Security & IT Leadership for Your Business

A security leader in your corner.
Without the full-time hire.

Your IT team manages the tools. But who owns the full picture, security controls, compliance, vendor oversight, insurance readiness, and AI governance across every site? That's the job of a CISO. Most growing businesses can't justify the hire, but they can't afford the gap. We make it affordable.

43%
of cyberattacks target small businesses.

Most don't have a security leader reviewing their systems, compliance, or response plan.

Source: Verizon Data Breach Investigations Report

200+
security settings live inside Microsoft 365.

The average business has configured fewer than 30. We close the gap, across every site, every system.

Source: Microsoft Secure Score data

194 days
is how long the average breach goes undetected.

Your IT team manages the tools. But who's watching the full picture, compliance, risk, and proof it's working?

Source: IBM Cost of a Data Breach Report

Ready when you are

See where your business stands.

Schedule your discovery call below. 20 minutes, no prep, no pressure.

Less risk. More proof. No drama.

The problem

Most businesses don't know what they don't know.

You have an IT provider, you have tools, and you might even have cyber insurance. But do you have full visibility into your security posture across every system, every site, and every compliance requirement your business is responsible for?

Who's reviewing your access controls, validating your backups, tracking your vendor SLAs, and documenting proof for your insurer?

The Four-Leaf Security System

Four goals. One outcome: less risk, more proof.

We organize every engagement around four simple goals. Start with Clarity. Layer the rest without overwhelm.

Clarity

We audit your cloud, email, and endpoints, then tell you exactly what's exposed.

Learn more →

Shield

MFA, password vaults, email filtering, and endpoint hardening: the controls insurers check first.

Learn more →

Guardrails

Adopt AI safely with data checks and governance controls.

Learn more →

Assurance

Steady monitoring, quarterly reviews, and incident response, month after month.

Learn more →
How it works

Three clear steps. Less confusion. Better control.

1

Assess

We review your cloud, identity, endpoints, AI tools, MSP contracts, and insurance posture. About an hour of your time.

2

Standardize

We turn findings into action: policies, configurations, MSP alignment, and tool validation. One consistent standard.

3

Lead & Monitor

Your named vCISO runs ongoing oversight. Monthly reports, quarterly reviews, incident coordination, and proof artifacts.

AI Practical Governance

Your team is already using AI. The question is whether it’s safe.

We don’t block AI. We help you adopt it with policies, controls, and oversight that protect your data and keep you compliant. Our 3-P Framework gives you a clear checklist.

People

Train the team on the 5 rules
Name an owner for AI access approvals
Set a monthly review date for AI connections and permissions
Create an incident response contact list
Document AI tool inventory

Permissions

Use a dedicated "AI Service" user account
Remove admin roles from the AI account
Limit access to one shared folder, not the whole drive
Limit mailbox scope to one mailbox, not all mail
Use Conditional Access where available
Require MFA, block legacy auth

Privacy

Create an "AI Work Zone" folder
Move only approved docs into that folder
Do not store client regulated data unless approved and encrypted
Review folder contents quarterly
Document what data is AI-accessible
"

The assessment didn’t just help us understand and secure our Microsoft 365 environment. It gave us documented evidence we could show our cyber insurer. We finally know where we stand.

- Principal, Regional Insurance Brokerage

Ready to see where you stand?

Start with a 20-minute discovery call. No prep, no pressure, no pitch.

Cyber Risk Assessment

Find the gaps before someone else does.

A 7-day assessment of your Microsoft 365, Google Workspace, and AI environment. You get a scored report, a 14-point insurance readiness review, and a prioritized roadmap.

Takes about 20 minutes to start · no prep required

What you get back

Nine deliverables. One clear picture.

