Had a breach or ransomware attack? Call 516-537-8575

A security leader for your firm, without the full-time salary.

MiTech builds and runs the security program for 20 to 200 person accounting, legal, financial and healthcare firms: the policies, the network, the compliance work, and the person accountable for all of it.

CISSPCISMCCSPCEHPMPMBA
Security leadership that sees your whole environment.
One named leadYou work with the person accountable for your program.
12-month roadmapFoundation, network, controls, then testing.
Plain-language reportingMonthly updates your partners can read in five minutes.
Written proposal firstScope and fee are agreed before any work starts.

Where does your firm stand today?

Ten controls insurers, regulators and clients ask about most. Tick what you have. Whatever is left is your gap list.

Ten-minute security check

Tick every control your firm has in place today. Be honest: this stays in your browser.

Controls in place
10 of 10 gaps
No controls confirmed yet. Start here.

Clients, insurers and regulators now ask for proof.

Regulators

The FTC Safeguards Rule requires tax and financial firms to run a written security program under a named Qualified Individual. The IRS expects the safeguards in Publication 4557.

Insurers and clients

Cyber insurance renewals and client questionnaires increasingly demand multi-factor authentication, tested backups and an incident response plan, in writing.

Nobody owns it

Most 50-person firms have an IT provider and no one accountable for risk. When something goes wrong, that gap is what gets examined.

What we take off your plate

vCISO leadership

A named senior security leader who sets the strategy, reports to the partners, and answers the insurer, the auditor and the client questionnaire.

Security program and network build

Policy framework (30 to 50 policies), network segmentation, privileged access, multi-factor authentication, monitoring and incident response, designed and implemented by us.

Compliance and audit readiness

FTC Safeguards, IRS Publication 4557, NIST alignment and SOC 2 readiness, with an annual IT security audit that produces evidence you can hand over.

Your data is the target. Controls are how you protect it.

Client files, tax returns and case records sit in cloud platforms, servers and laptops. We map where the data lives, then put identity, network, backup and monitoring controls around each place.

  • Segmented networks and secure remote access
  • Multi-factor authentication and privileged access
  • Tested, offline backups and logging
  • Incident response you have rehearsed

How an engagement works

  1. Assess

    We review your systems, data flows and obligations, then rank the gaps by real risk.

  2. Build

    We write the policies, redesign the network and deploy the missing controls.

  3. Operate

    Monthly leadership, reviews and reporting keep the program running.

  4. Improve

    An annual audit tests the controls and sets next year's priorities.

Three plans, one for each stage

Platinum

SOC 2 readiness, penetration test coordination and post-breach recovery, on top of everything in Gold and Standard.

Gold

The complete build: a full security program, network redesign and a 30 to 50 policy framework, with hands-on engineering.

Standard

Ongoing leadership and oversight for firms that already have a program in place.

Questions firms ask first

What is a vCISO?

A virtual CISO is an outsourced security executive. You get the planning, policy, risk management and compliance leadership a full-time Chief Information Security Officer provides, for a fixed annual fee instead of a full-time executive salary.

We already have an IT provider. Do we still need this?

Usually yes. Your IT provider keeps systems running. A vCISO decides what has to be protected, writes the policies, owns the risk and compliance obligations, and holds the IT provider accountable to them. We work alongside your current team.

What rules apply to an accounting firm?

Tax preparers are covered by the FTC Safeguards Rule under the Gramm-Leach-Bliley Act. It requires a written security program, a named Qualified Individual, a risk assessment, multi-factor authentication, encryption, and an incident response plan. IRS Publication 4557 sets out the practical safeguards the IRS expects.

What does it cost?

Pricing depends on your firm's size, systems and goals. Every plan is a fixed annual fee, quoted in writing after a free assessment call, and every plan includes an annual IT security audit and security training.

Can you help if we have already had a ransomware attack?

Yes. The Platinum plan includes post-breach recovery. We stabilize the environment, rebuild the controls that failed, and document the work for insurers and regulators.

Find out where your firm stands.

A 30-minute call covers your current controls, the rules that apply to you, and what a first 90 days would look like. No cost, no sales deck.