassified information, why a machine shop's drawings count, where CUI hides in email and Dropbox, and why 'we only make brackets' fails.
Reputation and business riskCyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied
Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.
ThreatsData Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.
A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.
ThreatsDeepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director
Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.
Practical controlsEDR vs Antivirus for a Small Business, and the Question That Matters More: Who Is Watching It at 2 a.m.?
EDR vs antivirus explained for a business owner: what each one catches, why insurers ask for EDR, and why a red alert nobody reads is the same as no alert.
US complianceFTC Safeguards Rule: The CPA, the Car Dealer and the Tax Preparer Are All Financial Institutions Now
The FTC Safeguards Rule covers CPAs, dealers with in-house financing and tax preparers. What a WISP is, who the qualified individual is, and the 30-day notice.
ThreatsInfostealers and Stolen Session Cookies: How Attackers Walk Past Your MFA Without Touching It
Infostealer malware lifts saved passwords and live session cookies from a browser, so the attacker never sees an MFA prompt. Here is how to close the door.
ThreatsInsider Risk in 2026: The Disgruntled Admin, the Careless Contractor and the Remote Hire Who Is Not Who You Think
Insider threat now includes the remote developer whose laptop lives in a stranger's house. How to verify hires, cut access on exit day, and watch the logs.
US complianceISO 27001 vs SOC 2: Which One Your Customers Are Actually Asking For
ISO 27001 vs SOC 2 for a small software company: what each one proves, who asks for which, what the certificate costs you in time, and how to do the work once.
Reputation and business riskLicence, Accreditation and Reputation: The Breach That Ends a Practice Without a Fine
Healthcare data breach consequences rarely arrive as a fine. They arrive as a conditional licence renewal, a delisted insurer network and referrals that stop.
ThreatsMobile Banking Malware: The Phone That Approves Your Payments Now Works for Someone Else
Mobile banking malware on one phone can overlay the bank app and forward one-time codes. How it gets in and how to keep it off the phones that approve payments.
Practical controlsMulti-Factor Authentication for a Small Business: Where It Belongs, Which Kind Works, and Why Outlook Alone Is Not Enough
Multi-factor authentication for a small business: the five doors it must be on, which kind survives a fake login page, and why Outlook alone is not enough.
US complianceNIST 800-171 Self-Assessment: Why an Honest 60 Beats a Fake 110
How a NIST 800-171 self assessment and SPRS score really work, why a false 110 is now a signed federal statement, and how to post a score you can defend.
US complianceNIST CSF 2.0 or CIS Controls IG1: Which One a 30-Person Business Should Start With
Choosing a cybersecurity framework for small business: CIS Controls IG1 for the work, NIST CSF 2.0 for the client conversation, and why you start with IG1.
US complianceNYDFS Part 500 for the Small Covered Entity: MFA Everywhere, an Asset List, and an April Signature
NYDFS Part 500 requirements for a small agency or broker: universal MFA since 1 November 2025, an asset inventory, and the April certification the owner signs.
Practical controlsPatch Management for a Small Business: Why 43 Days Is Too Slow for the Firewall and Fine for the Printer
Patch management for a small business: which devices need updates within days, which can wait, and why the firewall nobody reboots is the one that gets you.
US compliancePCI DSS 4.0.1 for a Small Merchant: The Questionnaire Changed, and So Did Your Checkout Page
PCI DSS 4.0.1 small business guide: what became mandatory on 31 March 2025, what changed in SAQ A, and why the scripts on your checkout page are your problem.
ThreatsPhishing in 2026: The QR Code, the Text Message and the Login Page That Steals Your Session
Phishing attacks on small business now arrive by QR code, text and phone call, and the fake login page steals your session, not just your password.
The data you holdPII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export
PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.
ThreatsRansomware in a Clinic: What Nine Days Without the EHR Really Looks Like
Healthcare ransomware stops refills, referrals and the front desk, not just files. What nine days of EHR downtime looks like, and how a small practice prepares.
ThreatsRemote Desktop Security: RDP, VPN and RMM Are the New Front Door, and It Is Usually Unlocked
Remote desktop security in 2026 is about three doors: RDP, the VPN box and the RMM tool. How attackers find them in days, and how to lock each one this week.
US complianceSEC Regulation S-P for the Small RIA: 30 Days to Tell Clients, and a Program to Prove You Could
Regulation S-P amendments reached smaller advisers on 3 June 2026: incident response program, 30-day client notice and vendor oversight. What the exam asks.
Practical controlsSecurity Awareness Training for a Small Business: Why the Report Button Beats the Delete Key
Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.
AI and new risksShadow AI: Your Staff Are Already Pasting Client Data Into Chatbots. Here Is the Policy.
Shadow AI is already in your business: what the 2026 breach data says about unapproved chatbots, and the one-page AI acceptable use policy that fixes it.
US complianceSOC 2 for a 20-Person Company: Type 1, Type 2, the Cost, and When You Actually Need It
SOC 2 for small business, explained plainly: Type 1 vs Type 2, what drives the cost, who really needs a report, and how a founder loses a deal without one.
The data you holdSource Code and Secrets: The API Key in the Repo Is the Whole Company
Source code security for a small software team: why the API key in the repo is the whole business, the first hour after a leak, and how to stop the next one.
US complianceState Privacy Laws in 2026: Which of the 20 Actually Apply to a Business Your Size
State privacy laws 2026: 20 are in force, three started in January, and Texas has no consumer-count threshold. How to tell which ones apply to your business.
Reputation and business riskThe Enterprise Security Questionnaire: How to Answer 212 Questions Without Lying or Losing the Deal
How to answer a security questionnaire from a big customer without lying or losing the deal: the 212-question workbook, what 'yes' commits you to, a method.
ThreatsThe First 72 Hours of a Ransomware Attack on a Small Business, Hour by Hour
What a ransomware attack on a small business looks like in the first 72 hours, what the 2026 numbers say about paying, and five moves that decide recovery.
US complianceThe HIPAA Risk Analysis: What OCR Actually Fined Practices For in 2025 and 2026
A HIPAA risk analysis is the document OCR asks for first. What it is, why annual training does not count, and how a small practice writes one that holds up.
US complianceThe HIPAA Security Rule Update Is Still a Proposal. The MFA Clock Is Not.
The HIPAA Security Rule update 2026 is still a proposal, with finalization projected for July 2027. Why MFA and encryption cannot wait for the final text.
Practical controlsThe One-Page Incident Response Plan a 25-Person Company Can Actually Follow
An incident response plan for a small business on one page: who calls whom in the first hour, the regulator clocks, and what to do when your IT provider is hit.
Reputation and business riskWhat a Breach Really Costs a 30-Person Business (It Is Not the USD 4.99 Million Headline)
The cost of a data breach, small business edition: not the USD 4.99 million headline but eleven days of lost closings, a bank that drops you, and payroll.
Reputation and business riskWhat a Cybersecurity Risk Assessment Actually Checks (and What a Free Scan Does Not)
What a cybersecurity risk assessment checks, what it costs for a company under 50 people, and why three free scans left a law firm unable to answer a client.
The data you holdWhere PHI Hides in a Small Practice: 14 Places Nobody Thinks to Check
What is PHI, and where does it live in a small practice? Fourteen places patient data hides outside the practice-management system, and how to find them.
ThreatsYour Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review
A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.
Never too big or too small