State of IT reportWhat’s in place, what’s not, where you’re exposed
Cybersecurity gap reportSpecific findings mapped to the Four-Leaf System
14-point Insurance Readiness ScorecardScored against what carriers actually check
MSP / IT provider contract summaryWhat your providers commit to, and where the gaps are
Asset inventoryEndpoints, networking, applications, cloud services
Dark web credential scan resultsCompromised accounts tied to your domain
AI tool exposure mapWhat AI tools your team uses and how they connect to your data
Risk registerTop risks prioritized by impact and likelihood
90-day hardening roadmapWhat to fix first, and who does it
See it before you buy it

What the report actually looks like.

A real leadership summary, built from your assessment data. Scored, prioritized, and ready to hand to your insurer, your board, or your IT provider.

Sample report · illustrative data only
Black Clover Cybersecurity
BLACK CLOVERCYBER SECURITY
Prepared for Sample Business Group Leadership Team

Cyber Readiness — Leadership Summary

Across 12 assessed sites, 3 low-risk, 3 medium-risk, and 6 high-risk. 2 of 14 sites not started yet.

↓ Download PDF 🔗 Public view 📄 vCISO plan
Executive summary / overview

Where things stand: we assessed 12 of 14 sites. Group readiness averages 68 out of 100, with 3 low-risk, 3 medium-risk, and 6 high-risk. The same gaps show up at more than one site, most often tested backups and multi-factor login. Fixing these once, as a group, helps more than fixing each site on its own. Recommendation: close the urgent items at each site now, then handle the repeating gaps as a group, with shared oversight, so every site improves the same way.

Group readiness
68
Medium risk
Strengths & deficiencies by area
Accounts & Access56% · Partial
Devices & Email68% · Partial
Data & Recovery33% · Needs work
Response & Oversight27% · Needs work
68
Avg score*
10
Completed
2
Partial
2
Not started
3
Low risk
3
Medium risk
6
High risk
Priority insights — top group findings
  • Immediate attention: tested backups flagged at most assessed sites.
  • Immediate attention: multi-factor login (MFA) flagged at multiple sites.
  • Immediate attention: device protection (EDR) flagged at multiple sites.
  • Incident response plan flagged at every assessed site.
  • Activity monitoring and logging flagged at every assessed site.

Sample layout shown for illustration. Your report reflects your own environment and findings.

14-Point Insurance Readiness Checklist

What carriers actually check at renewal.

We score you against all 14 during the assessment, not after months of services.

MFA coverage
Endpoint protection (EDR)
Email security
Backup & disaster recovery
Patch management
Vulnerability management
Identity & access controls
Admin account controls
Incident response plan
Security awareness training
Network segmentation
Encryption (rest + transit)
Vendor / third-party risk
Logging & monitoring
After the assessment

Two paths. Your call.

You handle it.

Take the report and roadmap to your IT provider. Use the 14-point scorecard at your next insurance renewal. Done.

We lead it.

Black Clover executes the hardening plan, standardizes your tools and MSP contracts, and transitions to ongoing vCISO / vCIO leadership.

Assessment

$2,000 – $3,750
per site · multi-site scoping available. Talk to an advisor

Monthly Retainer (vCISO/vCIO)

$4,500 – $8,750
per month · $350–$450/hr based on hours and sites in scope

Start with a Cyber Readiness Review.

20 minutes. No prep. We'll walk through your setup and tell you exactly where you stand.

Services

What your vCISO actually does.

We don’t replace your IT provider. We make them better. We don’t sell tools. We make sure the right ones are in place and working.

Clarity

Clarity: Find the gaps.

Assessment, risk visibility, and scoring.

  • Cloud tenant configuration review (M365 / Google Workspace)
  • Dark web compromised-credential scanning
  • AI tool usage and exposure mapping
  • Asset, vendor, and application inventory
  • MSP / IT provider contract review
  • 14-point Insurance Readiness Scorecard
Shield

Shield: Make sure protection is in place.

Advising, validating, and managing the protections your MSP should be running.

  • Review and standardize endpoint, email, and backup tools across sites
  • MFA enforcement validation across all accounts
  • MSP contract review and SLA negotiation
  • Quarterly MSP performance monitoring
  • Backup verification and disaster recovery testing
Guardrails

Guardrails: Use AI and cloud safely.

