4 min read
Employee Security Awareness Training Explained
In today’s digital age, ensuring that your employees are well-versed in IT security is more crucial than ever. Employee security awareness...
6 min read
Andrew Eckstrom : Updated on June 4, 2026
Do a light quarterly refresh (progress, risks, budget), and a deeper annual reset after your fiscal planning and risk assessment.
For SMBs, NIST CSF is a great backbone (govern/identify/protect/detect/respond/recover). You can map ISO 27001, HIPAA, CMMC, PCI, or SOC 2 requirements onto it.
Budget to your risk and growth goals—not a generic number. Typical SMBs fund identity/MFA, device health, backups, monitoring, training, and one or two “big rocks” per quarter (e.g., SSO rollout, backup modernization, Zero Trust micro-segmentation).
Publish an approved app catalog, provide fast request/approval, and run continuous discovery. Pair with SSO/MFA and data access policies (least privilege). Offer safe alternatives so teams can move quickly.
Begin with identity and device health: enforce MFA, move to SSO, require compliant devices for access, and segment one high-value system. Expand to conditional access and data controls as you mature.
Back up daily, but restore at least quarterly (more often for critical systems). Document RPO/RTO results so you’re not guessing during an incident.
Use a simple scoring model: risk reduction, business impact, regulatory requirement, effort/cost. Fund a balanced portfolio: quick wins + foundational controls + one strategic initiative each quarter.
Clear roles, severity tiers, playbooks (ransomware/BEC/data loss), comms templates, legal/insurance contacts, and a tabletop schedule. Include a one-click Report Phish path and after-action review.
SSO + MFA, compliant device checks, conditional access, encrypted endpoints, and collaboration controls. For Seattle/Everett construction/engineering, lock down jobsite data sharing; for Phoenix healthcare/finance, emphasize HIPAA/PCI alignment.
Keep it simple: approved apps, SSO/MFA, automated patch/EDR, managed backups with quarterly restores, and a short policy set people actually follow.
Treat compliance as requirements mapped to your controls, not as separate projects. Refresh evidence quarterly so audits become routine, not emergencies.
Yes—on-site or virtual in Seattle, Everett, Phoenix, and Kalispell. Many clients do an on-site kickoff, then quarterly virtual reviews.
Ready to ditch reactive IT?
Book an IT Strategy & Risk Assessment with Succurri’s vCIO team in Seattle, Everett, Phoenix, or Kalispell. We’ll map your next 90 days and set the cadence that keeps you compliant—and resilient.
Andrew leads Succurri’s vCIO practice, aligning technology plans with business goals for SMBs across construction, healthcare, financial services, engineering, and professional services. He focuses on pragmatic roadmaps, clean execution, and measurable outcomes—so IT reduces risk, boosts productivity, and supports growth.
4 min read
In today’s digital age, ensuring that your employees are well-versed in IT security is more crucial than ever. Employee security awareness...
4 min read
Audit Readiness Audit readiness isn’t a folder of policies; it’s a living system. Build a lightweight control set mapped to your framework...
3 min read
Why This List Matters When you search for best IT companies, IT managed services companies, managed it services companies, or top IT managed...