Frequently Asked Questions

Got Questions? Real Answers.

Everything you need to know about AegisPro, how security assessments work, and what Texas compliance means for your business.

Section 1

About AegisPro.

What does AegisPro CyberShield TX do?

AegisPro CyberShield TX is a Fort Worth-based cybersecurity consulting firm that provides security assessments, compliance gap analysis, staff training, and policy development for small businesses across Texas.

Think of AegisPro as the cybersecurity expert most small businesses can't afford to hire full-time — available when you need an assessment, a compliance review, or an honest second set of eyes on how your business is set up.

What type of businesses does AegisPro work with?

AegisPro works with Texas small businesses that handle sensitive customer data or operate under compliance requirements. That includes:

  • Dental practices, optometry clinics, and healthcare offices (HIPAA)
  • Restaurants and retail shops (PCI DSS)
  • Law firms, financial advisors, and CPAs (client data protection)
  • Any Texas business that wants SB 2610 safe harbor qualification

If your business handles patient records, payment cards, client financials, or any data you'd need to explain in a breach notification, AegisPro can help.

What areas of Texas does AegisPro serve?

AegisPro is headquartered in Fort Worth and serves clients across the DFW metroplex and Houston. On-site assessments are available within a 50-mile radius of Fort Worth at no additional travel cost. Remote services are available to any business in Texas.

For clients outside the standard service area, on-site visits can be arranged with travel costs quoted in advance.

What makes AegisPro different from other cybersecurity firms?

Three things:

  • CISSP-certified: Your assessment is performed personally by a CISSP-certified professional — the gold standard in information security — not handed off to a junior technician.
  • Built for small business: AegisPro is purpose-built for businesses that need real protection without enterprise pricing or complexity. The recommendations fit your size and budget, not a Fortune 500 playbook.
  • Plain language: Reports, findings, and conversations are written for business owners, not IT departments. You'll understand every finding and know exactly what to do about it.
What credentials does AegisPro hold?

AegisPro's founder, Nicholas Turner, holds the following certifications:

  • CISSP (ISC²) — the gold standard for information security professionals, covering security operations, risk management, and compliance
  • CompTIA Security+ — foundational cybersecurity certification
  • Qualys VMDR — Vulnerability Management, Detection & Response

Additionally, Nicholas has hands-on experience across security operations, vulnerability management, risk analysis, and compliance at organizations including DXC Technology, Concentra, and Eyecare Service Partners. More details are on the About page.

Section 2

Services & Pricing.

What services does AegisPro offer?

AegisPro offers four core services today:

  • Security Assessments: A full review of your network, endpoints, access controls, and compliance posture with a written report and remediation roadmap.
  • Compliance Gap Analysis: A targeted review against HIPAA, PCI DSS, SB 2610, NIST, or whichever framework applies to your industry.
  • Staff Training: One-hour on-site or remote sessions covering phishing, passwords, social engineering, and data handling — tailored to your workflow.
  • Policy Development: Custom security policies (acceptable use, incident response, BYOD, etc.) drafted for your business and ready for employee sign-off.

Managed endpoint security and 24/7 monitoring services are in development and launching in 2027. See the Services page for details.

How much does a security assessment cost?

A full Small Business Security Assessment is $1,500 per location. This includes pre-engagement research, an on-site walkthrough, network vulnerability scanning, compliance gap analysis, a written report with prioritized findings, and a remediation roadmap.

AegisPro is currently offering a founding client rate of $750 for a limited number of early engagements. This rate includes the same full assessment at half the standard price.

For complete pricing on all services, visit the Pricing page.

What is the free walkthrough?

Every client engagement starts with a free, no-obligation walkthrough. AegisPro comes to your location for about 30 minutes, takes a look at how things are set up, and gives you an honest read on where you stand.

There's no cost, no contract, and no pressure. If something needs attention, you'll know what and why. If a full assessment makes sense, AegisPro will tell you. If it doesn't, you'll hear that too.

Schedule a free walkthrough here.

Does AegisPro offer ongoing support after the assessment?

Yes. The Security Advisory Retainer is available at $500/month (or $1,350/quarter) for businesses that want continued oversight after the initial assessment. It includes:

  • Quarterly vulnerability scans
  • Policy review and updates as regulations change
  • Direct access to a CISSP-certified advisor for security questions
  • Quarterly compliance status reports
  • Annual reassessment included

The retainer is designed for businesses that want to maintain their SB 2610 compliance posture year-round without hiring internal security staff.

What do I receive after the assessment?

Every assessment produces a written report that includes:

  • An executive summary of your security posture
  • Every finding documented and prioritized by risk level
  • A compliance gap analysis against the applicable framework
  • A remediation roadmap with clear next steps
  • A 30-minute findings review call to walk through the results

The report is written in plain language so you and your team can act on it without needing a translator. Results are delivered within 10 business days of the on-site visit.

Does AegisPro require long-term contracts?

No. Security assessments, staff training, and policy development are all one-time engagements with no ongoing commitment required. The advisory retainer is available on a monthly or quarterly basis and can be paused or cancelled.

AegisPro earns continued business by delivering results, not by locking you into a contract.

Section 3

Cybersecurity Basics.

Why do small businesses need cybersecurity?

Small businesses are increasingly the primary target for cyberattacks. Attackers know that small businesses often lack dedicated security resources — making them easier to breach than larger enterprises.

