Updated October 2026. Originally published January 30, 2025.
You can’t protect what you haven’t measured. Exploiting vulnerabilities is now the most common way attackers get into a business, at 31% of breaches, overtaking stolen credentials (Verizon DBIR). Assessing your IT security on a regular schedule is how you find those openings before someone else does. Having security tools in place is only the start; you also have to keep checking that they work and keep strengthening them.
Why a security assessment matters now
Most organizations are falling behind on the fixes that matter most. Only 26% of the critical vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully remediated in 2025, down from 38% the year before, and the median time to fix them grew to 43 days (Verizon DBIR). CISA recommends using that catalog to decide what to patch first (CISA). Aging systems add to the problem: Windows 10 stopped receiving free security updates on October 14, 2025, so any PC still running it without extended updates is falling further behind every month (Microsoft).
How Starfish Computer assesses your environment
Starfish Computer starts by learning how your business works and which technology it depends on. Then we evaluate your network systematically with our assessment tool, looking for weaknesses an attacker could exploit.
Detailed equipment analysis. We review every device on your network, from firewalls and switches to servers and workstations, looking for weak configurations, unsupported software and outdated hardware that create risk.
Identifying security gaps. We look for common oversights such as missing multifactor authentication and open ports. CISA notes that some forms of MFA can still be phished or bypassed and calls phishing-resistant MFA the gold standard (CISA), so we check which kind you use, too.
Custom solution design. We turn the findings into a plan built for your company: the policy changes needed to tighten security, user training that helps staff spot and report threats, and any additional tools that would strengthen your defenses.
A structured process for immediate and long-term protection
Findings only help if they get fixed in the right order. We roll out improvements in phases so the most serious risks are handled first and the cost and workload stay manageable.
Immediate actions. Critical changes, such as resetting compromised passwords or closing an exposed port, happen right away. Simple policy changes can sharply reduce risk in days.
Priority-based execution. We lay out the order in which the remaining issues should be addressed, so your budget goes to the most severe threats first.
Ongoing partnership. Security isn’t a one-time project. We reassess as your business and the threats change, and we align the plan with the NIST Cybersecurity Framework 2.0, which NIST designed for organizations of every size, including small businesses (NIST).
For Ohio businesses there is a legal reason to document this work. Under Ohio law, a business that maintains a written cybersecurity program reasonably conforming to an industry-recognized framework can use it as an affirmative defense against certain tort claims after a data breach (Ohio Revised Code).
Schedule your IT security assessment
Don’t leave your IT security to chance. Rather than waiting for a real attack to show you where the gaps are, let Starfish Computer stress test your environment first. Contact us to schedule an assessment. Our team, including experts like Adam, will work with you to build a security plan that fits your business and keeps your data and operations safe.
Protect your business: start with an assessment
The question isn’t whether your business will face a cyber threat, but whether you’ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:
Assess current security posture and risk
Plan a cybersecurity roadmap aligned to NIST CSF 2.0
Implement the right tools and processes for your size and budget
Train your team on today’s threats, including AI-driven scams
Support and improve your security over time
Call (440) 808-0468 or visit starfishcomputer.com to schedule a security assessment.
About the author
R.J. Arhar is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of Attack or Defend – When is Enough Cybersecurity Enough?
This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.

