AccuSights
Partners
Book my 30-minute demo

The AccuSights blog

Stories, threats and plain-English fixes from the Cyber Expert and Dr. Kash

Every post opens with what a breach looks like from the inside, gives you the 2026 numbers behind it, and ends with the handful of moves that decide how it turns out. Written for the owner who built something real, by people who ran security inside the largest institutions.

Reputation and business risk

Agencies and Staffing Firms: The Shared Drive, the SOC 2 Question, and What to Answer Before You Have a Report

Agency and staffing SOC 2 questions arrive with your biggest deal. What client data in shared drives exposes, and the answer that keeps the deal alive.

Sam Khan6 min readMarch 1, 2027
US compliance

The NYDFS Annual Certification: What to Have Ready in March So the 15 April Filing Takes an Afternoon

The NYDFS annual certification is due 15 April. The evidence a covered entity should collect in March for Part 500, from asset inventory to MFA and logs.

Sam Khan6 min readFebruary 22, 2027
Threats

Auto Repair and the Trades: When Your Own Invoice Reaches the Customer With Someone Else's Bank Details

Invoice fraud in auto repair and the trades: how a shop's email gets read for weeks, why the customer pays a stranger, and the ten-minute fix that ends it.

Sam Khan6 min readFebruary 15, 2027
Practical controls

Restaurants and Hotels: The Point-of-Sale Network, the Guest Wi-Fi and the PCI Question Your Bank Will Eventually Ask

Restaurant and hotel PCI compliance starts with one cable: how the point-of-sale network, guest Wi-Fi and the SAQ your bank asks for actually fit together.

Sam Khan6 min readFebruary 8, 2027
Threats

Tax Season Phishing at CPA Firms: The Fake IRS Notice, the Cloned Portal Link, and the Four Minutes That Cost a Filing Season

Tax season phishing peaks in February at CPA firms. How the fake IRS e-Services notice and the cloned client portal work, and the reply that stops both.

Sam Khan6 min readJanuary 25, 2027
US compliance

CMMC Watch: What the Return of Phase 2 Would Change, and Why None of the Readiness Work Is Wasted

CMMC Phase 2 return readiness: what changes when third-party assessment comes back, what conditional status at 88 means, and the work that counts either way.

Dr. Kashmala Khalid6 min readJanuary 18, 2027
The data you hold

Private Schools, Tutoring Centers and the Shared Link: Student Data When IT Is One Person Who Also Teaches Robotics

Private school student data and FERPA: what schools hold, which rules apply when you take no federal funds, and the 56 safeguards one IT person can run.

Sam Khan6 min readJanuary 11, 2027
US compliance

The 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About

A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.

Sam Khan6 min readDecember 28, 2026
US compliance

The WISP a CPA Firm Can Write in a Week, Before the January Rush Starts

A CPA WISP for tax season: what the FTC Safeguards Rule and IRS Publication 4557 expect, the Security Six, and the PTIN attestation you already signed.

Sam Khan6 min readDecember 21, 2026
Practical controls

Renewal Season: Answer the MFA, EDR and Backup Questions Before the Broker Asks Twice

Cyber insurance renewal questions on MFA, EDR and backups: the eight-item evidence pack that shortens the form, sharpens the quote and protects the claim.

Sam Khan6 min readDecember 7, 2026
US compliance

The HIPAA Security Rule Rewrite: The Dates to Budget Around and the Controls That Stop Being Optional

HIPAA Security Rule update timeline: the proposal is not final and HHS projects July 2027, so here are the controls to budget for and the dates to plan around.

Dr. Kashmala Khalid6 min readNovember 30, 2026
US compliance

Regulation S-P Six Months In: The 30-Day Clock Runs While You Wait for the Mailbox Export

Regulation S-P six months in: where the 30-day customer notice actually goes wrong for smaller advisers, and the four records that shorten the clock.

Sam Khan6 min readNovember 16, 2026
The data you hold

The Donor File Is Your Most Sensitive Record, and It Is Wide Open Until Thursday

Nonprofit donor data security before the year-end appeal: what sits in the CRM, who can reach it, and the six checks a Washington DC nonprofit makes first.

