Information Security Services
Make the next attempt fail quietly
You have antivirus, a firewall, and a vendor who says you are covered. What you do not have is a written answer to the question of what happens on the Tuesday morning someone in accounting opens the wrong attachment.
Business email compromise does not look like an attack. Someone reads a mailbox quietly for three weeks, learns how your company phrases a payment request and which two people approve one, and then sends a message that is correct in every particular except the account number. No malware. No alert. The first sign is a vendor asking where their money is.
That is the shape of most real losses at mid-market organizations: not sophisticated intrusion, but patient use of ordinary access that was never tightened.
IT21 works on the controls that change the outcome of that Tuesday morning. Who can reach what, and from where. What gets logged and whether anyone reads it. How quickly a compromised account can be shut off. Whether a payment change can clear on an email alone. Whether the data that would end your week if it leaked has been located and protected, or merely assumed to be fine.
What you get:
- A current picture of where your sensitive data actually sits, including the copies nobody sanctioned
- Multi-factor authentication and privileged access sorted out for the accounts that matter, starting with the ones that can move money
- An incident response plan short enough that people read it, with roles assigned by name and a call list that is current
- Security awareness training aimed at the two or three attacks your organization will actually see
- Evidence your insurer, your bank, or your largest customer will accept without a follow-up questionnaire
Assess is a real look at your environment against a recognized standard rather than a vendor’s product checklist. Transform is closing the gaps in the order that reduces the most exposure per dollar, which is rarely the order a product catalog suggests — identity and access first, almost always. Optimize is the drill: testing the response plan before the incident, because a plan that has never been rehearsed is a document, not a capability.
The security work and the audit work are the same work looked at from two sides. Having spent years as the person examiners answer to, and years before that as the examiner, shapes what we tell you to fix first. It also means the file you end up with is built to be reviewed by a third party, since sooner or later it will be. The credential shown with this page is the short version of that history.
The first sign is a vendor asking where their money is.
[PROOF: security engagement — sector, region, what was found, what changed — supply]
The IT Risk & Readiness Assessment is the first step here. It is measured against a recognized governance framework auditors and boards use to judge whether technology risk is being managed, and it gives you a ranked list of what to fix rather than a scan report with four hundred rows in it.
- Assess
- Transform
- Optimize
Oscar Chacon, CISA
Certified Information Systems Auditor since 1997
Not sure where you stand? Start with the assessment.
Request the AssessmentPractical information security — a brief
Where sensitive data actually sits, privileged access sorted for the accounts that move money, a response plan people will read, and evidence your insurer and bank accept.
Get the PDF — enter your email
HubSpot form — assessment-request — not configured
Set portalId and forms.assessment-request in src/lib/hubspot.ts.
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

