Calder & Lane
(CYBERSECURITY HARDENING)

We make security provable.

We work out the short list of protections your business actually needs, bring in the right engineers to put it in place, and make sure you hold the record that shows it. When the insurer, the bank client, or the auditor asks, you have something to show them.

(THE CALL WE GET)

I thought we had cybersecurity.

We hear it after a hack, after a few questionable bank transactions, or after a form from the insurer that nobody in the building could answer.

I feel like I was sold something that was never actually delivered.

If you are the one telling your IT provider that a backup failed, something is wrong. The same goes for a monitoring report nobody has seen and an admin password that lives in one person's head.

One factory owner wrote, in an essay published after the attack, that the criminals demanded a million dollars to give him his own business back. He had cyber insurance and backup drives the whole time, and the attackers deleted the drives.

The drives existed, and so did the policy. What was missing was a copy the attacker could not reach.

Our job is to find that kind of gap before an attacker does, bring in the engineers who close it, and make sure what they did is written down in a record you keep. The next time someone asks, you open it.

(BEFORE YOU CALL)

Yes, you are a target.

The first question is usually whether a firm your size is really a target. It is. Attackers do not pick by size. They pick whichever door opens first, and a small firm with one shared password and an untested backup is an easy door.

Here is what we hear before the first call, and what we say back.

  • We hearI don't have anything worth stealing, and the risk is not high enough to justify the cost. We say: You have a payroll, a bank login, and your customers' details. What the attackers want is your ability to work, because that is what you will pay to get back. The list that protects it is short, and the first item on it is usually already inside something you pay for, switched off.
  • We hearMy password is strong enough. We say: A fake login page steals a strong password as easily as a weak one. A second step at sign-in is what usually stops a stolen password from working.
  • We hearWe already have an IT company. We say: Keep them. We ask the questions you would not know to ask, sit in while they answer, and tell you what we heard in plain terms, without anyone losing face.
  • We hearThere are a lot of businesses out there professing to be experts. We say: Do not take anyone's word for it, ours included. Ask whoever looks after your systems to show you the last backup restore and the list of accounts with a second sign-in step. Who can and who cannot tells you most of what you need to know, and we will sit with you while you ask.
  • We hearThis whole business is a racket. All that paper exists to cover someone, and no one will read your answers. We say: Some of it is paper. We sort what a contract or a carrier requires from what keeps you working, and we tell you which is which before anyone starts.
  • We hearI am a staff of one, and we do not have a lot of funds. We say: Then the list starts at one item, and it is usually a setting inside something you already pay for, switched on by the provider you already have. You choose the next item when the first is shown working, and every write-up is yours to hand to whoever you report to.
(WHAT WE DO)

A short list, in place and shown to work.

One question comes up after every scare, in almost the same words: what do we need to prevent any issue in the future?

Our answer is the list below, and that is what cybersecurity for small business comes down to: a few things done properly, checked again, and written down.

We start with the business, not the servers: how you work, what you have now, and what your current provider says is in place. Then we bring the right engineers to the table, from more than one provider where it matters, to close the gaps in the order an attacker would try them. You choose who does the work, and we stay in the room while they do it.

Ransomware protection is mostly this list. The attack that closed a 158-year-old haulage company, as reported at the time, began with one employee's guessed password.

That is what we mean by security hardening: the list in place, each item shown to work by the people who put it there, and nothing on it you do not need.

  • Backups that are restored, not just run. A copy the attacker cannot reach, a restore the provider has shown you working, an agreed answer to how old the newest copy is allowed to be, and the date of the last restore in a record you keep.
  • A second step at sign-in (MFA) on email, banking, remote access, and every admin account, with the owners and partners first.
  • A list of who can get in. Every admin account named, every account of someone who left closed, and no password that only one person knows.
  • Updates and email filtering that run without anyone having to remember them.
  • A one-page plan for a bad day, written with you. who to call, what to switch off, where the backups are, and what to tell customers. No longer than your carrier's form requires, in words your staff could follow.
(SIGN-IN)

Sign-in protection people will keep.

The objections to a second sign-in step come in the staff's own words: it is too much of a hassle, I am not giving you my personal phone number, it slows me down, and the IT team is already overloaded. They deserve answers.

Nobody has to use a personal phone. A small hardware key, an app on a company device or a laptop, or a prompt that asks you to match a number all work, and we help you pick the one your people will tolerate before the provider turns anything on.

The order matters: owners and admins first, then one team at a time, with a one-line note on why. We agree that order with you and with the engineers doing the work before it starts. The reason is not to police anyone.

The director of that haulage company told reporters he has never named the employee whose guessed password let the attackers in. A second step at sign-in means no one on your staff can be that person.

If the method is still causing friction after the first few days, we ask the provider to change the method, not the rule. The MFA rollout is done when people stop noticing it.

(THE QUESTIONNAIRE)

Every answer true, with the evidence beside it.

The question arrives in almost the same words every time: how do we answer this honestly? Line by line, with the evidence beside each answer. The form sometimes runs to a hundred-plus questions, and the people filling it in say the same two things: it takes a lot of time, and we are too small to hire someone for this.

Most of the cyber insurance questionnaire help people ask us for comes down to that one thing. You sign the form, so you are the one on the hook if an answer is wrong, and we make sure you never have to guess at one.

