Eugene & Springfield, Oregon · Cybersecurity

Cybersecurity That Holds Up to Scrutiny.

Being protected and being able to prove it are two different problems. We run the layers, and we can show you what each one is doing.

A technician at a laptop beside a glass wall overlooking a server room.
Prevent, Detect, Respond, Prove

Most Cybersecurity Stops at the First Job.

Prevention is the part everyone sells, and it is the easiest part to buy. A firewall in the closet, a filter on the mailbox, antivirus on the laptops, a training video once a year. Nearly every provider in Eugene will quote you some version of that list, at close to the same number.

It is worth having. It is also the part attackers have had the longest to study. Most incidents that reach a small business in Lane County are not sophisticated at all. They are ordinary. A convincing invoice from a name you recognize. A login page that looks exactly right. A password that got reused somewhere it should not have been. Prevention is built to stop the attempt, and it stops a great many of them. It was never built to tell you what happened on the day one worked.

Which leaves three questions a prevention-only program has no answer for. What is watching when nobody is at a desk. What happens in the four minutes after something gets through. And what you hand an insurer, a client, or an auditor who asks you to prove any of it in writing.

Four jobs, not one. The rest of this page is how each of them runs for businesses in Eugene, Springfield, and across Lane County.

Prevent

Seven layers between an attempt and your data. Email, people, the web, the network, the device, the account, and the patching underneath all of it.

Detect

Something watching how software behaves, continuously, rather than checking names against a list.

Respond

Containment that happens on the machine, in the moment, without waiting for somebody to answer a phone.

Prove

Answers for the questions you actually get asked. An insurer at renewal, a client running a vendor review, an auditor.

Defense in Depth

We Cannot Drive the Car. We Can Line the Road.

Here is how the conversation usually goes. We do not know how to drive your car. We do not know where you are going, or how fast you need to get there. That is your business, and you should run it at whatever speed it needs to run at.

Our job is the guardrails. A guardrail does not promise that nobody ever drifts out of a lane. It promises that when somebody does, and eventually somebody does, there is already something there to slow the car and turn it back before the drop. You can still take the wheel and drive off the cliff deliberately. Nothing stops that. But an ordinary mistake at an ordinary moment should not end the trip.

Seven security layers shown as guardrails along a roadSix guardrails stand between the traffic and the drop: email, people, identity, web and DNS, firewall, and endpoint. The road surface beneath them is patching.01Emailbefore it reaches the inbox02Peoplethe human firewall03Identityon the account04Web & DNSwherever the laptop is05Firewallat the network edge06Endpointon the machine itselfPATCHING · THE SURFACE EVERYTHING ELSE RUNS ONSeven security layers shown as guardrails along a roadSix guardrails stand between the traffic and the drop: email, people, identity, web and DNS, firewall, and endpoint. The road surface beneath them is patching.01Emailbefore it reaches the inbox02Peoplethe human firewall03Identityon the account04Web & DNSwherever the laptop is05Firewallat the network edge06Endpointon the machine itselfPATCHING · UNDERNEATH ALL OF IT
Layer by Layer

Seven Layers, and What Each One Is For.

Each layer covers ground the one before it was never built to reach. Read down the right hand column and you can follow the handoff: where one layer finishes, the next is already holding.

Layer
What It Does
Hands To
01

Email Filtering

Sits inside Microsoft 365 or Google Workspace and inspects mail after the platform has already taken its turn, so it sees what the built in layer let through. It can also pull a message back out of an inbox after delivery, when something is recognized later.

Hands toPeople
02

Security Awareness Training

Training every month and a simulated phishing campaign every month, with the results going to your primary contact. The goal is not a certificate on the wall. It is that the tenth suspicious invoice gets the same second look as the first one did.

Hands toIdentity
03

Identity Threat Detection

Watches the account rather than the device, across Microsoft 365 and Google Workspace. If a credential does get handed over, or turns up from somewhere it has never been used before, the account is where that shows up first.

Hands toWeb & DNS
04

Web and DNS Filtering

Blocks known bad destinations at the moment of the click, on the device itself. A laptop on Willamette Street or at a kitchen table in Springfield is filtered exactly the way it would be at the office.

Hands toFirewall
05

Firewall

Governs what crosses the boundary at the office, keeps inbound access closed by default, and separates the traffic that has no reason to mix. The fixed edge, for everything that still lives behind one.

Hands toEndpoint
06

Endpoint Detection and Response

Watches how software behaves on the machine rather than matching files against a list. When something starts acting like ransomware, the agent isolates that machine on its own, without waiting for a person to be awake.

Hands toPatching
07

Patching

Operating systems and third party software updated on a schedule, so published flaws stop being useful to anyone. On premises Active Directory is covered by continuous alerting and regular review alongside it.

Hands toThe Surface All Six Run On
Ongoing Security Management

A Stack You Install Once Is Already Out of Date.