The consequences of a breach can be severe:

  • Financial losses from theft, ransomware, or fraud
  • Regulatory fines under HIPAA, PCI DSS, and Texas state laws
  • Loss of customer trust and reputation damage
  • Lawsuits from affected customers or partners
  • Without SB 2610 safe harbor, exposure to punitive damages on top of everything else
What is a security assessment?

A security assessment is a systematic review of your business's networks, devices, access controls, and policies to identify weaknesses before an attacker can exploit them.

A typical AegisPro assessment covers:

  • Network infrastructure and firewall configuration
  • Wi-Fi security and network segmentation
  • Remote access and VPN configuration
  • Endpoint and device security
  • Email authentication (SPF, DKIM, DMARC)
  • Access controls, shared credentials, and MFA coverage
  • Compliance posture against applicable frameworks

The result is a written report with every finding prioritized by risk and a clear plan to address each one.

What is phishing and why is it so dangerous?

Phishing is when attackers impersonate trusted sources — a bank, a vendor, a coworker — to trick employees into giving up credentials, clicking malicious links, or transferring money to fraudulent accounts.

It's one of the most common and most dangerous attack methods because it bypasses technical security entirely and exploits human trust. The majority of successful data breaches start with a phishing email.

That's why staff training is one of AegisPro's core services. Teaching your team to recognize phishing before they click is one of the highest-impact, lowest-cost defenses available.

What is ransomware and how can I protect my business?

Ransomware is malware that encrypts your files and demands payment to restore access. Attackers often steal your data before encrypting it and threaten to release it publicly — a tactic called "double extortion."

Key protections include:

  • Regular, tested, off-network backups
  • Email filtering and phishing protection
  • Multi-factor authentication on every account
  • Staff training on suspicious links and attachments
  • Patch management to close known vulnerabilities

A security assessment identifies which of these protections your business currently has in place and which are missing.

What is multi-factor authentication (MFA) and do I really need it?

Multi-factor authentication requires more than just a password to log in — typically a code from your phone, an authenticator app, or a physical security key. Yes, you really need it.

MFA is one of the highest-impact security controls available. It blocks the vast majority of automated account takeover attempts. It's free or very inexpensive to enable and dramatically reduces your risk.

If you're not using MFA on email, banking, POS systems, and admin accounts — that should be your immediate next step.

Section 4

Compliance & Regulations.

What is Texas SB 2610 and how does it affect my business?

Texas Senate Bill 2610, in effect since September 1, 2025, creates a legal safe harbor for businesses that maintain a documented cybersecurity program aligned with a recognized framework like NIST, ISO 27001, or CIS Controls.

The benefit: businesses with a qualifying program in place before a breach receive legal protection from punitive damages in breach-related lawsuits. Without it, your business faces significantly higher exposure if you're sued.

AegisPro's compliance gap analysis specifically includes an SB 2610 qualification review — telling you whether your business qualifies today and what steps are needed if it doesn't. Read more about SB 2610 here.

What is PCI DSS compliance and does my business need it?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for any business that accepts, processes, stores, or transmits credit card information.

If you take card payments — yes, PCI DSS applies to you. The exact requirements scale based on your transaction volume, but every business handling cards must:

  • Maintain a secure network and systems
  • Protect cardholder data
  • Run regular vulnerability scans
  • Implement strong access controls
  • Monitor and test networks regularly
  • Maintain an information security policy

Non-compliance can result in fines, increased transaction fees, and loss of the ability to process cards.

What are the actual penalties for non-compliance in Texas?

Texas has several laws with significant penalties for businesses that fail to protect customer data:

  • Texas Data Privacy and Security Act (TDPSA): Up to $7,500 per violation
  • Texas Identity Theft Enforcement and Protection Act: Up to $50,000 per violation for failing to notify Texas residents of a breach
  • PCI DSS violations: $5,000–$100,000 per month from card networks
  • HIPAA violations (healthcare): $100–$50,000 per violation, up to $1.5 million per year

Sources: Texas Attorney General's Office; Texas Business & Commerce Code, Chapter 521.

I'm not in healthcare or retail. Do I still need compliance support?

Most likely, yes. Compliance applies to more industries than people realize:

  • PCI DSS: Any business accepting credit card payments
  • HIPAA: Healthcare providers and their business associates (lawyers, accountants, IT vendors who touch patient data)
  • FTC Safeguards Rule: Financial institutions including loan brokers and tax preparers
  • Texas SB 2610: Any Texas business that wants safe harbor protection

AegisPro's compliance gap analysis identifies exactly which frameworks apply to your specific business and where the gaps are.

How often should I have a security assessment?

Industry best practice is at least annually, with additional assessments recommended when:

  • You add new systems, payment processors, or critical software
  • You open a new location
  • Staff turnover changes who has access to your systems
  • You expand into a new compliance framework
  • After any suspected security incident
  • Before any external audit or cyber insurance renewal

The advisory retainer includes an annual reassessment for businesses that want continuous coverage between full assessments.

What is a "safe harbor" provision and why does it matter?

A safe harbor provision is a legal protection that shields businesses from certain liabilities — provided they've taken specific, documented protective actions beforehand.

Under Texas SB 2610, businesses with a documented and maintained cybersecurity program in place before a breach receive safe harbor protection from punitive damages in breach-related lawsuits. This can mean the difference between a manageable incident and a business-ending one.

The key requirement is "before a breach." The program must be documented and in place before something goes wrong — not created after the fact. AegisPro's assessment and policy development services are designed to get you there.

Still Have Questions?

Let's Talk About Your Business.

Every business has unique security and compliance needs. Start with a free walkthrough and get answers specific to your situation.