Policies, controls, and governance for AI and cloud tool adoption.

  • AI Safe Use policy development (People, Permissions, Privacy)
  • Acceptable use policy creation and rollout
  • Data loss prevention configuration
  • Shadow IT and unapproved app detection
  • M365 / Google Workspace configuration hardening
Assurance

Assurance: Stay covered. Month after month.

Ongoing vCISO / vCIO leadership, monitoring oversight, and incident response coordination.

  • Named Virtual CISO / CIO as your senior point of contact
  • Monthly reporting and quarterly security reviews
  • MSP performance review and SLA enforcement
  • Incident response coordination
  • Cyber insurance alignment and renewal support
  • Risk register maintenance and annual budget review

Your virtual CISO: what they do, and what they don’t.

What your vCISO does

  • Owns your security posture across all sites and tools
  • Manages and holds IT providers accountable
  • Leads incident response coordination
  • Produces proof for insurance, audits, and questionnaires
  • Reviews AI adoption and new tool risk
  • Runs quarterly security reviews with leadership
  • Advises on IT budgets and vendor selection

What your vCISO doesn’t do

  • Operate a help desk
  • Sell you endpoint software
  • Run a SOC or monitoring platform
  • Replace your IT provider

Your MSP runs the day-to-day.
Your vCISO runs the program.

Who it’s built for

Businesses that need a leader, not a product.

Multi-site Medical Organizations

Standardize security across locations. HIPAA compliance, patient data protection, one standard.

CPA & accounting firms

Client data obligations, insurance audits, AI tool adoption.

Law firms

Confidentiality, bar compliance, document security, AI policy.

Insurance agencies

Carrier requirements, proving you practice what you sell.

What our clients say

Trusted by businesses like yours.

"Black Clover Cyber gave us insight into our cloud environment that we simply didn't have. Their assessment made it clear what was at risk, what needed attention, and what steps we had to take to protect our clients' financial data. It was eye-opening, practical, and exactly what we needed."

Managing Partner
Local CPA Firm

"Their assessment revealed configuration issues and licensing inefficiencies in our Microsoft 365 environment, simultaneously improving our security posture while reducing unnecessary costs. We didn't even know we had the problem."

Principal
Independent Insurance Brokerage

Ready to see where you stand?

Start with a 20-minute discovery call. We'll review your setup, identify your biggest risks, and map the path forward.

About Black Clover

Security simple enough to run. Strong enough to matter. Documented enough to prove.

Our mission

We give businesses the visibility, protection, and guidance they need to identify risk, manage their security posture, and execute a smarter approach to cybersecurity and AI, so they can focus on running their business.

The team

The people behind the program.

JL

Jeff Lennon

Go-to-Market, Revenue & Sales Advisor
  • Channel and GTM operator, 20+ years in cybersecurity and GRC
  • Builds repeatable partner programs and go-to-market execution
  • Makes security practical and accessible for SMBs
EH

Erik Hanson

Virtual CISO Advisor
  • 16+ years in information security across regulated environments
  • CISSP, PCI-ISA certified
  • Leads client engagements as the named security and IT leader
  • Specialties: GRC, risk management, incident response, NIST CSF

Let's start the conversation.

Whether you need an assessment, a security advisor, or just a second opinion on your setup, we're here.

Get in touch

Let’s talk about where you stand.

Start with a 20-minute discovery call. No prep, no pressure, no pitch.

Drop us a line.

Or reach out directly.

LocationPhiladelphia, Pennsylvania
Serving businesses nationwide

The golden lining:

Most places offer a silver lining. We offer a golden one: clear answers, documented proof, and a leader who's got your back.

The Clover Chronicles

Behind the Shield

Practical security insights for small business leaders. Published every other week, organized around our Four-Leaf Security System.