Buying seven layers is a purchase. Keeping them worth having is the work. Attackers change what they try, vendors change what their tools can do, and your business changes underneath both. A stack that was right for you in January is not automatically right in September.

The program runs on a loop of its own. We learn from what actually happened, in your environment and across every environment we watch. We train, and we watch what comes back closely enough to know whether it is landing. We adjust the controls, because a filtering rule that made sense before you opened a second location does not make sense after it. And we adapt the stack itself, adding layers as better ones become available rather than waiting for a renewal date to raise the subject.

That last part is the one you cannot buy in a box. It is also why the seven layers listed on this page are not a product list. They are the current state of something that keeps moving, and moving it is the job.

For a business in Eugene or Springfield, that is the practical difference between owning security software and having somebody accountable for whether it still works.

The PathWise IT security operating cycleA continuous four stage loop: learn what changed, train the human layer, adjust the controls, and adapt the stack itself. The cycle repeats rather than finishing.1Learnwhat changed2Trainthe human layer3Adjustthe controls4Adaptthe stackALWAYSRUNNING
Cyber Insurance Requirements

The Standard Moved. Somebody Should Have Told You.

How the baseline for small business security has risenTwo stacks compared. In 2018 the accepted baseline was antivirus and a firewall, two layers. Today the expected baseline is seven layers: patching, endpoint, firewall, web and DNS, identity, people, and email.FirewallAntivirusPatchingEndpointFirewallWeb & DNSIdentityPeopleEmailTHE BAR IN 2018THE BAR TODAYWHAT WAS ENOUGHWHAT IS EXPECTED NOW

The wording changes with every carrier and every renewal. The direction has not changed in years. A business already running the program answers from what is in place, while a business assembling one against a deadline buys the same controls in a hurry and still has a gap to explain.

Antivirus and a firewall was a perfectly reasonable answer in 2018. It was the standard. It is not laziness that it stopped being the standard, and it is not obvious either, because nothing arrives to announce it. The bar simply sits somewhere new, and one day you find out where.

Attackers moved first. We moved with them, which is what the section above is about. What is less obvious is that the people underwriting the risk moved too, and they moved for unsentimental reasons. They paid out, they looked at what the losses had in common, and they rewrote what a business has to have in place before they will price a policy. That is not a marketing opinion. It is an industry adjusting to arithmetic.

Which means the standard is no longer a matter of technical taste. There is a second party grading it now, and the grade arrives attached to a number. A renewal quote that jumped. A control that has to be in place before coverage is offered at all. A larger client running a vendor review before they will sign. None of those are IT decisions, and none of them wait the way a technical recommendation waits.

Tracking any of it is not the highest and best use of your time. You should be running your practice, your firm, your shop. Nobody expects an owner in Eugene to be reading underwriting bulletins on a Tuesday afternoon, and the fact that you were not is not the failure here. Somebody should have been doing it for you, and telling you what it meant for your business specifically, before it turned up priced.

That is the half of the job most providers skip. Installing the tools is the visible part. Watching what is being asked, what is coming next, and working out whether it actually affects a business your size in Lane County, is the part that makes somebody a partner instead of a vendor.

Detection and Response

It Will Not Look Like an Attack.

The picture most people carry is cinematic. Screens going dark, a countdown, somebody in a hood. Real intrusions are the opposite of dramatic, and that is the entire problem. They are quiet, incremental, and designed to look like ordinary activity for as long as possible, because the longer it all looks normal the further it gets.

So the useful question is not whether somebody would spot it. Nobody would. The question is what is watching, and what is able to act without waiting to be asked.

1

It arrives looking ordinary

A login that succeeds. An attachment that opens. A file that saves. Nothing turns red, nothing pops up, and there is no moment where anybody could reasonably be expected to notice something is wrong.

2

It moves in small steps

A rule added to a mailbox. An application registered against an account. A process starting quiet work on one machine. Every one of those is a thing that happens legitimately a hundred times a week.

3

The pattern is what gives it away

Which is why the tooling is built to watch how things behave over time rather than to recognize a file or a location. Intent shows up in the sequence, not in any single step of it.

4

The response is built to act on its own

Containment and remediation are designed to run from the tooling rather than to wait for somebody to notice and log in. On the identity side that extends to reversing what an attacker changed, including the rules and app registrations most people never think to check.

5

Then a person picks it up

What happened, how it got in, what it reached, and what changes so the same route does not work a second time. That part is not automated and should not be.

None of this depends on anybody being awake, which is the point of building response into the tooling rather than into a phone tree. A person still does the thinking afterwards, and being reachable when it matters is part of the arrangement rather than an upgrade. But the first move does not sit in a queue waiting to be noticed.

Compliance and Regulated Industries

Some Businesses Do Not Get to Decide How Much Security Is Enough.

