Cybersecurity and Safeguards Rule compliance for small firms in Wichita Falls, explained in plain English
Open Book Cyber is a boutique cybersecurity consultancy serving small businesses in Wichita Falls, Texas, surrounding communities, and beyond. We specialize in security assessments, compliance readiness, policy development, and security awareness training. Built for firms that handle sensitive client data but don't have (and don't need) a full-time security department.
WHO WE WORK WITH
Built for firms where client trust is the whole business
Firms that handle sensitive client data but don't have (and don't need) a full-time security department. Our core focus is financial services businesses covered by the FTC Safeguards Rule, and we also serve other small professional teams that take client confidentiality seriously.
CPA & accounting firms, tax preparers
You're a "financial institution" under federal law. The FTC Safeguards Rule requires a written security program, and the IRS requires tax professionals to maintain a Written Information Security Plan (WISP). We build both and the evidence behind them.No dedicated security staff on hand
You may have IT support, but no one specializes in security. Decisions fall to whoever has time. We fill that gap without adding headcount.Independent insurance agencies
The Safeguards Rule applies to you too, and carriers increasingly expect their appointed agencies to demonstrate real security controls. We get you ready for both.Budget-conscious about security
You need real improvements, not enterprise tools. Maximum value per dollar, no unnecessary bells and whistles.Small teams (1–50) handling sensitive data
Financial records, legal documents, or confidential business information. A breach would damage client trust and may trigger legal notification obligations.OUR PHILOSOPHY
Accessible, transparent, and honest
Our goal isn't to create dependency. It's to give you the knowledge and protection you need to run your business with confidence. We don't sell fear, and we won't recommend services you don't need.
BUNDLES, IN THE OPEN
The Security Pipeline: four tiers, each built on the last
Each tier builds on the one before it, because each tier genuinely depends on the last. Policies written without assessment findings are generic templates. Training without a phishing baseline can't be measured. The pipeline exists so every deliverable is built on evidence from your actual environment. Every bundle is a quote confirmed after a free consultation, and individual services are available for a specific one-off need.
The evidence-gathering tier. We examine your environment the way an attacker would, from the outside in: vulnerability scan, Microsoft 365 or Google Workspace review, email security configuration review, user access review, dark web exposure check, and a phishing simulation baseline. Optional add-ons: cloud sharing reviews.
—————————————————-
Best for: a clear-eyed look at where you stand today.
1 : Technical Assessments
Everything in Tier 1, plus
All Tier 1 findings synthesized into one unified risk report: an executive summary readable in five minutes, an asset and data inventory (a Safeguards Rule requirement you'll now have on file), risk-rated findings with business impact explained, an FTC Safeguards Rule and IRS Publication 4557 gap map, and a prioritized 30/60/90-day roadmap.
—————————————————-
Best for: compliance standing, insurance renewals, a starting point roadmap.
2: Risk Assessment Report
Everything in Tier 2, plus
The written security program your regulators and insurers expect, drafted from your actual assessment findings, not a generic template with your name pasted in: WISP, Acceptable Use Policy, and Incident Response Plan.
—————————————————-
Best for: meeting Safeguards Rule and IRS written-program requirements.
3: Policy Development
Everything in Tier 3, plus
Your human defense layer, because the phishing email that matters won't be stopped by a firewall: live in-person training customized to your industry and your phishing baseline results, a follow-up simulation to measure improvement, and an assessment quiz with completion certificates for staff records.
—————————————————-
Best for: a complete, defensible security program.
4: Awareness Training
THE COMPLIANCE REALITY FOR FINANCIAL PROFESSIONALS
The FTC Safeguards Rule isn't optional, and "we have antivirus" isn't a plan
If you're a CPA, tax preparer, or insurance agency, federal law classifies you as a financial institution. That means the FTC Safeguards Rule requires you to maintain a written information security program with specific elements: a designated responsible individual, a risk assessment, documented safeguards, and staff training.
Tax professionals have a second layer: the IRS requires a Written Information Security Plan (WISP), and when you renew your PTIN, you attest that you have one. IRS Publication 4557 spells out what it should contain. A surprising number of practices attest to a plan that doesn't actually exist yet, a problem that only surfaces at the worst possible moment, like after a breach or during an insurance claim.
