lutz logo
lutz logo
  • Services
  • News & Insights
  • About
  • Client Portal
Search
  • Services
  • Accounting
  • Advisory
  • Financial
  • M&A
  • Talent
  • Tech
  • Accounting Services
Services
  • Audit & Assurance
  • Client Advisory Services
  • Outsourced Accounting
  • Tax
  • Business Valuation
  • Litigation Support & Forensic
View All
Industries
  • Agribusiness
  • Construction
  • Family Office
  • Healthcare
  • Manufacturing & Distribution
  • Nonprofit
View All
News & Insights
Financial Access Checklist
Guide
Financial Access Checklist

Share this information with your spouse to assure you each have access to manage important financial tasks independently.

Read More
  • Advisory Services
Services
  • Accounting
  • Financial
  • M&A
  • Talent
  • Tech
View All
Resources
The Art of Budgeting
Recording
The Art of Budgeting + Smart Saving Strategies
Learn how to get your finances under control and increase your savings! Hear real-life examples and best practices to secure a successful future.
Watch Now
Business Insights
Comparing Business Valuation Methods
Blog
Comparing Business Valuation Methods: Which is Right for You?
Valuation experts rely on three primary approaches to determine the value of a business: income approach, asset approach, and market approach.
Read More
  • Financial Services
Services
  • Financial Planning
  • Investment Advisory
  • Retirement Plan Services
  • Pooled Employer 401(k) Plan
View All
Resources
  • Lutz Financial Blog
  • Our Team
  • Client Portal
  • Charles Schwab Login
  • Send Files Securely
Contact Us
NEWS & INSIGHTS
Website Featured Content Images
Market Commentary
Financial Market Updates

Want to receive financial market updates straight to your inbox? Sign up below!

Subscribe
  • M&A Services
Services
  • Sell-Side Representation
  • Transaction Advisory
  • Exit Planning
  • Business Valuation
View All
Resources
Selling a C Corporation
Blog
Factors to Consider When Selling a C Corporation

Understand the tax issues affecting both buyers and sellers involved in C corporation merger and acquisition transactions

Read More
Business Insights
Post-Acquisition Checklist
Guide
Post-Acquisition Checklist for a Seamless Transition
To help you navigate this critical period, we've compiled a comprehensive checklist covering key areas that demand attention after the deal closes. 
Read More
  • Talent Services
Services
  • Search & Staffing
  • Outsourced HR
  • HR Consulting
View All
Candidate Resources
  • Job Seeker Process
  • Current Opportunities
  • Lutz Internships
Contact Us
News & Insights
Overcoming Bias in Recruitment
Blog
Unconscious Bias in Recruitment: How to Overcome It
Learn how to take the bias out of recruitment and build a diverse, talented workforce with these tips.
Read More
  • Tech Services
Services
  • Outsourced IT
  • Data Analytics
  • Technology Strategy
  • Software Consulting
View All
Resources
When to outsource your IT
Blog
How to Know When It's Time to Partner with an IT Pro

One day your technology seems manageable, and the next you're wondering if you need more support. Here are the clear signs it's time to outsource your IT.

Read More
Business Insights
Untitled design (1)-Mar-08-2024-08-50-35-9527-PM
Video
Pella Client Testimonial
"I've used them for valuation work, stock transfers, hosting all of my technology, and now data analytics. I'd say they lead the pack in terms of anticipating what I'm going to need before I even know I need it."
View Now
Business Insights
BLOG
Explore Topics

Get the latest news and insights on relevant topics that matter most to you.

View All
Webinars & Events
Events
Register Today

Register for an upcoming event or access our library of on-demand recordings.

View All
Financial Market
COMMENTARY
Stay Informed

Catch up on market moves with our weekly update, featuring in-depth insights and analysis.

View All
Resources
EBOOKS & GUIDES
Download Now

Take a deep dive into challenging business topics with these free educational resources. 

View All
  • News & Insights
  • Business Insights
  • Webinars & Events
  • Financial Market
  • Resources
Business Insights
BLOG
Explore Topics

Get the latest news and insights on relevant topics that matter most to you.

View All
  • About
About

Lutz is a business solutions firm for people seeking a partner to help energize and heighten economic and organizational success.

Our Company
Our Team
Offices
Careers
Internships
Contact Us
  • Contact
Client Portal

Log in to your relevant client portal to access your account, upload documents, or make a payment.

