Category
AI & TechnologyUpdated October 2026 to our current guidance. The original reporting date is unchanged.
Has anyone asked you to prove your security lately: an insurer, a client, an auditor? The new rules ask the same thing in writing. Here is what they check, three things you can do today, and a way to count what is on your own computers.
Count What’s on Your Computers →See how many programs each Windows PC has, how many are current, and how many need updating. No credit card needed.
In this article
Hey folks! Most small businesses I talk to have a setup they trust. Someone handles the computers. Updates run. There is antivirus on every machine. For years nobody outside the company asked to see any of it, and that worked fine.
That is changing, and mostly it is not a regulator doing the asking. It is the customer. Since November 10, 2025, the federal rule called CMMC has been part of defense contracts, so a company that wants defense work, or wants to supply someone who does, has to show certification to win the bid. The bigger company up the chain asks, and the smaller one either has the answer or loses the work.
Healthcare may follow. On January 6, 2025, regulators proposed an update to the HIPAA Security Rule that would require the same basics, encryption, a second login step, and a regular scan for known weak spots, of anyone who holds medical records. It is a proposal, not law yet. Insurers and large customers are already asking for much the same list on their own questionnaires.
Strip away the acronyms and CMMC is a checklist with three levels. Most businesses that touch it land in the middle one. An assessor sits down with you and walks through it, and the questions are plainer than you would think. A customer’s security questionnaire asks most of the same ones:
• Can you show a list of every computer and program you run?
• Is the sensitive data encrypted, on the laptops and in the cloud?
• Is a second sign-in step turned on for email and remote access?
• Do you install security updates on a schedule, and can you show when?
• Do you scan your systems for known weak spots, and how often?
• If something goes wrong, is there a written plan, and has anyone read it?
Here is the part that catches owners. Doing these things is only half of it. You also have to show that you do them, with records. Plenty of businesses already do half this list and have nothing written down, so on paper they look like they do none of it. The proposed HIPAA update leans the same way: an up-to-date inventory of your systems, encryption, a second sign-in step, and a vulnerability scan at least twice a year.
Read that list again. Underneath it sits one habit: know what you have, and know whether it is current. The inventory, the updates, and the scan are the same question asked three ways.
This is also the part that keeps a business running. A machine shop does not lose sleep over a questionnaire. It worries about not shipping on Friday because the computer that runs the job schedule is down. The programs nobody has looked at in a while are usually the ones on that computer.
There is one boundary most owners have never had pointed out. Windows Update never touches third-party software. It keeps Windows current. It does not update the PDF reader, the accounting add-on, or the old program you forgot was there. A Mac works the same way: its built-in updater covers Apple’s own software. Nobody did anything wrong. That is simply where the updater’s job ends. So who has been checking the rest?
You do not need a consultant to start. None of these costs anything, and they are the floor everything else is built on.
Make the list, every computer and every program. It is the first thing an assessor asks for, it is on nearly every customer questionnaire, and most owners cannot produce it on the spot. Everything else on the checklist starts from this list.
A second sign-in step on email. Encryption, which is built into both Windows and Mac and only has to be switched on. Automatic updates. The note that says when you did each one is what you will hand over when someone asks.
Checking for known weak spots is the step nearly everyone skips, and it is the one every one of these lists comes back to. It is hard to do by eye, because the programs that matter are the ones you forgot were installed.
Feeling behind on this is normal. Everyone I talk to who runs a shop this size assumed the computers were handled, and mostly they were. What nobody had done was count.
I have spent 35+ years in cybersecurity. FBI InfraGard trainer. Dozens of managed clients since 1991. None has had ransomware. When I do see trouble, it almost always starts with a program nobody updated, the same kind of forgotten software these rules are written about.
Steps one and two are yours to do today. Step three is the one the Reveal Scan does for you on each Windows PC.
Before you run it, guess how many programs are on one of your computers and write the number down. Then run the scan. It counts what is installed and tells you how many programs are current and how many need updating. Most people I ask are off by a factor of three.
If the second number is higher than you expected, that is common. You don’t have to be able to do this. We’ll do it with you.
And if a customer or an insurer wants a dated, reviewed record every month rather than a one-time count, that is what Second Opinion: Reviewed is for: up to 100 computers, from $4,500 a year. See how it works.
Because the rules travel through contracts. If you sell to a company bigger than you, its own customers and insurers are asking it these questions, and it passes them down to its suppliers on a questionnaire. Who’s your biggest customer, and how much bigger than you are they? That is usually where the first questionnaire comes from.
The questions are the same whether a rule applies to you or not, and the answer starts with knowing what is on your computers.
The Reveal Scan counts what is installed on each Windows PC: how many programs are current and how many need updating. Read-only, no credit card needed. It is the first line of the answer when someone asks you to show your security.
Count What’s on Your Computers →The scan is on us. If you want step-by-step instructions afterward, that’s a paid report, and you’ll see the price before you decide.
If you run it and never speak to us again, that’s a fine outcome.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
Join the owners who get Craig's Insider Notes every week.