Compliance & Security Specialists - Western New York

Pass Your Next Audit.
Prove Your Compliance.

Compliance and security management for accounting firms, law offices, and financial practices in Western New York

If a regulator, your cyber insurer, or a client's audit team asked for your written security plan tomorrow, could you produce it? We build the documentation and the monitoring behind it - so "we take security seriously" becomes something you can prove, not just say.

Not a regulated business? Home & Small Office Support →

CCNA Certified Microsoft AZ-700 10 Years IT Experience Locally Owned - Western New York FTC Safeguards - SHIELD Act - NYDFS
Alexander DeKalb - Owner of 716 Tech Support, Buffalo NY

We're Not Your IT Department

We don't compete with your IT provider - we make sure whatever you already have holds up to scrutiny.

Works Alongside Your Current IT

No rip-and-replace, no turf war. We layer compliance-specific monitoring and documentation on top of whatever setup you already have.

A Dedicated Second Set of Eyes

Your IT provider is measured on uptime. We're measured on whether your documentation holds up - a separate focus, with someone whose name is on the security program.

One Job: Prove It

Your IT company keeps the lights on. We make sure you can prove, in writing, that you're meeting the specific regulation your business is on the hook for.

Can You Prove It, If Asked?

These are the moments that catch regulated firms off guard.

"Our cyber insurance renewal sent a security questionnaire we can't answer."

MFA, employee training records, an incident response plan - insurers want specifics in writing, and "we think we're okay" isn't an answer they accept anymore.

"We don't have a written information security plan - and the FTC Safeguards Rule requires one."

For firms the Rule covers, a written security program isn't optional paperwork - it's a federal requirement with no small-business carve-out. The first question is whether it reaches you. The second is what you have in writing if it does.

"If a regulator or a client's auditor asked for our documentation tomorrow, we'd have nothing to hand them."

Passwords and antivirus aren't compliance. Compliance is the paper trail proving what you did, when, and why - and most firms don't have one.

24/7
Continuous compliance monitoring, every device
Monthly
Evidence reports your auditor or insurer can use
10+ yrs
Professional IT and security experience
$0
Cost of your compliance gap assessment - no obligation

The Compliance Lifecycle

Not a one-time report. An ongoing process that keeps you audit-ready.

1

Risk Assessment & WISP Development

We evaluate your environment against the regulations that apply to you, then build the written information security plan that documents it.

2

Security Stack Implementation

MFA, backups, email/web filtering, endpoint monitoring, and employee security training - deployed to match what your WISP requires.

3

Continuous Compliance Monitoring

Ongoing monitoring plus a monthly evidence report - documentation your auditor, regulator, or cyber-insurer will actually accept.

4

Annual Review & Audit Support

Your WISP and risk assessment get refreshed every year - and if an audit or regulator inquiry comes up, we're the ones who show up with the paperwork.

What's in the Stack

The safeguards deployed in Step 2 and maintained for the life of your Compliance Monitoring retainer - each one mapped to a specific requirement, not just a feature.

Encrypted, Verified Backups

Automated backups with routine restore testing and encryption at rest - encryption of customer information as the Safeguards Rule requires, plus the recovery capability behind your incident response obligations.

Automated Patch Management

Operating systems and applications patched on a schedule, with monthly reports showing what was applied and when - documented evidence that systems are maintained, not just a claim.

Endpoint Protection & Monitoring

24/7 monitoring for malicious activity across every device - documented detection and response, not antivirus running quietly in the background.

DNS & Web Filtering

Known-malicious sites and phishing infrastructure blocked before a click becomes an incident - a technical safeguard you can point to, not a policy on paper.

MFA Enforcement & Password Management

Multi-factor authentication and managed credentials across your accounts - the access control requirement named directly in the Safeguards Rule and NYDFS regulation.

Security Awareness Training & Phishing Simulations

Ongoing employee training with tracked completion, plus simulated phishing tests - the workforce training element these regulations require you to prove, not just provide.

Continuous Compliance Posture Monitoring

Ongoing visibility into your security posture across the whole stack, feeding directly into your monthly evidence report.

Every one of these produces documentation - your monthly evidence report shows patches applied, backups verified, training completed. When your auditor or insurer asks, you have proof, not promises.

This is what your Compliance Monitoring retainer covers. Fixing gaps your risk assessment finds is scoped and billed separately - see Pricing.

