201 CMR 17.00
Massachusetts requires any business holding a single MA resident's personal information to maintain a written information security program, enforceable at up to $5,000 per violation. We build WISPs that hold up, not shelf documents.
Risk assessments, compliance, penetration testing, and incident readiness from a senior team headquartered in Boston, working with clients wherever they operate. Every project is fixed scope with deliverables in writing, and the same team can carry the work into 24/7 operations through bcxBastion.
Attackers use AI to write flawless phishing, clone voices, and move faster once inside, and mid-sized companies are carrying the risk.
We map your assets, data, and threats against the controls you actually have, verified with evidence: whether MFA covers every account, whether backups restore, whether file permissions match what anyone intended. Findings come ranked by likelihood and business impact, with a remediation roadmap that names owners.
Leadership gets the risk picture in plain language and dollar terms, and your IT team or MSP gets the detail to execute. Not a hundred-page PDF; a working document that becomes next quarter's plan.
Massachusetts requires any business holding a single MA resident's personal information to maintain a written information security program, enforceable at up to $5,000 per violation. We build WISPs that hold up, not shelf documents.
New DoD contracts require CMMC certification starting October 31, 2026. We run gap analyses against your required level and manage remediation to assessment readiness.
The Security Rule overhaul makes MFA and encryption mandatory rather than addressable. We translate the rule into a project plan.
Compliance work feeds one evidence library that also serves your insurance renewals and customer security reviews. For the Massachusetts requirements in checklist form, read our 201 CMR 17.00 compliance checklist, and see our vCISO service for ongoing compliance ownership.
Tests are scoped to how you actually run: external and internal network, web applications, cloud configurations, and social engineering including AI-generated phishing. Senior testers do the work, every finding comes with a specific fix, and we retest after you remediate.
Most clients test because an insurer, customer, or assessor asked for proof, and we deliver reports those audiences accept.
We write the response plan, assign the roles, and run tabletop exercises against realistic scenarios: ransomware on a Friday afternoon, a compromised email account moving money, a deepfake video call from your CEO authorizing a wire. Each exercise ends with a written gap list and fixes sequenced into your roadmap. Rehearsal is the cheapest control you can buy.
Assessments are snapshots; attacks are continuous. bcxBastion extends our consulting into 24/7 operations, with bcx analysts triaging alerts around the clock, and the consultants who assessed your environment hand off to the team that watches it. See how the platform works.
If you hold personal information about even one Massachusetts resident, including an employee, it applies. The regulation requires a written information security program, risk assessments, access controls, encryption, and vendor oversight, enforceable at up to $5,000 per violation.
If you sell to the Department of Defense or sit in a defense supply chain, new DoD contracts require CMMC certification starting October 31, 2026. Assessments take months and remediation often takes longer, so start the gap analysis now rather than waiting for the contract clause.
We inventory your assets and data, map threats against the controls you actually have, verify claims with evidence, and deliver findings ranked by likelihood and business impact, with a remediation roadmap that names owners.
Consulting finds and fixes gaps; bcxBastion keeps watch afterward. It is our managed detection and response platform built on Google SecOps, CrowdStrike, and Palo Alto Networks, operated by bcx analysts around the clock.
The free Business AI Maturity Assessment takes about 8 minutes and scores AI maturity across six dimensions, including governance, risk, security and resilience.
Take the free AI Assessment