# Cyber Security | ThatDeveloperGuy > Cybersecurity from ThatDeveloperGuy LLC for government organizations, prime contractors and small and medium businesses: a human security review, monitoring a person reads, an incident response plan you can rehearse, and infrastructure protection that is documented. - [Visible page](https://thatdeveloperguy.com/capabilities/cybersecurity): The human-readable and canonical version of this content. - [Site-wide AI discovery index](https://thatdeveloperguy.com/llms.txt): The root index that joins every scoped discovery file. ## Overview Detect, protect, respond — with a named person reading the results and writing down what should change. ## Page sections - [Security monitoring overview](https://thatdeveloperguy.com/capabilities/cybersecurity#monitoring): The threat map and the 100% readout in the room are illustration. Monitoring in practice is scoped to what you run and reported in plain language on an agreed schedule. - [Security review and system health](https://thatdeveloperguy.com/capabilities/cybersecurity#security-review): A person reads the configuration, the exposure and the logs, and writes down what should change and why. - [Incident response planning](https://thatdeveloperguy.com/capabilities/cybersecurity#response): Who is called, what is isolated, what is preserved, who is told — decided before an incident, rehearsed once. - [Infrastructure protection](https://thatdeveloperguy.com/capabilities/cybersecurity#infrastructure): Patching, segmentation, backups that restore, and access that is granted on purpose. - [Security review process](https://thatdeveloperguy.com/capabilities/cybersecurity#process): Scope, collect, read, report, remediate, re-check. ## Service scope - Problem addressed: Most small organizations and local government offices do not have a security person. They have a laptop fleet, a few servers or cloud accounts, a website, email, and vendors — and nobody whose job is to read the logs, check the configuration, or decide in advance what happens when something goes wrong. The exposure is ordinary: reused passwords, unpatched systems, backups that were never restored, and no plan for the day an account is compromised. - Included: Security review: configuration, exposure and access read by a person, across the systems you name in scope - Included: Monitoring set-up on the systems you already run, with results read and explained in plain language on an agreed schedule - Included: Incident response plan: who is called, what is isolated, what is preserved, who is told — written for your organization and rehearsed once - Included: Infrastructure protection: patching cadence, network segmentation, backups that are restore-tested, access granted on purpose and documented - Deliverable: A written security review with findings ordered by what to fix first, and why - Deliverable: A monitoring summary you can read without a technical background, on the agreed schedule - Deliverable: An incident response plan document plus one rehearsal record - Deliverable: An infrastructure protection checklist with the current state of each item and its owner - Deliverable: A remediation record: what changed, when, and how it was checked - Not included: Compliance certification or attestation of any kind — this work prepares you for a reviewer; it does not certify you - Not included: 24/7 monitoring or guaranteed response times unless written into a specific engagement - Not included: Penetration testing against systems you do not own or have not authorized in writing - Not included: Handling of classified or controlled unclassified information; scope is agreed before any such material is discussed - Not included: Legal advice on breach notification — the plan names when to call counsel, it does not replace counsel ## Questions and answers - **We are a small office with no IT person. Is a security review still worth it?** Yes, and it is the most common case. The review is scoped to what you actually run — usually a handful of laptops, email, a website and one or two cloud services — and the report is written so that whoever manages the office can act on it without a technical background. - **Will this make us certified or compliant?** No. The work prepares you for a reviewer and produces the records a reviewer asks for, but ThatDeveloperGuy does not issue certifications or attestations. If a specific framework applies to you, that is written into the scope and the report maps findings to it. - **Is the monitoring 24/7?** Not by default. Monitoring is set up on your systems and read by a person on an agreed schedule — daily, weekly, or as written into the engagement. Continuous coverage or guaranteed response times are only offered when they are written into a specific agreement. - **What if we are having an incident right now?** Call the number in the footer. An active incident is handled as its own engagement with its own written scope; the incident response plan described here is preparation for next time, not emergency service. - **What access do you need?** Read-only wherever possible, granted by you, with your staff present, and removed when the review ends. Anything that requires more than read access is listed in the scope before work starts. - **Do you work with government offices and prime contractors?** Yes. Government organizations and prime contractors buy through a written requirement and need records that survive the project; the Government Solutions room describes that pathway. Procurement identifiers are shown on this site only once the owner has supplied and verified them. - **What happens after the report?** The agreed fixes are either made by ThatDeveloperGuy or handed to your staff with step-by-step instructions, each fix is checked afterwards, and a short close-out records what changed. ## Related pages - [IT Services](https://thatdeveloperguy.com/capabilities/business-it) - [Government Solutions](https://thatdeveloperguy.com/government) - [Company](https://thatdeveloperguy.com/company)