Security Readiness for Modern Business

Practical security assurance for small businesses.

Amethyst Assurance Group helps small businesses identify security weaknesses, reduce operational risk, and improve readiness against modern threats.

What We Do

We help owners see practical exposure before it becomes expensive.

Our flagship service, the Onsite Business Assurance Review, is built for small businesses that need a clear, nontechnical view of where they may be exposed and what should be improved first.

Business Readiness Review

We evaluate everyday business practices that affect security, continuity, and operational resilience.

  • Owner/manager interview
  • Security ownership review
  • 30/60/90 day roadmap

People, Process & Physical Exposure

We look beyond computers to identify visible and procedural weaknesses that remote reviews often miss.

  • Workstation habits
  • Document handling
  • Vendor and access practices

Practical Cyber Hygiene

We review core readiness areas without intrusive scanning, hacking, or technical disruption.

  • Password and MFA practices
  • Wi-Fi and device hygiene
  • Backup and recovery readiness
Free Employee Security Guidance

Build a stronger Human Firewall—one practical habit at a time.

A Human Firewall is a team that knows how to pause, verify, protect, and report. Employees do not need to become cybersecurity experts. They need clear habits, permission to question unusual requests, and a safe way to report concerns quickly.

The employee rule Pause. Verify. Protect. Report.

When something feels rushed, unusual, secret, or too good to be true, slow down and check it.

Security works best when people feel supported.

Give employees simple instructions, a trusted person to contact, and permission to stop a questionable request. Reward quick reporting—even when someone clicked first. Early notice gives the business more time to limit damage.

01Pause Before You Click

Phishing succeeds by creating urgency, curiosity, fear, or an unexpected reward.

Watch for

  • Unexpected links, attachments, login prompts, or QR codes.
  • Messages demanding secrecy or immediate action.
  • Sender names that look familiar but use a different address.

What to do

Stop, inspect the sender and destination, and open known websites yourself instead of using the message link.

If something happens

Stop interacting with the message and report the message or click immediately. Follow your company's incident instructions and do not delete evidence.

02Protect Every Sign-In

One stolen password should not unlock every account an employee uses.

Build the habit

  • Use a unique password or passphrase for every business account.
  • Use a company-approved password manager when one is available.
  • Turn on multi-factor authentication, preferably an authenticator app or security key.

Never do this

Never share passwords or approval codes. Deny unexpected sign-in prompts and report them right away.

03Verify Unusual Requests

Attackers may impersonate owners, managers, vendors, banks, or coworkers.

Verify separately

  • Payment, payroll, banking, gift-card, or account-change requests.
  • Requests for sensitive files, credentials, or personal information.
  • Sudden changes to a vendor's contact or payment details.

Use a trusted channel

Call a known number, speak in person, or start a new message using saved contact information. Do not rely on the contact details inside the request.

04Handle Devices and Data Safely

Everyday handling choices protect customer, employee, and business information.

Simple protections

  • Lock screens whenever devices are unattended.
  • Install approved updates and use only approved apps and storage.
  • Keep sensitive papers, screens, and conversations away from public view.

When away from work

Avoid unknown USB devices and public Wi-Fi for sensitive work unless the company provides a secure method.

05Report Quickly—Without Fear

Fast reporting is a security strength. Silence gives a small mistake time to grow.

Report immediately

  • A suspicious message, unexpected login prompt, or missing device.
  • A click, download, password entry, or information disclosure that may be unsafe.
  • Unusual account activity or a security control that is not working.

For owners and managers

Make the reporting path obvious, thank employees for speaking up, and focus first on containing the problem—not assigning blame.

06Practice the Habit

Short, repeated practice works better than a once-a-year lecture.

Keep it practical

  • Use a five-minute security reminder in regular team meetings.
  • Discuss one realistic example from the kind of work employees perform.
  • Practice how to verify and where to report—not just how to spot danger.

Reinforce progress

Repeat the message after new threats, role changes, incidents, and onboarding. Recognize good questions and quick reporting.

Human Firewall Quick Checklist

Use these questions before acting on an unusual message or request.

  • Was I expecting this?
  • Is someone creating urgency, fear, secrecy, or pressure?
  • Does the sender address and destination look correct?
  • Can I verify the request through a trusted, separate channel?
  • Am I being asked for a password, approval code, payment, or sensitive data?
  • Do I know exactly where and how to report this?
Our Process

A clear path from uncertainty to prioritized action.

OBAR is designed to be calm, structured, and useful. The goal is not to overwhelm your team. The goal is to identify what matters most.

1

Intake

We learn about your business, critical systems, vendors, and concerns before arriving onsite.

2

Onsite Review

We conduct an owner interview and walkthrough across people, process, physical, and technology areas.

3

Scorecard

Your business receives an Amethyst Assurance Rating across seven practical readiness domains.

4

Roadmap

We deliver a written report with priority findings and a 30/60/90 day improvement plan.

Service Packages

Choose the level of review that fits your business.

Pilot pricing may be available for a limited number of local businesses during our founder launch phase.

OBAR Essential

$595

For very small businesses that need a clear starting point.

  • Pre-visit intake
  • Up to 2 hours onsite
  • Basic walkthrough
  • Short findings summary
  • Top 5 recommendations
Ask About Essential

OBAR Plus

$1,950

For businesses with higher concern or deeper planning needs.

  • Everything in Professional
  • Expanded vendor review
  • Tabletop-lite scenario
  • Follow-up planning session
  • Expanded readiness roadmap
Ask About Plus
What This Is Not

A practical review, not a scary technical audit.

The Onsite Business Assurance Review is not a penetration test, forensic investigation, legal review, compliance certification, cyber insurance approval, or guarantee against future incidents. It is a practical advisory review designed to help your business reduce avoidable risk and improve preparedness.

Combined Experience

Cybersecurity knowledge grounded in real small-business experience.

D. Mickelson, E. Mickelson, and Astrid

Our team brings more than 50 years of combined experience across loss prevention, security engineering, field observation, business communication, entrepreneurship, systems architecture, documentation, and practical readiness consulting.

Our team's qualifications include CompTIA Security+ certification and degrees in business and cybersecurity. This combination of technical training and business education helps us translate security concerns into clear, practical priorities.

We have also been small-business owners across a span of more than 30 years. We understand the challenges of limited time, competing priorities, tight budgets, and making responsible decisions without a large internal security team.

Ready to understand where your business may be exposed?

Tell us what is concerning you. Our intake assistant will offer safe next steps and help you understand whether an Onsite Business Assurance Review may be a good fit.