Make a Payment
Accounting Client Portal
Financial Client Portal
Charles Schwab Login
Send Files Securely
Contact Us
  • Cybersecurity

A Beginner's Guide to Cybersecurity

Scott Kroeger, Lutz Tech Shareholder
March 24, 2022
A Beginner's Guide to Cybersecurity

Every business that operates online has critical data which, if accessed by unauthorized people, could result in major disruptions in operations. Worst case scenario, such access can lead to the downfall of a business. For that reason, companies today invest heavily in cybersecurity to ensure all of their private data remains safe and secure from access by hackers. 

If your business lacks proper IT security, there is no need to worry. This guide details the options available for you to boost your IT security structure. 

 

What are the IT security options available for my business?

Luckily for you, there are a variety of ways you can ramp up your IT security. Some of the most common processes/services include:

1. IT Security Assessment / Cybersecurity Assessment

A cybersecurity assessment is the most comprehensive option that you can go for. Essentially, it involves reviewing and benchmarking most areas in your business to expose any operations, practices, or system configurations that pose a threat to the exposure or leakage of your data.

The assessment will ensure you cover servers, routers, firewalls and workstations. For efficiency, the assessment will go the extra mile to include procedures, policies, and operational practices. 

At the end of the assessment, you will get a 20-50 page report containing an outline of your business's current state alongside some viable recommendations of what you can incorporate to tighten up your IT security. It is recommended that you perform an IT security assessment once every two years. Therefore, if you are interested in this service, the current market price ranges from $15,000- $50,000.

2. IT Security Audit / Cybersecurity Audit 

A security audit is an overall assessment of the organization's security status - both physical and non-physical. The aim of this audit is to expose any loopholes that cybercriminals may use to cause a cyberattack on your business. Majorly, security elements (PCI, SOC, HIPAA, GLBA) are assessed in detail through security scans to identify loopholes and deal with them accordingly.

At the moment, assessing the above-mentioned security elements will cost you, as indicated below:

  • PCI audit- $30,000 - $50,000
  • SOC audit- $30,000
  • HIPAA audit- $20,000 - $30,000
  • GLBA audit- $35,000 - $60,000

In that case, if you need to ramp up your cybersecurity structure, make sure to conduct an audit at least twice a year.

3. Penetration testing

As the name suggests, this test helps determine what cybercriminals can access and the extent of damage they can cause once that data is accessed. To get accurate results, the test simulates a real-world attack on your organization and exposes any and all security gaps. Once done, you are advised accordingly on how to seal these holes, thereby strengthening your security structure.

Penetration testing exists in two main categories:

  • External penetration- Works by simulating an attack on your organization by hackers from anywhere in the world.
  • Internal penetration- Works by simulating an attack from within your own network.

Subcategories include:

  • Application- This subcategory works by testing custom-developed web applications. One thing to note here is that most loopholes are created by weak code development.
  • Physical - Tests the physical access to data in your organization.
  • IoT - In this category, IoT devices are tested (emphasis made on custom OS distros).
  • Social Engineering- Here, a test is done on your employees to check for vulnerabilities in accessing your organization's data.

Currently, the cost of running a penetration test stands in the $5,000-$20,000 range. Additionally, it is recommended that you conduct this service at least once a year.

4. Vulnerability scanning

A vulnerability scan is a regular check of your business environment to try and identify vulnerabilities and fix them. It is conducted quarterly and can be done in two ways:

  • External vulnerability- Here, the scan tests the security of the systems which are exposed to the internet space. For instance, firewalls and servers are all tested.
  • Internal Vulnerability- This method scans and tests any systems which are not exposed to the internet. For instance, workstations, servers and network infrastructure are all tested.

The current market price for vulnerability scanning ranges from $500- $3,000.

5. Risk assessment

As the name suggests, a risk assessment is aimed at evaluating risks to your IT systems and the extent of damage that may occur in the event that it happens. Risk assessments document threats and expose all system vulnerabilities.

For maximum efficiency, we advise you to conduct a risk assessment once annually. This translates to around $6,000 - $40,000, depending on the extent of the assessment in that year. 

6. Security Awareness Training and Phishing

Another way to improve your IT security structure is by training all your employees on the clients' site. You can teach them using presentations that contain information on how to keep the organization's data safe through good technology practices.

Phishing works by simulating and testing your employees at an individual level to try and identify who is likely or unlikely to click insecure links shared through email. Currently, a security awareness training will cost you anywhere from $1,000 - $2,000. On the other hand, phishing can cost you anywhere from $1,000 - $3,000 annually. If you need this service, some of the companies that offer it include KnowBe4 and SANS institute.