Clarity
May 15, 2026

The 5 Things Every Cyber Insurance Application Actually Checks

Your insurer doesn’t care about your firewall brand. They care about MFA, EDR, backups, incident response, and access controls. Here’s how to document proof before renewal.

Read more →
Shield
May 1, 2026

Is Your MSP Actually Protecting You? 7 Questions to Ask This Week

Your managed service provider runs your IT. But who’s verifying they’re doing what they promised? These 7 questions separate good MSPs from risky ones.

Read more →
Guardrails
April 17, 2026

The Zero-Click Thief and Why Your AI Might Be Over-Sharing

A new wave of attacks doesn’t need you to click anything. Meanwhile, your team’s AI tools might be sharing data you never intended. Here’s how to check both.

Read more →
Assurance
April 3, 2026

What a Monthly Security Review Actually Looks Like (and Why It Matters)

Most small businesses never review their security posture after the initial setup. Here’s what a real monthly check looks like and why it prevents the slow drift that leads to breaches.

Read more →
Clarity
March 20, 2026

Dark Web Scans: What They Actually Find and What You Should Do About It

Your employees’ credentials might already be for sale. A dark web scan shows you which accounts are compromised, and the three steps to take before attackers use them.

Read more →
Shield
March 6, 2026

MFA Isn’t Optional Anymore: A Plain-English Setup Guide

Multi-factor authentication is the single most effective control against account compromise. If you haven’t enforced it everywhere, here’s a step-by-step guide your team can follow today.

Read more →
Assurance
February 20, 2026

Cybersecurity Best Practices for Small Businesses: What Actually Works

You don’t need a fortune to build strong security. These are the best practices that actually move the needle for businesses with 5 to 100 employees.

Read more →
AI Governance

AI Safe Use for Your Business

AI tools are transforming how businesses operate. But when AI connects to your email, files, and customer data, it creates real security responsibilities. This guide helps you use AI productively while keeping your data protected.

78%
Businesses Using AI
SMBs now deploying AI tools daily
63%
Security Concerns
Organizations reporting AI-related risks
Why It Matters

AI reads everything you give it access to.

When you connect an AI assistant to your email, file storage, or customer databases, you grant it broad access to confidential business records, client personal data, financial documents, and proprietary information. Unlike traditional software that performs specific, limited functions, AI systems search, analyze, and synthesize across multiple sources.

A single compromised prompt, a phishing attack that tricks an employee, or a misconfigured integration can expose years of sensitive communications. The good news: AI security does not require complex technical expertise. Five core rules and straightforward controls can significantly reduce your risk.

Foundation

The 5 Essential AI Security Rules

Each rule addresses a specific vulnerability that attackers or accidents could exploit. Apply these across all AI tools your team uses.

Rule 1

Least Access Wins

Only connect AI to the minimum apps and folders needed for the task. If it only needs marketing docs, it should not have access to HR files, financials, or customer databases.

Rule 2

Separate AI Accounts

Use a dedicated AI workspace account, not a global admin or your main inbox. Create service accounts with limited privileges that can be monitored, audited, and revoked if compromised.

Rule 3

No Secrets in Prompts

Never paste passwords, MFA codes, SSNs, bank info, tax docs, private keys, or medical details into AI prompts. AI platforms often retain conversation history and may use inputs for training.

Rule 4

Treat Unknown Content as Hostile

Do not run AI summaries or automations on external content without a quick human review. Attackers can craft emails or documents to manipulate AI into revealing sensitive information.

Rule 5

Log It and Review It

Turn on audit logs and review AI connected access monthly. Monitoring provides visibility into what AI tools are accessing, when, and on whose behalf. Regular reviews catch anomalies early.

The 3-P Framework

People, Permissions, Privacy

Our framework for AI guardrails and assurance. Three categories, each with actionable controls your team can put in place today.

