Cybersecurity and Data Protection Assessment (CDPA)
Find out what would actually hurt, and fix that first.
The same key security controls every time, scoped from what your kind of business stands to lose: the drawings, the client list, the card terminals, the patient records, the closing wire. An engineer looks from the inside, tests what matters, and hands you a ranked plan in plain English with a fixed fee for the fixes.
Scoped for your business
Pick your industry. This is what we look at.
Cybersecurity and Data Protection Assessment for Healthcare
Built on the CIS Controls v8.1 IG1 and the HIPAA Security Rule, scoped from what a practice stands to lose: patient records, the schedule and the license. The output is the risk analysis OCR asks for first, the safeguards set up rather than recommended, and a plan an owner can read in ten minutes.
- HIPAA security risk analysis documented to the HHS guidance, naming every system, vendor and business associate (CIS Controls 1, 2 and 15)
- On-site engineer visit in major cities to set up the critical controls (MFA, encryption, email and endpoint protection, backups) and install the protection agent
- Account audit: shared front-desk logins, ex-staff access, MFA on the EHR, email and the patient portal (CIS Controls 5 and 6)
- Backup and restore test for the EHR extract, imaging and practice-management data (CIS Control 11)
- Vendor and BAA review for billing, imaging, transcription and IT providers, with access limits set (CIS Control 15)
- Breach response plan rehearsed with the practice, plus a ranked remediation plan and a cyber health score
What you hold, and why someone wants it
Worth more than card data on the criminal market and the trigger for OCR, the state and your license. Encryption, access limits, MFA and a current risk analysis protect them.
The door for the fake vendor invoice and the diverted insurance payment. Email protection, MFA and monitoring protect them.
Unencrypted devices and an unpatched server are the two findings OCR sees most. Encryption, patching and offline backups protect them.
Billing, transcription, imaging and IT vendors with access to patient data; a third of healthcare breaches start there. BAAs, access review and monitoring protect you.
Copays and balances under PCI DSS v4.0.1. Segmented terminals and hardened payment pages protect them.
How it runs
Four steps. No consulting army.
Locations, people, systems, what you hold. You get a fixed fee on the call, never a surprise after.
We inventory what you own, test what matters (backups, MFA, the terminals, the file share), interview the people who run it, and check the cloud apps.
A cyber health score, the top gaps in plain English with the statistic that says why each one matters, quick wins separated from projects, and what it costs to close them.
Our team implements the controls at a reasonable rate, from DLP to scanning to protection of the assets, or your IT provider does with our plan. Then Protect keeps it that way.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Governance, Risk and Compliance (GRC), simplified
The discipline the largest institutions run, sized for a business that cannot hire a department for it.
Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.
Governance
Who owns security, which policies are real, and what the owner signs. One page, not a binder.
Risk
What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.
Compliance
The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.
A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.
Questions owners ask
What is a Cybersecurity and Data Protection Assessment?
We have no regulator. Why would we need this?
How is it different from a free scan?
What does it cost?
Never too big or too small