If you’re a partner, owner, or office manager at a small to mid-sized law, accounting, or healthcare practice—you’ve probably been hearing more about frameworks lately.
HIPAA. IRS Pub 4557. The ABA’s cybersecurity guidelines. Your cyber liability insurance renewal asking 50+ questions about MFA, backups, and endpoint protection.
It all starts to feel like a compliance alphabet soup.
But here’s the thing: there’s one framework quietly powering all of it—and if you’re not using it yet, you’re missing a big opportunity to get ahead (and stay protected).
That framework is CIS Controls version 8.1.
CIS stands for the Center for Internet Security. They’re a nonprofit that builds prioritized, practical steps organizations can take to reduce cyber risk.
Their framework—CIS Controls v8.1—isn’t some monster document only tech people can use. It’s actually designed to be practical and progressive, especially for small organizations.
Even better? It’s what insurance companies and regulators are starting to use as a measuring stick.
If you’re wondering:
“What do I really need in place to meet compliance?”
“How do I prepare for my cyber insurance renewal?”
“Are we secure—or just lucky so far?”
Then CIS 8.1 gives you a clear, structured roadmap.
Group 1 is where most SMBs should start. It’s focused on:
✅ Inventory of hardware/software
✅ Strong passwords and MFA
✅ Backups
✅ Antivirus/EDR
✅ User access control
✅ Security awareness training
It’s manageable. It’s actionable. And it builds a solid foundation.
Groups 2 and 3 scale with your business, adding more advanced practices as you grow or face more complex risks.
Most underwriters are now asking questions that map directly to CIS 8.1. Things like:
“Do you use MFA for remote access?”
“Are backups encrypted and tested?”
“Do you provide phishing simulations?”
They’re not just checking if you have cybersecurity tools—they want to know you’re using them in line with best practices.
And if you can show that your business is mapped to CIS? That’s a big green flag.
You don’t need a full-time CISO or in-house IT team to get this right. But you do need a plan. With our BigView Secure, Secure Plus and VCISO service we can handle it for you.
At Big Water Technologies, we help firms map to the CIS Controls—starting with Group 1—and grow from there.
Whether you’re prepping for an insurance renewal, a client audit, or just want to sleep better at night knowing you’ve got your house in order—we can help.
📩 Want a quick review of where you stand on CIS 8.1? Let’s talk.
Hire us to set your IT strategy up for sustainable success.
Learn about our proven No-Nonsense approach.
Get an IT roadmap designed specifically for you.
Fearlessly grow your business.