Sam Khan6 min readNovember 9, 2026
Threats

Open Enrollment Is Phishing Season: The Benefits Email That Costs a Practice a Payroll Run

Open enrollment phishing hits HR and benefits data every November: the four emails a practice will get, and the check that stops the direct deposit change.

Dr. Kashmala Khalid6 min readNovember 2, 2026
US compliance

Nine Terminals, Five Stores, One Holiday Peak: PCI DSS 4.0.1 for Atlanta Retail

PCI DSS for multi-location retail in Atlanta: what 4.0.1 asks of nine terminals across five stores, and the six checks to finish before the holiday peak.

Sam Khan6 min readOctober 26, 2026
Threats

Wire Fraud at a Miami Closing Table: How the Payoff Email Changes Banks

Wire fraud in a Miami real estate closing: how the payoff email changes banks, the three signals that catch it, and the callback rule that ends the argument.

Sam Khan6 min readOctober 12, 2026
Practical controls

Cybersecurity Awareness Month for a 30-Person Business: Four Controls, in Order

Cybersecurity Awareness Month, done properly by a 30-person business: four controls in the order that removes the most risk per hour of work, not a poster.

Sam Khan6 min readOctober 5, 2026
US compliance

CMMC in the Phase 2 Pause: What a Dallas Machine Shop Still Owes This Quarter

The CMMC Phase 2 pause suspended the C3PAO mandate on 13 July 2026. What a Dallas machine shop still owes on SPRS, DFARS 7012 and Phase 1 this quarter.

Dr. Kashmala Khalid6 min readSeptember 28, 2026
Practical controls

How to Read Your Cyber Hygiene Score: What 77 Percent Coverage Means and the Three Fixes That Move It

Your cyber hygiene score is coverage, not a grade. What 77 percent coverage means, why the number moves, and the three fixes that raise it fastest.

Sam Khan6 min readSeptember 7, 2026
Practical controls

A Backup Strategy for a Small Business That Survives Ransomware: 3-2-1-1-0 and the Restore Test Nobody Runs

A backup strategy for a small business that survives ransomware: why sync is not backup, what 3-2-1-1-0 means, and the monthly restore test nobody runs.

Sam Khan6 min readSeptember 2, 2026
Threats

AI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not

AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.

Sam Khan6 min readSeptember 2, 2026
AI and new risks

AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill

An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.

Sam Khan7 min readSeptember 2, 2026
AI and new risks

AI Inside Your Vendors: Prompt Injection, Agent Permissions and the Questions to Ask Before You Connect Anything

AI agent security for a small business: how prompt injection turns a helpful assistant against you, what permissions to give it, and what to ask the vendor.

Sam Khan6 min readSeptember 2, 2026
Practical controls

Audit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door

Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.

Sam Khan6 min readSeptember 2, 2026
Threats

Business Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank

Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.

Sam Khan6 min readSeptember 2, 2026
The data you hold

Card Data: The Safest Way to Store It Is to Never Touch It

PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.

Sam Khan6 min readSeptember 2, 2026
The data you hold

Client Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding

Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.

Sam Khan6 min readSeptember 2, 2026
US compliance

CMMC in 2026: The Pause Is Not a Pardon

CMMC 2026 status: Phase 2 certification is suspended, but Phase 1 self-assessments, SPRS scores and DFARS 7012 are still in force. What to do now.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
The data you hold

CUI for the Shop Floor: What It Is, Where It Hides, and Why 'We Only Make Brackets' Is Not a Defense

What is controlled unclassified information, why a machine shop's drawings count, where CUI hides in email and Dropbox, and why 'we only make brackets' fails.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
Reputation and business risk

Cyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied

Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.

Sam Khan6 min readSeptember 2, 2026
Threats

Data Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.

A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.

Sam Khan6 min readSeptember 2, 2026
Threats

Deepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director

Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.

Sam Khan6 min readSeptember 2, 2026
Practical controls

EDR vs Antivirus for a Small Business, and the Question That Matters More: Who Is Watching It at 2 a.m.?

EDR vs antivirus explained for a business owner: what each one catches, why insurers ask for EDR, and why a red alert nobody reads is the same as no alert.

