top of page
Small Business IT Insights & Resources
Explore practical articles on cybersecurity, Microsoft 365, compliance, AI governance, and technology planning for small businesses.
Search


CMMC Level 1 Requirements: All 15 Explained in Plain English
In my last article, I talked about a landscaping client who unexpectedly ran into CMMC while working on a bid. They were asked whether their company was CMMC Level 1, Level 2 or Level 3, and they had no idea how to answer the question. Once a small business figures out that CMMC Level 1 may apply, the next question is usually pretty straightforward. What do I actually have to do? CMMC Level 1 has 15 cybersecurity requirements. On paper, that sounds manageable, especially when

Shay
Aug 1415 min read


Microsoft 365 HIPAA Compliance: What Does a Small Medical Practice Actually Need?
I have worked with small healthcare organizations that believed they were HIPAA compliant because they were using Microsoft 365. I understand how they got there. Microsoft talks about HIPAA, provides a Business Associate Agreement for covered services and offers security tools that can be used to protect electronic protected health information, commonly called ePHI. If you are a small practice owner who depends on an outside IT company to manage all of this for you, it is rea

Shay
Aug 1312 min read


CMMC Level 1 for Small Businesses: What Do I Actually Need to Do?
If you own a small business that currently performs work for the Department of War (DoW), or you are considering bidding on DoW contracts for the first time, CMMC Level 1 is something worth understanding before an opportunity lands in front of you. I have seen how quickly this can come up. A client of mine was working on a bid when they came across a question asking for their CMMC level. They own a landscaping company and had never had a reason to think about CMMC before. Now

Shay
Aug 1215 min read


FCI vs. CUI: What Small Government Contractors Actually Need to Know
CMMC can show up on a bid even if you have never thought of your business as a government contractor. I recently had this happen to a small business client who was asked whether they were CMMC Level 1, 2 or 3 and had no idea what the question meant. In this article, I explain FCI, CUI and CMMC in plain language, with examples that make sense for small businesses.

Shay
Aug 1212 min read


CMMC Level 1 for Small Businesses: What One Landscaping Company Learned
What does CMMC Level 1 actually look like for a small business? See how one landscaping company strengthened Microsoft 365, identity, endpoints and security while building a better foundation for future government work.

Shay
May 2913 min read


CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2
Small government contractors working toward CMMC Level 1 or Level 2 still have to turn cybersecurity requirements into technical controls that actually work. I explain how I approach CMMC technical implementation at SNL-Tech Services, from understanding the existing IT environment and hardening servers, Active Directory and networks to protecting CUI, documenting the environment and maintaining those controls over time.

Shay
May 118 min read


HIPAA Compliance for Law Firms: What Your Practice Needs to Know
Does HIPAA apply to your law firm just because you handle medical records? Not necessarily. I explain when HIPAA may apply to a law firm, what that means for your technology, and what I discovered during an IT Baseline Assessment that uncovered problems with backups, shared accounts, Microsoft 365 security, access controls, and documentation.

Shay
Apr 1720 min read


Microsoft 365 for Small DoD Contractors: What CMMC Level 2 Actually Changes
Updated August 2026: I originally wrote about this client after helping a small defense contractor deal with a compromised Microsoft 365 email account. Since then, what started as an email security problem has become a much larger conversation about Microsoft 365 for small DoD contractors, CUI, and what CMMC Level 2 actually changes in the technology environment. The company handles Controlled Unclassified Information, or CUI, which means the conversation has expanded well be

Shay
Apr 828 min read


From Outdated IT to HIPAA Readiness: HIPAA Compliance for Small Business
A healthcare business came to me needing to address HIPAA requirements and CARF accreditation, but first we had to understand where their technology stood. This real client story covers the IT Baseline Assessment, security improvements, cloud transition, incident response planning, and how those changes helped the business stay operational when a severe storm later damaged its office and IT equipment.

Shay
Apr 17, 202520 min read
bottom of page