This is exactly the gap our Tier 2 and Tier 3 bundles close: the risk assessment the rule requires, and a WISP built from your real findings rather than a downloaded template.
What the Safeguards Rule expects you to have on file
A written security program with a named person responsible for it
A documented risk assessment of your systems and data
An inventory of the data you hold and where it lives
Access controls, encryption, and MFA on systems with customer data
Staff security awareness training
An incident response plan with notification procedures
À LA CARTE
All services can be purchased as standalone engagements, priced after a free consultation. If you need three or more, a bundle will save you money, and we'll tell you so.
Every service, individually available
TECHNICAL ASSESSMENTS
-
Internal and external scanning for known weaknesses, with every finding rated against your actual business risk, not just a technical severity score. Includes a plain-language report and a 60-minute findings presentation.
-
Can attackers impersonate your domain to defraud your clients? This is a common vector for fake-invoice fraud and tax-season wire fraud. Includes step-by-step remediation guidance.
-
MFA status, conditional access, sharing settings, and security defaults, benchmarked against Microsoft's standards with a prioritized action list.
-
Finds active accounts belonging to former employees, excessive admin privileges, and offboarding gaps across your systems.
-
OneDrive, SharePoint, Google Drive, and Dropbox configurations: misconfigured storage, overly permissive sharing links, and access gaps, prioritized by data sensitivity.
-
Admin settings, MFA enforcement, third-party app access, and sharing permissions, with actions prioritized by business impact.
-
Have your credentials already leaked? We check whether your organization's emails, domains, or passwords appear in known breaches, with remediation prioritized by urgency.
-
Simulated attacks measuring how your team actually responds: who clicked, who entered credentials, who reported it. Includes training recommendations based on real behavior.
POLICY DEVELOPMENT
-
Clear expectations for how employees may use company systems, email, and business data, protecting the organization legally while giving your team clarity. Includes an acknowledgment form.
-
Step-by-step guidance for identifying, reporting, and responding to an incident: who's responsible, what happens when, and your client, regulatory, and insurance notification obligations.
-
Governs access from outside the office: home networks, personal devices, public Wi-Fi, cloud storage, and video conferencing, customized to your tools and team.
-
The foundational document required by the FTC Safeguards Rule and the specific plan tax professionals attest to at PTIN renewal, per IRS Publication 4557. Customized to your operations, with an implementation guide and employee-facing summary.
SECURITY TRAINING
-
Live, interactive sessions built around your industry and the actual threats your team faces: phishing, passwords and MFA, data handling, mobile devices, and incident recognition. No generic corporate videos. Includes a quiz and completion certificates.
Annual Security Review
Security isn't a one-time project, and neither is compliance. On a defined schedule, not an on-call retainer, we keep everything you built current:
Refreshed technical assessments and an updated risk report with year-over-year comparison
Policy reviews and updates as your business changes
Training refresh with a new phishing simulation
Cyber insurance renewal support and two scheduled check-in calls
Best for clients who've completed Tier 2 or above and want their compliance evidence maintained without thinking about it.
STRAIGHT ANSWERS
Frequently Asked Questions
-
Attackers don't pick targets off a map. Automated scans and phishing campaigns hit every business with an internet connection, and small professional firms are attractive precisely because they hold valuable client data behind lighter defenses. Tax practices see seasonal spikes in wire-fraud and impersonation attempts aimed at their clients.
-
Keep them. We're designed to work alongside your IT provider, not replace them. IT support keeps systems running; we independently verify they're secure and build the compliance documentation regulators and insurers expect. An independent set of eyes is actually a feature: we have no incentive to grade our own homework.
-
For most firms, Tier 2. It includes all the hands-on assessments plus the unified risk report that satisfies the Safeguards Rule's risk assessment requirement and gives you a prioritized 30/60/90-day roadmap. If you just need one specific thing, say a WISP or a phishing test, individual services exist for exactly that. And if a bundle isn't right for where you are, we'll say so in the free consultation.
-
No. We're based in Wichita Falls and serve surrounding communities in person, but assessments, reports, and policy work all travel well remotely, and we serve clients beyond the area. The Tier 4 training session is delivered in person; standalone training can be run in person or remote.
Start with a free 30-minute consultation
We'll talk through your current security concerns, your business environment, and which bundle or individual service provides the most value for your situation. If a bundle isn't right for where you are today, we'll tell you that.