Sam Khan6 min readSeptember 2, 2026
US compliance

FTC Safeguards Rule: The CPA, the Car Dealer and the Tax Preparer Are All Financial Institutions Now

The FTC Safeguards Rule covers CPAs, dealers with in-house financing and tax preparers. What a WISP is, who the qualified individual is, and the 30-day notice.

Sam Khan6 min readSeptember 2, 2026
Threats

Infostealers and Stolen Session Cookies: How Attackers Walk Past Your MFA Without Touching It

Infostealer malware lifts saved passwords and live session cookies from a browser, so the attacker never sees an MFA prompt. Here is how to close the door.

Sam Khan6 min readSeptember 2, 2026
Threats

Insider Risk in 2026: The Disgruntled Admin, the Careless Contractor and the Remote Hire Who Is Not Who You Think

Insider threat now includes the remote developer whose laptop lives in a stranger's house. How to verify hires, cut access on exit day, and watch the logs.

Sam Khan6 min readSeptember 2, 2026
US compliance

ISO 27001 vs SOC 2: Which One Your Customers Are Actually Asking For

ISO 27001 vs SOC 2 for a small software company: what each one proves, who asks for which, what the certificate costs you in time, and how to do the work once.

Sam Khan6 min readSeptember 2, 2026
Reputation and business risk

Licence, Accreditation and Reputation: The Breach That Ends a Practice Without a Fine

Healthcare data breach consequences rarely arrive as a fine. They arrive as a conditional licence renewal, a delisted insurer network and referrals that stop.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
Threats

Mobile Banking Malware: The Phone That Approves Your Payments Now Works for Someone Else

Mobile banking malware on one phone can overlay the bank app and forward one-time codes. How it gets in and how to keep it off the phones that approve payments.

Sam Khan6 min readSeptember 2, 2026
Practical controls

Multi-Factor Authentication for a Small Business: Where It Belongs, Which Kind Works, and Why Outlook Alone Is Not Enough

Multi-factor authentication for a small business: the five doors it must be on, which kind survives a fake login page, and why Outlook alone is not enough.

Sam Khan6 min readSeptember 2, 2026
US compliance

NIST 800-171 Self-Assessment: Why an Honest 60 Beats a Fake 110

How a NIST 800-171 self assessment and SPRS score really work, why a false 110 is now a signed federal statement, and how to post a score you can defend.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
US compliance

NIST CSF 2.0 or CIS Controls IG1: Which One a 30-Person Business Should Start With

Choosing a cybersecurity framework for small business: CIS Controls IG1 for the work, NIST CSF 2.0 for the client conversation, and why you start with IG1.

Sam Khan6 min readSeptember 2, 2026
US compliance

NYDFS Part 500 for the Small Covered Entity: MFA Everywhere, an Asset List, and an April Signature

NYDFS Part 500 requirements for a small agency or broker: universal MFA since 1 November 2025, an asset inventory, and the April certification the owner signs.

Sam Khan6 min readSeptember 2, 2026
Practical controls

Patch Management for a Small Business: Why 43 Days Is Too Slow for the Firewall and Fine for the Printer

Patch management for a small business: which devices need updates within days, which can wait, and why the firewall nobody reboots is the one that gets you.

Sam Khan6 min readSeptember 2, 2026
US compliance

PCI DSS 4.0.1 for a Small Merchant: The Questionnaire Changed, and So Did Your Checkout Page

PCI DSS 4.0.1 small business guide: what became mandatory on 31 March 2025, what changed in SAQ A, and why the scripts on your checkout page are your problem.

Sam Khan6 min readSeptember 2, 2026
Threats

Phishing in 2026: The QR Code, the Text Message and the Login Page That Steals Your Session

Phishing attacks on small business now arrive by QR code, text and phone call, and the fake login page steals your session, not just your password.

Sam Khan6 min readSeptember 2, 2026
The data you hold

PII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export

PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.

Sam Khan6 min readSeptember 2, 2026
Threats

Ransomware in a Clinic: What Nine Days Without the EHR Really Looks Like

Healthcare ransomware stops refills, referrals and the front desk, not just files. What nine days of EHR downtime looks like, and how a small practice prepares.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
Threats

Remote Desktop Security: RDP, VPN and RMM Are the New Front Door, and It Is Usually Unlocked

Remote desktop security in 2026 is about three doors: RDP, the VPN box and the RMM tool. How attackers find them in days, and how to lock each one this week.