7. IT Forensics

In the event that you get attacked, IT forensics is done to determine how cybercriminals managed to get into and access your system. The procedure also identifies the type of data that was accessed. A report is then compiled with recommendations of how you can seal such loopholes and prevent any future incidences.

One thing to note is that this service is pretty expensive and can cost you up to $300 per hour. Therefore, completing the job can cost you an average of $20,000, with $8,000 being on the lower side and $75,000 being on the higher side. 

8. Security Policy Creation

This service assists businesses in creating a technology policy. For instance:

  • Cybersecurity
  • Acceptable use of technology at work
  • Business continuity plan

Typically, this service can cost you up to $6,000, inclusive of a template which costs around $3,000, and an interview with your staff which can cost $3,000 to customize it to your organization. If you have already set policies, it is advised that you review them at least once a year.

9. Vulnerability Remediation

One thing about all the services mentioned above is that once something has been identified, say a potential risk, many items need to be remediated. This includes:

  • Adding patches
  • Starting and stopping some services
  • Updating firmware

However, it is worth it that you know that most of the major security companies do not conduct the remediation of the affected items. Therefore, this task is left to your IT department or Managed Service Provider (MSP) to handle.

With that in mind, these services are charged by multiplying a rate by the number of hours taken to complete the task. Rates will vary. It is also important that the company conducting a security assessment is not the same one to conduct the remediation.

 

Key Takeaway

The IT security for your business matters a lot. Therefore, you are encouraged to take the necessary measures to strengthen your IT security structure to prevent access to critical data by outsiders. With that said, feel free to contact us if you have any questions or visit our website to learn more about our Lutz Tech services.

  • Ideation, Strategic, Individualization, Relator, Arranger

Scott Kroeger

Lutz Tech Shareholder

Scott Kroeger, Lutz Tech Shareholder, began his career in 1998. Since joining Lutz in 2011, he has played a foundational role in growing Lutz Tech—leading the acquisition and integration of two MSPs and expanding the division from 13 to more than 70 team members. His leadership extends across the firm, having served over a decade on the Lutz Board of Directors, eight years on the Lutz Financial Board, and twelve years as the Lutz Tech Department Head. 

Championing Lutz Tech’s service strategy, Scott focuses on executive leadership, business development, operations, and client relationships. He values collaborating with the team and delivering peace of mind to clients through reliable IT solutions that help their businesses thrive. His background across software and services industries gives him a broad perspective, and he is passionate about building scalable, practical technology strategies. 

 

At Lutz, Scott makes the complex simple by translating business needs into smart, results-driven solutions. His ability to build meaningful relationships and arrange resources efficiently has been pivotal in the substantial growth of the firm's technology practice. Scott consistently strives to develop strategic solutions that advance the firm's technological capabilities. 

 

Scott lives in Omaha, NE, with his wife, Wendi, and their four children—Kelly, Chase, Leo, and Emmy—along with their two dogs, Nicky and CeCe. Outside the office, you can find him golfing or enjoying the outdoors. 

402.827.2304

skroeger@lutz.us

Connect on LinkedIn

Recent News & Insights

Job Seeker
5 Ways to Maximize Your Chances of Employment
Let’s face it, job searching can be a rollercoaster. One moment you're motivated, the next ...
Read More
Guide
Finding a Lifelong Career
You’ll spend over 90,000 hours of your life at work. That’s more time than you’ll spend with ...
Read More
Rural Hospital
CMS Announces New Method II Billing Edits for Critical Access Hospitals
Starting July 1, 2025, Critical Access Hospitals (CAHs) that bill under Method II will face a ...
Read More
Market Commentary
The Dollar and International Diversification + 4.30.25
With recent tariff and trade news, the tone and trading of the dollar has decidedly changed. ...
Read More
module-bg-desktop module-bg-mobile

Let’s get you where you want to go.

We work to simplify complexities, help make critical business decisions, and confidently focus on the things that are truly important to you. We embrace your business as our own to spark the right solutions and help you thrive.
Contact Us
Lutz-Logo-white
  • Services
    • Accounting
    • Consulting
    • Financial
    • M&A
    • Talent
    • Tech
  • About
    • Our Company
    • Our Team
    • Offices
    • Careers
    • Internships
    • Current Opportunities
  • Client Portal
    • Make a Payment
    • Accounting Client Portal
    • Financial Client Portal
    • Send Files Securely
    Submit RFP
TOLL-FREE: 866.577.0780 | © Lutz & company, PC 2025 | Privacy Policy
Follow us on Facebook Follow us on LinkedIn Twitter - X Logo Follow us on Instagram Follow us on Facebook