SCM Technologies

Security assessments for regulated small businesses in Texas.

If you run a law firm

The risk that matters most right now is business email compromise aimed at your trust account. The FBI's Internet Crime Complaint Center has tracked this pattern for years: an attacker gets into an email thread around a real estate closing, waits for wiring instructions to come up, and sends a replacement account number that looks like it came from you or the title company. The money doesn't come back. Texas Rule 1.15 makes safekeeping client trust funds a direct duty, not a technicality. Rule 1.01 requires competent representation, and Rule 1.05 makes protecting confidential client information an ongoing obligation. None of the three is a suggestion. See how this gets fixed before the wire goes to the wrong account.

If you're a tax preparer, mortgage broker, or title company

The FTC classifies you as a financial institution under the Gramm-Leach-Bliley Act if you prepare taxes, broker mortgages, arrange auto financing, run a collection agency, handle real estate closings, or work as a non-SEC investment adviser, whether or not you'd describe your own business that way. The Safeguards Rule (16 CFR 314) applies directly: a written security program, access controls, and vendor oversight are requirements, not suggestions. The failure mode is usually a third-party integration nobody audited. In 2025, the auto-finance credit platform 700Credit was breached through a compromised third-party API, undetected from July until it was discovered that October, exposing names, dates of birth, and Social Security numbers belonging to roughly 5.8 million people who had applied for vehicle financing through about 18,000 dealerships (SecurityWeek). Under 16 CFR 314.4(f), overseeing that vendor is the covered firm's obligation, not the vendor's. See how this gets fixed before someone else's vendor breach becomes your compliance problem.

If you run a medical or dental practice

HIPAA's Security Rule (45 CFR 164.308, 164.310, 164.312) requires a documented security risk analysis and real administrative, physical, and technical safeguards for patient data, regardless of practice size. It's built to scale down to a small office, not exempt one. The realistic failure mode isn't sophisticated: a staff member clicks one phishing link, an attacker sits unnoticed for weeks quietly reading and copying records, then locks the entire patient record system at once. Weeks of access nobody sees, then one morning when nothing opens. See how this gets fixed before weeks of quiet access become a full lockout.

How this works

First

Gap Assessment

A structured review of your firm against the NIST Cybersecurity Framework, and against HIPAA or PCI DSS where either applies to what you handle. I look at email authentication, access controls, backup configuration, and whether logs get reviewed. You get a findings report and a fix list ranked by risk, not a document nobody reads.

Then

Hardening & Setup

Fixing what the assessment found. This usually means: email authentication (DMARC, SPF, DKIM), tightening access controls so the right people have the right logins and no one else does, verifying backups actually restore, and setting up monitoring so something is watching after I leave.

Ongoing

Monthly Advisory

Once things are fixed, someone still has to watch them. That's log review, a monthly report you can actually read, and a direct line to call when something looks wrong. Not a ticket queue. Me.

What a finding actually looks like

This is a worked example, not a client document. It shows the format and the depth of a Gap Assessment finding: what gets checked, what gets written down, and what the fix actually involves. The firm and the domain are invented. This is the standard a report is written to.

Constructed example, illustrative Severity: High

Finding 4.2: Email authentication not enforced

Domain checked
[example-firm].com (placeholder)
Observation
No DMARC record published. SPF present but set to ~all (soft-fail, not enforced). No DKIM selector found on the primary mail flow.
Why it matters
Anyone can send email that appears to come from [example-firm].com. A message that looks like it's from the managing partner, asking a client to wire funds to a new account, will pass through most spam filters unblocked.
Fix
Publish a DMARC record at p=quarantine, move SPF to -all once every legitimate sending source is confirmed, and enable DKIM signing on the mail provider. About two to three hours of work with access to DNS.
Framework
NIST CSF, Protect function (data security, identity management).

About Stephen

Stephen Matthews works front-line SOC and MDR operations: triaging alerts, investigating incidents, and being the person who actually reads the logs when something looks wrong. SCM Technologies is how that work gets offered directly to firms too small to staff it.

SCM Technologies is Stephen. There's no tier-one help desk between you and the person who wrote your findings report, and no one else who picks up the phone when you call next month. If that's the wrong fit for a larger firm with its own IT department, it's worth knowing up front.

This is a new practice, so there are no testimonials on this page. There is a full sample finding above instead, which is a better basis for judging the work anyway.

Free: an External Exposure Snapshot

Before spending anything, you can have a one-page report on what anyone on the internet can already see about your firm's email and web setup. No access to your systems, nothing installed, no obligation, and it is yours to keep whether or not we ever work together.

It answers, in plain language:

Every finding comes from public records, and each one is written so you can confirm it yourself. Ask below and it comes back within one business day.

What it cannot tell you: whether your backups restore, whether anyone reviews your logs, or who still has access after they left. That needs access to your systems, and it is what the Gap Assessment is for.

Contact

Ask for your free snapshot, or anything else, at stephenmatthews@scm-technologies.com, or use the form below.

A sentence or two is enough. I'll ask follow-up questions if I need to.