For most companies this is a judgment call. For a regulated practice it is not, and the standard is set by somebody else entirely. The layers on this page are the same either way. What changes is that a regulated firm has to be able to describe them to a third party, sometimes on short notice, and usually at the least convenient moment. Here is what that actually means for the three kinds of firm we see most across Eugene, Springfield, and Lane County.

Dental and Medical

HIPAA Security Rule

  • A documented Security Risk Analysis, reviewed annually. It is the single document OCR asks for most often, and the most commonly missing one
  • Unique logins for every person, audit controls, and automatic log off. Shared front desk credentials make it impossible to say who opened what
  • A signed Business Associate Agreement with every vendor that touches patient data, including your IT provider
  • Encryption of records at rest and in transit, plus access controls limiting each role to what it needs
  • Multi factor authentication is classed as addressable today rather than required, which in practice has meant skipped. A proposed update removes that flexibility, so it is worth having in place before it is asked for
Law Offices

Oregon RPC 1.6(c)

  • Reasonable efforts to prevent unauthorized access to client information. The rule is deliberately flexible, which means the standard rises as technology does
  • Competence with the technology you use is part of the duty, not separate from it
  • Third party storage is permitted when you have taken reasonable steps to confirm the provider actually secures the data
  • Matter files and client communication live in email and document storage, which is where identity attacks aim first
  • One compromised mailbox is a disclosure problem for every matter inside it, and the notification conversation goes to clients
Financial and Wealth

FTC Safeguards Rule

  • A Written Information Security Program is required at any size. Tax preparers, accountants and bookkeepers are financial institutions under the rule
  • Multi factor authentication on every system holding customer information. Not recommended, required
  • Encryption of customer information at rest and in transit
  • A named Qualified Individual accountable for the program, which can be a service provider rather than an employee
  • A written incident response plan, staff training, and documented oversight of your own vendors
  • Core requirements have been enforceable since June 2023, and breaches touching 500 or more people are reportable to the FTC within 30 days

We handle the technical side of that: the controls themselves, how they are configured, and being able to show what is in place when somebody asks. Compliance programs, audits, and formal attestations are their own profession, and we work alongside the people who do that rather than pretending to replace them. There is also a fourth version of this that catches businesses off guard, and it is not a regulator at all. It is a larger client running a vendor security review before they will sign, which is now routine and arrives with a deadline attached.

Free Scorecard

See What an Attacker Sees Before They Do.

The Cyber Risk Scorecard looks at your domain the way somebody sizing you up would. Exposed services, email configuration, credentials already circulating from breaches elsewhere. It takes a few minutes, it costs nothing, and it tells you where you actually stand rather than where you assume you do.

Run the Scorecard No ObligationNo Sales PitchStraight Answers
A laptop screen showing an external security scan in progress.
Common Questions

Questions We Hear a Lot

The things people actually ask before they change how their business is protected.

Something not covered here?

Ask it directly and you will get a straight answer, not a sales call.

Get in Touch →

Is cybersecurity something I can buy on its own?

Ours is sold as part of Managed IT or Co-Managed IT, because running these layers well depends on knowing the environment they are protecting. Security bolted onto a network somebody else configured is where most of the gaps come from.

We already have antivirus and a firewall. Is that not enough?

It was the accepted standard for a long time, and it still stops a great deal. What it cannot do is tell you what happened on the day something got past it, or answer the questions an insurer now asks. That is the gap the other layers close.

Who is watching if something happens at two in the morning?

Containment runs on the machine itself rather than from an office, so the first response does not wait for anybody to wake up. A person follows up afterwards to work out how it arrived and what needs to change. Being reachable when it matters is part of the arrangement.

Will you help us fill out our cyber insurance questionnaire?

Yes, for clients. Every carrier words it differently, so there is no canned answer sheet. We go through the form with you and the answers come from what is actually configured, because we are the ones who configured it.

Do you handle HIPAA or FTC Safeguards compliance for us?

We handle the technical side: the controls themselves, how they are set up, and being able to show what is in place. Formal compliance programs, audits and attestations are a separate profession, and we work alongside the people who do that rather than claiming to replace them.

How often does security awareness training actually run?

Monthly, along with a simulated phishing campaign that goes out unannounced. Results go to your primary contact. Anyone who clicks gets follow up training assigned, and repeat clicks get raised with the owner or manager.

What happens to the tools when something better comes along?

They get replaced. The seven layers on this page are the current state of the program rather than a fixed product list, and part of the job is adding or swapping layers as better ones become available instead of waiting for a renewal date.

Do you work with businesses outside Eugene and Springfield?

Yes. Most of our clients are across Lane County, and remote work is normal for a good deal of this. Anything that genuinely needs hands on hardware is a drive rather than a dispatch queue.

Let’s Talk

Find Out Where You Stand.

Most businesses in Eugene and Springfield have more in place than they think in some areas and less in others. A short conversation is usually enough to tell which is which, and there is no pitch attached to it.