Cyber Security
Most breaches don't come from sophisticated attacks. They come from gaps you didn't audit.
The Problem
The breaches that take down mid-sized organizations are rarely interesting. They come back to ordinary hygiene — credentials that should have been rotated, access that outlived the relationship it was granted for, a backup nobody had ever tested.
The reason these persist is not ignorance. It is that security spending tends to follow whatever was in the news, so organizations end up with sophisticated tooling layered over unresolved basics. The tool generates alerts nobody triages while the actual entry point sits unexamined.
For firms holding other people's sensitive material — law practices, energy operators, campaigns — the exposure is not only operational. It is a client obligation, and increasingly it is the first question a counterparty or an insurer asks.
What We Deliver
- Security posture audits and threat modeling
- Penetration testing oversight and remediation planning
- Incident response planning and tabletop exercises
- Compliance support for industry-specific regulatory frameworks
Who We Serve
Small to mid-sized businesses handling sensitive client data, including law firms, energy operators, and political campaigns, plus organizations recovering from an incident.
Why Acacia Lake
We translate cyber risk into business decisions: what to fix now, what to monitor, and what's not worth the spend.
How An Engagement Runs
- 01
Discovery
We inventory what you actually have — systems, data, identities, vendors, and access — and establish what would genuinely hurt if it were lost, leaked, or locked. Threat modeling starts from consequence, not from a product catalogue.
- 02
Diagnosis
A written posture assessment: where you are exposed, ranked by how likely each gap is to be reached in practice and by what the loss would cost. Explicitly including the findings that are not worth remediating, and why.
- 03
Execution
Remediation planning and oversight, including scoping and managing penetration testing so the report produces fixes rather than a filed PDF. We build the incident response plan and then exercise it.
- 04
Stewardship
Posture drifts as staff, vendors, and systems change. We re-assess on a cadence, refresh the response plan, and remain reachable during an incident.
What You Receive
- A written security posture assessment prioritized by business consequence, not severity score
- A threat model specific to your operation, data, and counterparties
- Penetration test scoping, vendor oversight, and a remediation plan with owners against each item
- An incident response plan naming who decides, who notifies, and in what order
- Tabletop exercise materials and written after-action findings
- Compliance documentation mapped to the frameworks your industry and insurers actually ask about
Common Questions
- Do you perform the penetration testing yourselves?
- We scope and oversee it, and we manage the remediation that follows. Keeping the testing separate from the party judging the results is a deliberate separation, and it is also how you avoid a report engineered to justify the next engagement.
- We are small. Are we really a target?
- Most attacks are not targeted. They are opportunistic and automated, which makes organizational size close to irrelevant — what matters is whether the opening exists. Smaller organizations are frequently reached through a vendor relationship rather than directly.
- We think we are being breached right now. What do we do?
- Call rather than email, in case your mail is compromised. Preserve logs and do not begin wiping systems — the evidence you destroy in the first hour is usually what would have told you the scope.
- Will you tell us to buy more security tools?
- Frequently the opposite. A common finding is that an organization already owns capabilities it never configured. We do not resell security products and take no vendor commissions, so recommending spend earns us nothing.
- Can you help us answer a client or insurer security questionnaire?
- Yes, and it is a common starting point. A questionnaire you cannot answer honestly is a useful map of what to fix, and we would rather help you close the gaps than help you word around them.