The New Cybersecurity Rules: Do You Know What's Open on Your Machines?
The boring security basics just became mandatory, and an auditor's first question is whether you even know what's open on your computers. Here is exactly what they check, three things you can do today, and an hour with me to walk you through the rest.
Save My Seat →Thursday, July 9, 2 PM ET. No charge, no pitch.
The problem: For a growing list of businesses, patching, second logins, and security scans just went from "should do" to "must do", and the first thing an auditor asks is whether you even know what is open on your machines. The hardest part is the not-knowing, because you can't comply with what you can't see.
The solution: You do not have to figure it out alone, and most of it is plainer than the acronyms make it sound. By the end of this you will know what an assessor actually checks, you will have three things you can do today, and you will see the one habit every one of these rules is really after.
In this article
What just changed
For years, the dull security steps were things you were supposed to do. Patch your software. Turn on a second login. Scan for weak spots. Easy to put off, and most folks did. That free pass is closing.
Since last November, any company that does defense work falls under a federal rule called CMMC, and the certification is now mandatory. It is already showing up as a flat requirement to win contracts, no certificate, no bid. Healthcare looks to be next: regulators have proposed making the same basics, encryption, a second login, and a regular vulnerability scan, mandatory for anyone who holds medical records. That one is a proposal, not law yet, but the direction could not be plainer, and your business insurer is reading the same tea leaves.
What an auditor actually checks
Strip away the acronyms and CMMC is a checklist with three levels. Most businesses that touch this land in the middle one. An assessor sits down with you and walks through it, and the questions are plainer than you would think:
• Can you show a list of every computer and program you run?
• Is the sensitive data encrypted, on the laptops and in the cloud?
• Is a second login turned on for email and remote access?
• Do you install security updates on a schedule, and can you prove it?
• Do you scan your systems for known weak spots, and how often?
• If something goes wrong, is there a written plan, and has anyone actually read it?
Here is the part that trips owners up. It is not enough to do these things. You have to prove you do them, with records. Plenty of businesses are already doing half this list and have nothing written down to show for it, so on paper they look like they are doing nothing. The proposed healthcare rule leans the same way: an up-to-date inventory of your systems, encryption, a second login, and a vulnerability scan at least twice a year.
The one thing every rule circles
Read that list again and notice what sits underneath all of it: know what you have, and find what is open, before someone else does. The inventory, the patching, the scan, it is really one habit wearing different hats. You cannot comply with what you cannot see.
And the timing is no accident in spirit. The same season the rule-makers started requiring the basics, an AI got so good at finding flaws in software that the government put it on the kind of leash we usually save for weapons. The holes it turns up are not exotic. Some sat open in trusted software for seventeen and twenty-seven years. Let me be straight with you, because I will not sell you a story: no agency has said it wrote these rules because of any one AI. That is my read, not theirs. But when finding your open doors drops from a skilled crook's hard work to a machine's afternoon, "we'll get to it" stops being good enough.
And do not assume a Mac sits this one out. Apple built macOS on the same BSD foundation where some of those decades-old holes were found, so "Macs don't get hacked" was always a myth. Windows or Mac, every machine is full of programs nobody patches, and the built-in updater only ever covers the maker's own software. The PDF reader, the accounting add-on, the old app you forgot you had, those quietly go unpatched, and every one is a door an auditor and a criminal both care about.
Three things you can do today
You do not need a consultant to start, and you do not need to wait for me. Three steps, all free, all the foundation everything else is built on.
1. Count your machines and software.
Make the list, every computer, every program. It is the first thing an auditor asks for and the first thing most owners cannot produce. You cannot protect, or prove, what you have never counted, so this one step is the floor the whole checklist stands on.
2. Turn the basics on, and write down that you did.
A second login on email. Encryption, which is built into both Windows and Mac and just has to be switched on. Automatic updates. None of this costs a dime, and the part that satisfies a rule is the note that says when you did it. Doing it quietly is not the same as being able to prove it.
3. Get an honest look at what is open.
A scan for known weak spots is the one step nearly everyone skips, and it is the exact thing every one of these rules circles. It is also the one that is hard to do well by eye, because the dangerous doors are the ones you forgot were there.
Do the first two today and you have built the floor. The third, seeing what is actually open on your own machines, is the piece I will walk you through live.
You shouldn't need a security degree to keep your own business safe.
You started a business to serve your customers, not to become a compliance department. Feeling behind on this is normal, and it is not a personal failing.
I have spent more than thirty-five years watching how these attacks work. FBI InfraGard, zero ransomware on any client I have worked with. And when one of them does get in, it is almost always through an app nobody updated, the same kind of forgotten door the new rules are written about. The good news is that seeing your open doors is simple once someone shows you how, and that part I made easy.
The part you can't see yourself
The first two steps are yours to do today. Finding the open doors, the third step and the one every rule circles, is what I will walk you through, live, in plain English. No guesswork about how it works, here are the three steps.
My promise to you
✅ No charge, and nothing to buy on the call.
✅ It is not a pitch-fest. You will leave with real steps whether or not you ever buy a thing.
✅ Plain English. No jargon, and no talking down to you.
✅ Come live if you can, that is where I answer your questions. Saved a seat but can't make it? I'll send you the replay.
✅ If your setup is in good shape, I will tell you so. No scare tactics.
✅ Straight talk. I will show you what is "open" and "at risk," never "guaranteed."
"I'm not a defense contractor or a hospital. Why does this matter to me?"
Two reasons. First, these rules are the canary. What is required for regulated work today tends to become the baseline everyone is judged by tomorrow, including your insurer at renewal time. Second, the criminals do not check whether you are in scope before they knock. The open doors are the same on every business computer.
An hour now saves a scramble later. And if your machines are already in good shape, you will walk away knowing it.
Come see your open doors, live
You can't comply with what you can't see, and you don't have to see it alone. Spend one hour with me and walk away with a short list you can hand to your team, and with the quiet confidence of the owner who can answer "do you know what's open?" with a flat yes. The next audit, or the next 2 a.m. worry, stops being a knot in your stomach and becomes a box you already checked.
Save My Seat →Thursday, July 9, 2 PM ET. No charge, no pitch.
Want this kind of plain-English security news every week? Sign up for Craig's Insider Notes at CraigPeterson.com.