Phone 202 839-5563 


Cybersecurity and data protection are now national security issues impacting all U.S. businesses, no matter the size. China and other nation-states, as well as organized and disorganized criminals, are stealing intellectual capital, personal and business information, and creating havoc in business environments. No one is immune, and approximately 60% of small businesses that are hacked never recover. It is time to take this seriously and protect everything valuable to us and our nation. We are at war, act like it.

Cybersecurity Maturity Model Certification CMMC V1.0 Available

IMPORTANT:  As you consider assessing aganist this for certification know it is important to protect all the information (artifacts) associated with your assessment.  Limit who can have access to this information and have secure controls associated with this information.

We recommend FedRAMP hosted software and have recommendations.  

Please contact us for advice.

or call (seven zero three) 989-8777

Cyber and Data Breach Liability Insurance: Protecting Small Businesses and Our Nation


White Paper on the Value of Cyber and Data Liability Insurance for Small Businesses

This document is for small and mid-sized businesses who are considering acquiring “cyber and data breach liability insurance” to protect themselves against the increasing velocity and complexity of cyber and data breach attacks.

There is a appendix for the CMMC

It is also for larger businesses and governments to help them understand the value of the insurance for their contractors and extended supply chain members.

Some may wish to require subcontractors and suppliers to have proper Insurance in place, as a stipulation to providing goods or services to them. The paper is in the CMMC section.

Please provide feedback associated with this living document!

This white paper is a living document.
We are looking for germane contributions associated with the following topics contained in the body of work. .

  • What is Cyber and Data Breach Liability Insurance
  • What to Look for in an Offering
  • Suggested Requirements
  • Examples of Underwriting Questions
  • Sample Requirements for Contracts
  • Value to the Cybersecurity Model Certification (CMMC)

We would also like to hear of new topics associated with insurance.

Please send comments to 

A special Cybersecurity and Data Liability Insurance policy is available for small businesses Here ->

ASBDC Cybersecurity First Steps

 Cybersecurity First Steps is available here:

Small businesses are under cyber and data-breach attacks by nation-states, as well as organized and disorganized criminals, who are stealing intellectual capital, personal and business information, and creating havoc in business environments.

60% of small businesses that are hacked never recover.

The ASBDC is pleased to offer Cybersecurity First Steps, an online questionnaire to help you understand how to protect your company from cyber threats. 

A secure environment is used to protect  information while providing a consistent, standards-based way for you to learn good practices associated with cybersecurity and data protection.

It’s OK for you not to know all the answers to the questions in First Steps. It is more important for you to know what you don’t know. The information gathered is only accessible to you, but you may permit others to view the information for help, including local Small Business Development Center advisors.

In-line advice is provided with the questionnaire to help answer questions, and a report is prepared to help you understand what you can do to protect your business eco-system.

 It is critical to take the highest precautions to protect client sensitive information associated with cybersecurity and potential data breach information like this. For this reason, we are using a software tool located on a FedRAMP certified secure cloud platform. The Small Business Administration is the sponsor for the “high certification” evaluation of the application used.

Katie Arrington’s CMMC slide deck can be found here:

The Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)) recognizes that security is foundational to acquisition and should not be traded along with cost, schedule, and performance moving forward. The Department is committed to working with the Defense Industrial Base (DIB) sector to enhance the protection of controlled unclassified information (CUI) within the supply chain.

OUSD(A&S) is working with DoD stakeholders, University Affiliated Research Centers (UARCs), Federally Funded Research and Development Centers (FFRDC), and industry to develop the Cybersecurity Maturity Model Certification (CMMC).

Cybersecurity Maturity Model Certification

  • The CMMC will review and combine various cybersecurity standards and best practices and map these controls and processes across several maturity levels that range from basic cyber hygiene to advanced. For a given CMMC level, the associated controls and processes, when implemented, will reduce risk against a specific set of cyber threats.
  • The CMMC effort builds upon existing regulation (DFARS 252.204-7012) that is based on trust by adding a verification component with respect to cybersecurity requirements.
  • The goal is for CMMC to be cost-effective and affordable for small businesses to implement at the lower CMMC levels.
  • The intent is for certified independent 3rd party organizations to conduct audits and inform risk.

Large Organizations are Small Organizations Too

Large public and private organizations are comprised of big, medium and small organizational components. Sharing a common understanding and unified messaging is critical to delivering business/mission value and security. 

Small and mid-size businesses are the largest group of employers. Thinking of large organizations separately from this group ignores very important opportunities to increase business value and security because they are all connected and interdependent.

RightExposure helps small businesses and large businesses

DHS Releases Cyber Essentials for Businesses

The guide covers 6 actionable items that assist in reducing cyber risks:

  • Yourself: Drive cybersecurity strategy, investment, and culture;
  • Your Staff: Develop a heightened level of security awareness and vigilance;
  • Your Systems: Protect critical assets and applications;
  • Your Surroundings: Ensure only those who belong on your digital workplace have access;
  • Your Data: Make backups and avoid loss of info critical to operations; and
  • Your Actions Under Stress: Limit damage and restore normal operations quickly.

FTC Guidance for Cyber

The Federal Trade Commission easy to follow guidance for small businesses. 
 The FTC is going to update and release new guidance Oct 18th.

Is Your Business Prepared for an Emergency?
Is Your Data?

When an emergency strikes, your business’s most vulnerable asset may not be in the stockroom or warehouse. It could be the data that has been central to your success.  The FTC has six steps you can take to help protect your company’s information from the unpredictable.  

Secure Paper, Physical Media, and Devices

federal trade commission

High-profile hackers grab the headlines. But some data thieves prefer old school methods – rifling through file cabinets, pinching paperwork, and pilfering devices like smartphones and flash drives. As your business bolsters the security of your network, don’t let that take attention away from how you secure documents and devices.

FTC law enforcement actions, closed investigations, and experiences we’ve heard from businesses demonstrate the wisdom of adopting a 360° approach to protecting confidential data. As Start with Security suggests, securing paper, physical media, and devices is an important part of that strategy.

NIST 800-171 Controlled Unclassified Information

The protection of Controlled Unclassified Information (CUI) resident in non-federal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully conduct its assigned missions and business operations.

NIST releases 1.1 Roadmap to the NIST Cybersecurity Framework

Product or service to help  Business Risk Management including Cybersecurity

Federal Communications Commission on Reasonableness

By clarifying that our standard is one of “reasonableness” rather than strict liability, we address one of the major concerns that providers—including small providers and their associations—raise in this proceeding.

Mitre Releases Supply Chain Guidance for DoD

“Deliver Uncompromised”

cybersecurity first steps
Small Business? Get help!

"If we guard our toothbrushes and diamonds with equal zeal, we will lose fewer toothbrushes and more diamonds."

"It is super invigorating to work with team members who have a singular focus which is driving greater value through greater product and capability out to the business." para phrasing his the rest of his comments: 'no body wants to do cyber or tech for the sake of tech. They want to solve a problem, that is real invigorating."

David Shive, CIO General Services Administration Tweet

“If you’re asking me if I think we’re at war, I think I’d say yes”…We’re at war right now in cyberspace. We’ve been at war for maybe a decade. They’re pouring oil over the castle walls every day.”

Gen Robert Neller, Commandant, USMC Tweet

Contact Us

Phone 202 839-5563 – – email

Cyber liability and Data Breach Consulting

About us

Phasellus sodal dictum dolor quis fringilla. Nunc accumsan velit sit amet enim maximus solsodales.

Our mission

Help small businesses understand t

Our offer

  • sed accumsan enim rutrum
  • Etiam fringilla lobortis
  • Aenean iaculis magna