  1. Send us the questionnaire, the audit letter, or the client's security checklist, exactly as it arrived.
  2. We go through it with you line by line and sort every question into three piles: true today, not true yet, and does not apply to you.
  3. For the not-yet pile, we bring in the right engineers from your provider, or from more than one, and you choose who closes each gap. Some of it is a setting inside something you already pay for, switched on.
  4. Every answer goes in true, with the evidence beside it. Any gap still open gets a dated note saying when it closes, which is an answer you can defend.
  5. You keep the file, and we keep the renewal date. Next year starts from it instead of from a blank page.
(THE PROOF)

Proof you can hand to the bank.

A law firm's bank clients can require a penetration test. Its own clients can require a yearly audit of its IT and business processes. What each needs is a document that matches what is on the machines, and a promise will not do.

So the record is the point. What is in place, who put it there, when they showed it working, the list of accounts and which have a second sign-in step, the questionnaire with the reason beside every answer, and the one-page plan, kept plain, in your systems, in your name. We keep it up to date. You own it.

If a bank client demands a penetration test, we say whether you need one, help you agree what it should cover, and bring in a tester who does that for a living. Then we read the report with you. If a client asks for SOC 2, start with what founders who have been through it say: extremely unclear how to start, and everything is reactive and expensive.

SOC 2 readiness starts from the record you already hold, then needs written policies, an observation window that runs for months, and an auditor. We help you choose the auditor and the tools, we label which parts make you safer and which are there because the contract says so, and we stay in the room until the report is signed.

Larger firms want to know what good looks like. Regulated ones put it more bluntly: they cannot afford to be out of compliance, and they cannot afford an attack. For them the record is what goes to the board, and we write it so the board can read it.

For a ten-person firm, the proof is that you can say, and show, that you were careful with your customers' information.

Here is how the trust works. We learn your business first. We compare several providers rather than one and bring their engineers to the table. You choose. You own every account and every document. We read the contract before you sign it, we track the renewal date, and the person you meet on the first call is the person who stays, and who you hear from every week.

(What usually goes wrong)

We have seen this before.

  1. Our backups are on a drive in the office. They are always a week old.
  2. Everyone knows the admin password, including two people who left.
  3. We had insurance and a backup drive. They deleted the drive first.
  4. The form said yes all the way down. Nobody checked.
  5. We pay for monitoring. We have never seen a report.
  6. The second sign-in step was too much of a hassle, so it never went on.
(Straight answers)

Questions people ask about this.

All the straight answers

We're small. Are we really a target?

Yes. Here is what you can do this week, without us: turn on a second sign-in step for the owner's email and the bank login, and ask whoever looks after your systems to restore one file from last night's backup while you watch. If either takes more than an afternoon, or nobody can find the backup, that is the thing to send us. The list that fixes it is short, and the first item on it is often a setting you already pay for.

Do I need a SIEM or SOC for my carrier?

Only if the form says so. Read the form you were sent; the questions on it are the list, and a security operations center, a SIEM, or a monitoring subscription only goes on your list when a carrier, a regulator, or a client's contract names it. If one does, we say so, bring in more than one provider who offers it, and help you choose the smallest thing that satisfies the form. If a quote you have been given goes well past what the form requires, we will say that too, and we read the contract before you sign it.

Will my premium go up if I admit gaps on the questionnaire?

We cannot promise what an insurer will charge, and anyone who does is guessing. What we can say is that a false yes is the more expensive answer. They may not check when you sign. They check when you claim, and a form that does not match what was on the machines is how a claim gets questioned. So your provider closes the quick gaps before you sign, the rest get a date, and you sign a form you can defend.

If our IT company says we're compliant and we're not, who is liable?

Your name is on the questionnaire and on the contract with the client, so the carrier and the client look to you first. Whether you can recover anything from your provider depends on your contract with them, and that is a question for your lawyer, not for us. What we can do is make sure every answer you give has the evidence beside it, so you know what is true rather than what you were told. If you want, we ask your current provider for the same evidence, with you in the room, and tell you what we make of what comes back.

My staff will hate MFA. How do you get them to accept it?

In order, and with a reason. Owners and admins go first, then one team at a time, and each group gets one sentence on why: so that nobody on your staff ends up as the person whose password let them in. We agree the order and the method with you before the provider's engineers turn anything on, and if the method your people were handed is the problem, we ask for a different method and keep the rule.

Our backups run every night. Isn't that enough?

Not until someone has restored from one while you watched. Backup testing means bringing a file, and then a whole machine, back from the copy and writing down the date it worked. We ask your provider to show you that, and the date goes in the record you keep. The copy also has to sit where an attacker cannot reach it; the factory owner in the published essay had backup drives, and the hackers deleted them. And a copy that is always a week old means a week of work gone, so we help you agree with the provider how old the newest copy may be, and we ask the question again when the contract comes up.

A client is asking for SOC 2. Do we need it?

Only if a contract or a customer requires it, and we tell you which. Founders who have been through it say it is extremely unclear how to start, that everything is reactive and expensive, and that you only realize what you should have done earlier after you have already paid. So before you commit to anyone, we lay out each part of SOC 2 readiness: the written policies, the observation window that runs for months, the auditor, and the evidence your record already holds. We bring in more than one auditor and more than one tooling provider, and you choose. Part of it is box-ticking, and it does not have to be noble to be worth doing when the deal is blocked. The parts that keep you working are the ones worth keeping afterward, and we mark which those are.

(Get a second opinion)

Send us the form that started this.

The insurance questionnaire, the letter from the bank, the audit request, or the quote for a security package nobody explained. Give it two business days. By then the person who will stay with you has read what you sent and you are on a thirty-minute call, at no charge, about which answers are true today, which gaps are quick to close, and which line items you can skip. No pitch at the end, and nobody follows up unless you ask. You will be talking to someone who asks about your business before your servers.

Get a second opinion