SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

Who is Ron?

I'm just an ordinary, average guy, who has worked for many different types of businesses, doing the actual work, and not only information security. That helps me help you find a balance. I have a very strong business acumen. I know where the money comes from that your business needs to survive, and I know that information security is an expense that we hope will save more of your business's hard earned money than it costs to make it secure in the end.

In my time doing Information Security, I have found that polices, standards and specifications are often written in "Cyber-speak," phrases and acronyms that are hard to understand for even IT people. I can help explain it at whatever level you need, unless it's even over my head, and then we'll have to do some digging. I'm here to help you realize that quite often it's not worth the major fret that some cybersecurity people stoke up. Information security is meant to make your business better, not more painful to run. Cybersecurity folks should never pretend they are the police, here to arrest anyone for the slightest infraction. They are supposed to be like doctors and nurses, here to find problems, stop damage and offer possible solutions. You decide if you can afford the therapy, the prescriptions and if you want the side effects.

What is my Information Technology Experience?

I've been a data equipment reseller, a network admin, a network security engineer, and a risk analyst for over 25 year. I've worked for small and very large companies, including those in critical infrastructure, financial, healthcare and manufacturing, helping folks figure out just how secure they need to be without emptying their bank account. Now, after all the years doing that, I want to share my aquired knowledge to explain that not all businesses need to worry about their information security as much as others. They can be quite custom with the way they do things, and that's all totally cool with NIST CSF, the holy grail of cybersecurity for United States based businesses. If they need to be totally rock solid and allow nothing to get by, and they have the budget for that, that's fine. If they need a more measured approach, that's fine for them, too.

Most people who talk to me enjoy the experience. I teach. I don't preach. I help. I don't ridicule. I keep things private. I also can help you with your documentation, which seems to be a skill in short supply, sometimes. Remember that if you don't write down your plans, your rules, your standards, your policies and procedures, they are only wishes.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your information (don't say cyber) security.