Less Than the Cost of a Compliance Hire -
For Ongoing, Documented Protection

Most small firms don't need a full-time compliance officer. They need a defensible, documented program - right-sized for firms under 25 people.

vCISO / Compliance Consultant 716 Tech Support
Annual Cost Full-time or fractional CISO engagement
$60,000–$150,000+/year
From $7,800/year
$650/mo retainer, up to 10 users
Documentation Assessment report delivered once, then it ages Written WISP + monthly evidence reports
Audit Readiness Point-in-time snapshot; evidence gaps open up between engagements Documentation ready before you're asked
Monitoring Advisory only - monitoring left to you or your IT provider 24/7 monitoring across your environment
Regulatory Expertise Broad framework experience, often not New York-specific FTC Safeguards Rule, NY SHIELD Act, NYDFS-specific
Existing IT Relationship Consultants often require replacing your IT Works alongside your current IT provider
Contract Consultants often require long engagements Month-to-month retainer, cancel with notice

We deliver the compliance outcomes a small firm actually needs - documented risk assessments, a WISP, and audit-ready evidence - not a full in-house CISO function.

Simple, Transparent Pricing

Priced around the work - getting audit-ready, then staying audit-ready - not seat count.

Most clients start with the Risk Assessment, then move into Compliance Monitoring - the Annual Review is included free in your first year on that retainer. Think of it as a sequence, not a menu.

Risk Assessment & WISP
$2,500 one-time
Up to 10 users - scales to $4,500 for 11–25 users
  • Full risk assessment against the regulations that apply to you
  • Written Information Security Plan (WISP), delivered as a document you own
  • Prioritized remediation roadmap
  • Employee security training kickoff session
  • Gap analysis: FTC Safeguards Rule / NY SHIELD Act / NYDFS, as applicable
Start With an Assessment
Annual Review & Audit Support
$1,200/yr
Renewal add-on for Compliance Monitoring clients
  • Annual WISP refresh and updated risk assessment
  • Direct support if an auditor, regulator, or insurer comes asking
  • Updated documentation package for renewals
  • Priority scheduling ahead of your renewal deadlines
  • Included free in your first year of Compliance Monitoring. $1,200/yr starting Year 2, or for clients who did not start on the Compliance Monitoring retainer.
Ask About Audit Support

Remediation work - actually fixing what the risk assessment finds - is billed separately, hourly or per-project. Every remediation project is scoped and quoted before work begins, so there are no surprise bills.

Why Firms Choose 716 Tech Support

There are compliance platforms and there are national consultants. Here's what makes the difference.

Locally Owned - Western New York

Based in Buffalo, not a national compliance SaaS platform. Regulated firms trust a local human they can actually call.

Certified and Experienced

10 years of professional IT experience. Currently holding Cisco CCNA and Microsoft AZ-700 Azure Network Engineer, on a foundation of CompTIA A+, Network+, and CIOS.

Documentation Built to Be Used

Every report is written for the audience that'll actually read it - your auditor, your insurer, or a regulator - not just filed away.

Co-Managed, Not Territorial

We fit alongside your existing IT relationship instead of trying to replace it.

Vendor-Neutral Security Stack

We choose tools based on what fits your risk profile and budget - not a single vendor's product line.

Transparent Pricing

You know the cost of your assessment, your retainer, and any remediation work before anything starts.

Built for Regulated Small Businesses

We specialize in the industries where "we take security seriously" has to hold up to a specific regulation.

CPA & Accounting Firms

Tax preparation and many accounting services fall under the FTC Safeguards Rule, which requires a written security program, a designated Qualified Individual, and documented safeguards. We determine whether it reaches your practice, then build and maintain the program it calls for.

Law Firms

Client confidentiality obligations and New York's SHIELD Act both demand reasonable security safeguards for private information. We help you document and prove you're meeting them.

Financial Advisors & Insurance Agencies

Between the NY SHIELD Act and NYDFS cybersecurity regulation, financial and insurance practices face some of the strictest documentation requirements in the state. We keep you current and defensible.

Handle Sensitive Client Data?

Healthcare-adjacent practices, real estate, or any small firm handling private client information may be closer to a regulatory requirement than you think. If it sounds like you, let's talk it through.

Meet Alexander DeKalb

Owner & Founder, 716 Tech Support - Buffalo, NY

Alexander DeKalb - Owner of 716 Tech Support

I've spent 10 years in professional IT - from enterprise network infrastructure to small business support. I founded 716 Tech Support after seeing how many regulated small firms in Western New York were exposed: no written security plan, no documented monitoring, nothing to hand a regulator, insurer, or client's audit team if they came asking.

I built this practice around closing that specific gap - as a separate engagement from whoever already handles your day-to-day IT. A documented risk assessment, a real written information security plan, and ongoing monitoring with evidence you can actually produce when it matters.