People

Train the team on the 5 AI security rules
Name an owner for AI access approvals
Set a monthly review date for AI connections and permissions
Create an incident response contact list
Document your AI tool inventory

Permissions

Use a dedicated "AI Service" user account
Remove admin roles from the AI account
Limit access to one shared folder, not the whole drive
Limit mailbox scope to one mailbox, not all mail
Use Conditional Access where available
Require MFA, block legacy auth

Privacy (Data)

Create an "AI Work Zone" folder
Move only approved docs into that folder
Do not store client regulated data unless approved and encrypted
Review folder contents quarterly
Document what data is AI-accessible
AI Readiness

Is Your Business Ready for AI-Enhanced Cybersecurity?

Five categories every business should evaluate before adopting AI tools. Each area builds on the last.

1 Cybersecurity Foundation

  • Enable MFA across all critical cloud services (M365, Google Workspace)
  • Deploy endpoint detection and response (EDR/XDR) on all devices
  • Conduct vulnerability scans and security assessments on a regular schedule

2 Compliance and Risk Visibility

  • Identify which regulations apply to your business (HIPAA, PCI, GLBA, CMMC 2.0)
  • Maintain documentation for security and compliance practices
  • Review access permissions and user roles on a regular basis

3 Operational Readiness

  • Ensure reliable internal or outsourced IT support is in place
  • Document your incident response and disaster recovery plan
  • Require regular risk and security reviews from your MSP or IT partner

4 AI Understanding and Infrastructure

  • Build team familiarity with generative AI concepts and capabilities
  • Test AI tools in controlled, limited-scope environments before broad rollout
  • Confirm your systems (hardware and software) support cloud-based AI applications

5 Growth and Change Readiness

  • Plan how AI fits into your business expansion over the next 12 months
  • Identify routine workflows that automation could streamline
  • Explore how AI can improve client response times, accuracy, or service delivery
Incident Response

If You Suspect a Data Leak

Most breaches get worse because nobody had a plan. These five steps should be documented, printed, and accessible to every person on your team before an incident happens. Quick, decisive action limits damage.

1

Disconnect

Disconnect the AI tool or connector immediately. Stop the bleed before assessing the damage.

2

Reset Access

Reset passwords, revoke active sessions, and disable the compromised account until cleared.

3

Review Logs

Check audit logs for file access, mailbox activity, and data export patterns. Document everything.

4

Notify Leadership

Alert your IT owner, security advisor, and leadership team. The clock starts on notification obligations.

5

Follow Protocol

Execute your incident response plan. If client or regulated data is involved, follow your notification and reporting obligations.

Don't have an incident response plan? That's one of the first things we build during a Cyber Risk Assessment.

Ready to use AI safely?

We help businesses build AI governance that works. Start with a 20-minute discovery call. No prep, no pressure, no pitch.

Assessment Tool

Microsoft 365 Security Assessment

Find out if your M365 environment is configured to protect your business. We'll review your tenant, identify misconfigurations, and deliver a prioritized action plan.

Request Your M365 Assessment

Fill out the form below and we'll reach out within one business day to schedule your review.

Request received.

We'll review your submission and reach out within one business day to schedule your M365 Security Assessment.

Assessment Tool

Security Maturity Check

Understand where your security program stands today. We'll benchmark your maturity across the Four-Leaf Security System and show you the gaps that matter most.

Request Your Security Maturity Check

Fill out the form below and we'll reach out within one business day.

Request received.

We'll review your submission and reach out within one business day to schedule your Security Maturity Check.

Assessment Tool

AI Readiness Quiz

Is your business ready to adopt AI safely? We'll evaluate your cybersecurity foundation, compliance posture, and operational readiness so you can move forward with confidence.

Start Your AI Readiness Quiz

Fill out the form below and we'll reach out within one business day to walk you through the assessment.

Request received.

We'll review your submission and reach out within one business day to walk you through the AI Readiness Quiz.

Client Access

Client Portal Access

Access your Black Clover client portal, assessment updates, and related security documents.

Sign In

Don't have access yet? Contact us

Return to Black Clover Cyber