Real gaps: the 90-day plan that closes them
Score 13 to 25, no incident reported
Nothing in your answers says you are in trouble today. Several of the things that decide how bad an incident gets are missing or untested, and at least one outside party is likely to start asking questions — an insurer at renewal, a client's security questionnaire, or a regulator. This is the stage where the work is cheap and calm. Ninety days from now, done properly, you are in a different category.
You are in the majority. Most firms your size sit here — enough in place to feel fine, not enough to survive a bad week or answer a serious questionnaire.
The risk at this stage is not catastrophe, it is being forced into fast decisions by someone else's deadline: a client contract, an insurance renewal, a compliance requirement that arrives with 30 days' notice.
Almost everything in the first month below is free and takes hours, not weeks. The paid work is narrow and worth scoping precisely, which is what the diagnostic conversation is for.
Your 90 days, in order
- 1
Name an owner and put an hour a week on the calendar
Not a title change — a named person with a recurring hour and a short written list of what they check: new accounts, departed staff, failed logins, backup results, vendor access. Firms without this drift back within a quarter no matter what else they fix.
Week one You can do this yourself - 2
Make multi-factor login mandatory, not optional
Enforce it on email, remote access, banking, payroll, and any system holding customer or patient data. 'Enabled but not required' is the same as off for the account that gets targeted. Authenticator apps beat SMS.
Weeks one to two You can do this yourself - 3
Test a restore, not a backup
Choose a realistic file set, restore it to a separate location, time how long it took, and write the result down. Then confirm at least one backup copy is offline or otherwise out of reach of the credentials that run your day-to-day systems.
Weeks two to three You can do this yourself - 4
Build the vendor list you don't have
One spreadsheet: every outside party that can reach your systems or data, what they can reach, who owns the relationship, and when access was last reviewed. A large share of breaches now arrive through a supplier's credentials, and every serious questionnaire asks for this list.
Weeks three to five You can do this yourself - 5
Write a one-page AI and data-handling rule
Which AI tools are approved, what may never be pasted into them (client records, patient data, credentials, unreleased financials), and who to ask when unsure. One page that people read beats a policy nobody opens. Data pasted into a public model is disclosure you cannot claw back.
Week five You can do this yourself - 6
Remove access for everyone who left
Walk the list of departures for the past two years against every system, including the ones IT does not manage: the shared cloud drive, the billing portal, the marketing tools, the shared password vault. Then write the offboarding checklist so this is a five-minute task in future.
Weeks five to six You can do this yourself - 7
Get a scoped risk assessment, not a product pitch
This is the point where outside eyes pay for themselves: a specialist tells you which of your remaining gaps actually matter for your data, your industry, and your obligations — and which you can safely ignore. Insist the deliverable is a prioritised list you own, not a proposal for a platform.
Weeks six to nine Specialist help pays off here - 8
Rehearse the bad morning once
Sit five people in a room for an hour: everything is locked, it is 8am, go. Who calls whom, who talks to clients, where the phone numbers live if email is down, who can authorise spending. The first four hours of an incident decide most of the cost, and rehearsal is the cheapest way to buy those hours back.
Weeks nine to twelve Specialist help pays off here - 9
Read your insurance conditions before renewal
Find out what the policy requires of you — MFA, backups, training, incident notification windows — and confirm you meet each one in writing. Claims are routinely reduced over unmet conditions the insured never knew existed.
Before renewal You can do this yourself
What not to spend money on yet
- Do not buy a security platform before you know which gap it closes. Tooling bought at this stage is usually shelfware within a year.
- Do not start a formal certification (SOC 2, HITRUST) because it sounds impressive. Start one when a specific deal or requirement demands it, and scope it to that.
- Do not commission a penetration test as your first paid engagement. Without the basics fixed, you pay to be told what you already suspect.
- Do not accept a security review whose deliverable is a proposal. The deliverable should be a prioritised list you keep whether or not you hire the reviewer.
What this usually costs
- Everything in the first five weeks above is free apart from your team's time — typically 10 to 20 hours in total.
- Independent consultants commonly bill $150-$400 per hour for the scoped work.
- A focused risk assessment or HIPAA-style gap analysis for a small firm commonly runs from several thousand dollars up, depending on size and systems.
- The diagnostic meeting through us is free to your firm — specialists cover the cost — so you can scope the paid work before committing to any of it.
Questions to ask any specialist you talk to
- Given my industry and the data I hold, which three gaps would you close first and why?
- What is the deliverable, and do I keep it if I don't hire you for the follow-on work?
- What can my own team do, and where does paying you actually change the outcome?
- Have you taken a firm my size through this, and what did it cost end to end?
- What would you tell me to ignore?
Turn this list into a prioritised plan
Bring what the self-check flagged. We match you within 24 hours with a vetted specialist who works with firms your size, and the first meeting is free to your firm. Free for your firm — specialists cover the cost.
Book Your Free MeetingCommon questions
Can I just do all of this myself?
Most of the first five weeks, yes — and you should. The part that genuinely needs a specialist is deciding which remaining gaps matter for your specific data and obligations, and what you can safely leave alone. That judgement is what the free meeting is for.
How do I know if my IT provider is already covering this?
Ask them for three things in writing: the date of the last tested restore, the list of vendors with access to your systems, and the accounts that still have admin rights. If those take more than a few days to produce, they are not being covered.
A client sent a security questionnaire. Where do I start?
Answer honestly, note what is in progress with a date, and never claim a control you do not have — a discovered false answer costs far more than a gap disclosed up front. The vendor list and MFA enforcement above answer a surprising share of most questionnaires.
What does the free meeting actually cover?
A working conversation about what you flagged, which gaps matter for your industry, roughly what the paid work would cost if you pursue it, and what you should do next regardless. Free to your firm — specialists cover the cost.
This page is general guidance, not legal advice. If regulated data such as health or payment records may be involved, confirm your notification obligations with qualified counsel.