Professional Certifications

Current Certifications
Cisco CCNA Certification
Cisco CCNA Active
Microsoft Certified: Azure Network Engineer Associate (AZ-700)
Microsoft AZ-700 Azure Network Engineer
Professional Foundation
CompTIA Network+
CompTIA Network+ Previously Certified
CompTIA A+
CompTIA A+ Previously Certified
CompTIA CIOS
CompTIA CIOS Previously Certified
10+ Years Professional IT Experience
Hands-On Security Endpoint, Network & Email Protection
Network Engineering CCNA - Enterprise & SMB Networks
Microsoft Certified AZ-700 Azure Network Engineer
Compliance Focus FTC Safeguards Rule, NY SHIELD Act, NYDFS

What Happens After You Sign Up

The engagement runs on a defined schedule. Here's exactly what to expect.

Timeline shown for clients starting on the Compliance Monitoring retainer. An assessment-only engagement concludes with your WISP and remediation roadmap.

Day 1

Kickoff & Environment Review

We meet, review your current setup, and confirm which regulations apply to your business before any work begins.

Week 1

Risk Assessment Conducted

We evaluate your environment against the applicable regulation - devices, accounts, data handling, vendor relationships. Gaps get documented, not guessed at.

Week 2–3

WISP Delivered & Security Stack Deployed

Your written information security plan is delivered, and MFA, backup, filtering, and monitoring get configured to match it.

Month 1

First Monthly Evidence Report

You receive your first automated compliance report - the same kind of documentation an auditor or insurer will expect to see going forward.

Ongoing

Continuous Monitoring & Quarterly Check-Ins

Monitoring runs in the background, evidence reports arrive monthly, and we check in quarterly - so compliance doesn't quietly lapse between assessments.

Common Questions

Answers to what most firm owners ask before their first call.

The FTC Safeguards Rule sits under the Gramm-Leach-Bliley Act and applies to "financial institutions" that aren't regulated by another federal agency. Section 314.2(h) of the Rule lists thirteen example categories, and they're broader than the name suggests - tax preparation services, accountants providing certain financial services, mortgage brokers, financial advisors, collection agencies, and "finders" are all named. Covered firms must maintain a written information security program, designate a Qualified Individual to oversee it, and implement specific safeguards.

Whether it reaches your firm depends on what activities you actually perform, not just what industry you're in - a practice doing tax prep is treated differently than one doing audit and attest work only. Determining which side of that line you fall on is part of the free gap assessment.

New York's SHIELD Act requires any business holding private information of NY residents to maintain "reasonable" administrative, technical, and physical safeguards. It applies broadly - law firms, financial advisors, insurance agencies, and most professional service firms are covered.

If the FTC Safeguards Rule or NYDFS cybersecurity regulation applies to your business, yes - a WISP isn't optional. Even under the SHIELD Act's more general "reasonable safeguards" standard, a documented plan is the clearest way to demonstrate compliance if you're ever questioned.

Partially, and it's narrower than most firms expect. Maintaining information on fewer than 5,000 consumers exempts you from four specific provisions: the written risk assessment, the penetration testing and vulnerability assessment schedule, the written incident response plan, and the annual written report to leadership. That's it. You still need a written security program, a designated Qualified Individual, access controls, encryption, MFA, employee training, and service provider oversight.

The other catch: the threshold counts every consumer record you hold, not your active client list this year. Firms that have been in business a decade and retain records for the required period are often well over 5,000 without realizing it. If you're relying on the exemption, that assumption is worth documenting rather than presuming - a presumption of exemption rarely survives scrutiny on its own.

No. We work alongside your existing IT provider or in-house staff. We handle the compliance-specific layer - the risk assessment, the WISP, the safeguards those documents call for, and the monthly evidence reporting - without touching your day-to-day IT relationship.

That's exactly what we prepare you for. Between your WISP, monthly evidence reports, and annual review documentation, you'll have a paper trail ready to hand over - not a scramble to assemble one after the fact.

A consultant typically hands you a report and leaves. We build the plan, implement the technical safeguards behind it, and keep monitoring and documenting on an ongoing basis - so compliance doesn't quietly lapse six months after the assessment.

Yes - remediation (fixing the gaps we find) is available as separate hourly or project work, scoped and quoted upfront before anything begins.

That's part of the free gap assessment. We'll look at what data you handle and who you serve, and tell you plainly which regulations apply and where your actual exposure is.

Get Your Free Compliance Gap Assessment

No commitment. No cost. We review what data you handle, which regulations apply, and where your actual exposure is.

Get in Touch

Service Area

Buffalo · Cheektowaga · Williamsville
Amherst · Tonawanda · Lancaster
West Seneca · Erie County

Business Hours

Monday – Friday: 8AM – 6PM
Compliance Monitoring clients get a quarterly check-in and direct contact

The assessment is free, takes about 30–45 minutes, and carries zero obligation. You'll walk away knowing exactly which regulations apply to you and where the gaps are - even if you don't sign up.

Request Your Assessment