Sam Khan6 min readSeptember 2, 2026
US compliance

SEC Regulation S-P for the Small RIA: 30 Days to Tell Clients, and a Program to Prove You Could

Regulation S-P amendments reached smaller advisers on 3 June 2026: incident response program, 30-day client notice and vendor oversight. What the exam asks.

Sam Khan6 min readSeptember 2, 2026
Practical controls

Security Awareness Training for a Small Business: Why the Report Button Beats the Delete Key

Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.

Sam Khan6 min readSeptember 2, 2026
AI and new risks

Shadow AI: Your Staff Are Already Pasting Client Data Into Chatbots. Here Is the Policy.

Shadow AI is already in your business: what the 2026 breach data says about unapproved chatbots, and the one-page AI acceptable use policy that fixes it.

Sam Khan6 min readSeptember 2, 2026
US compliance

SOC 2 for a 20-Person Company: Type 1, Type 2, the Cost, and When You Actually Need It

SOC 2 for small business, explained plainly: Type 1 vs Type 2, what drives the cost, who really needs a report, and how a founder loses a deal without one.

Sam Khan6 min readSeptember 2, 2026
The data you hold

Source Code and Secrets: The API Key in the Repo Is the Whole Company

Source code security for a small software team: why the API key in the repo is the whole business, the first hour after a leak, and how to stop the next one.

Sam Khan6 min readSeptember 2, 2026
US compliance

State Privacy Laws in 2026: Which of the 20 Actually Apply to a Business Your Size

State privacy laws 2026: 20 are in force, three started in January, and Texas has no consumer-count threshold. How to tell which ones apply to your business.

Sam Khan6 min readSeptember 2, 2026
Reputation and business risk

The Enterprise Security Questionnaire: How to Answer 212 Questions Without Lying or Losing the Deal

How to answer a security questionnaire from a big customer without lying or losing the deal: the 212-question workbook, what 'yes' commits you to, a method.

Sam Khan6 min readSeptember 2, 2026
Threats

The First 72 Hours of a Ransomware Attack on a Small Business, Hour by Hour

What a ransomware attack on a small business looks like in the first 72 hours, what the 2026 numbers say about paying, and five moves that decide recovery.

Sam Khan6 min readSeptember 2, 2026
US compliance

The HIPAA Risk Analysis: What OCR Actually Fined Practices For in 2025 and 2026

A HIPAA risk analysis is the document OCR asks for first. What it is, why annual training does not count, and how a small practice writes one that holds up.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
US compliance

The HIPAA Security Rule Update Is Still a Proposal. The MFA Clock Is Not.

The HIPAA Security Rule update 2026 is still a proposal, with finalization projected for July 2027. Why MFA and encryption cannot wait for the final text.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
Practical controls

The One-Page Incident Response Plan a 25-Person Company Can Actually Follow

An incident response plan for a small business on one page: who calls whom in the first hour, the regulator clocks, and what to do when your IT provider is hit.

Sam Khan6 min readSeptember 2, 2026
Reputation and business risk

What a Breach Really Costs a 30-Person Business (It Is Not the USD 4.99 Million Headline)

The cost of a data breach, small business edition: not the USD 4.99 million headline but eleven days of lost closings, a bank that drops you, and payroll.

Sam Khan6 min readSeptember 2, 2026
Reputation and business risk

What a Cybersecurity Risk Assessment Actually Checks (and What a Free Scan Does Not)

What a cybersecurity risk assessment checks, what it costs for a company under 50 people, and why three free scans left a law firm unable to answer a client.

Sam Khan6 min readSeptember 2, 2026
The data you hold

Where PHI Hides in a Small Practice: 14 Places Nobody Thinks to Check

What is PHI, and where does it live in a small practice? Fourteen places patient data hides outside the practice-management system, and how to find them.

Dr. Kashmala Khalid6 min readSeptember 2, 2026
Threats

Your Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review

A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.

Sam Khan6 min readSeptember 2, 2026

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.