Why “Working IT” Is Not Enough for Regulated SMBs

Even if your systems run smoothly, that alone does not prove you can show how well they perform. For regulated SMBs, regulators focus on the difference between IT that works and IT that you can defend with evidence.
Functional IT answers a question that many regulated businesses often miss.
When asked about IT performance, most small business owners say everything is working fine. Email works, files are easy to get to, and the management system loads as it should. There have not been any problems for weeks.
This answer is true, but it is not the whole story. It only shows that systems are available. The main concern is whether everything is running and people can do their jobs. In the past, managed IT for small businesses just made sure systems stayed up, and that was seen as enough. Providers kept things running so businesses could work without breaks.
But when regulations come into play, whether new or previously unnoticed, your responsibilities grow. Managing protected health information, cardholder data, client files, or other sensitive information entails additional duties. New standards appear, often without clear instructions. IT support for regulated SMBs is different from just keeping things running, and that difference usually only shows up when something goes wrong.
Working IT answers a simple question: Is everything running?
Audit-ready IT has to answer a different question: Can you show proof of what your systems are doing and how you respond to risks?
These are two very different questions. You can say 'yes' to the first one for a long time, but the second might not be answered at all. Keeping systems up is not the main goal; it is a separate issue.
What regulators actually found in 2026
This is not just a theory. There are some recent real cases that prove it.
On April 23, 2026, the HHS Office for Civil Rights announced settlements with four organizations following separate ransomware investigations under the HIPAA Security Rule. Together, the breaches affected more than 427,000 people. The four entities paid a combined $1,165,000 and agreed to corrective action plans that OCR will monitor for two years.
Read the findings, and the pattern is impossible to miss. In every one of the four cases, OCR’s determination included the same deficiency: the organization had failed to conduct an accurate and in-depth risk analysis of the risks and vulnerabilities to its electronic protected health information — the requirement at 45 CFR §164.308(a)(1)(ii)(A).
The problem was not downtime or outages. Instead, the organization had never properly identified or reviewed its risks.
Look closely at one of them. Consociate, a third-party benefits administrator, reported in late 2021 that its systems had been encrypted in a ransomware attack. It subsequently learned that the threat actor had gained access to a server containing ePHI following a successful phishing attack in July 2020. For roughly seventeen months, someone was inside. During those seventeen months, the IT worked. Staff logged in. Claims processed. No dashboard said otherwise.
The breach brought regulatory attention, but the real problem was a lack of basic risk management.
A similar situation happened before. In March 2026, OCR settled with MMG Fusion, a dental software provider, after an incident exposed the protected health information of about 15 million people. OCR found problems such as unauthorized disclosure of PHI, insufficient risk analysis, and failure to notify the affected covered entities of the breach. This was the twelfth time OCR took action under its Risk Analysis Initiative.
MMG paid $10,000, and OCR took the company’s finances into account. But the bigger impact was agreeing to a corrective action plan with three years of federal oversight. The main cost is having to keep proving compliance, no matter the money involved.
During all this time, the dental practices using the software did not notice any IT problems.
The vulnerability nobody filed a ticket about
Threat intelligence data helps explain why these problems keep happening to organizations that think their IT is secure.
Verizon’s 2026 Data Breach Investigations Report — its nineteenth edition, covering more than 22,000 confirmed breaches across 145 countries — found that exploitation of vulnerabilities has become the most common way attackers gain their initial foothold, reaching 31% of breaches, up from 20% the year before. It overtook credential abuse, which fell to 13%. Ransomware appeared in 48% of breaches. Breaches involving a third party also reached 48%, a 60% year-over-year jump. The human element featured in 62%.
But the finding that most precisely indicts “working IT” concerns patching. Of the vulnerabilities on CISA’s Known Exploited Vulnerabilities catalog — the ones confirmed to be under active attack in the wild — only 26% were fully remediated in 2025, down from 38% the previous year. The median time to completely resolve one stretched to 43 days, up from 32. And the median organization had around 16 of them waiting, up from 11.
In practice, an unpatched device can remain on the network unnoticed. It does not slow things down, create support tickets, or set off alarms. So, it often goes unseen.
THE CORE PROBLEM: To users, working IT and vulnerable IT look the same. This is not due to carelessness, but because many risks are hidden by nature and only surface in regulatory findings.
This shows why system availability is an inadequate measure of security. Availability indicates that systems are responsive, but does not reveal unauthorized access. Earlier discussions have addressed the visible costs of IT downtime; equally important are the hidden costs incurred during periods of unbroken operation.
Four questions uptime cannot answer.
When auditors, regulators, or cyber insurance reps check your systems, they do not ask about uptime. Instead, they ask four key questions that standard dashboards do not answer.
- What do you have? An accurate inventory of every system that creates, receives, maintains, or transmits regulated data — including the SaaS tool someone signed up for with a company card. OCR’s own guidance for preventing these incidents starts exactly here: identify where the data lives and how it enters, moves through, and leaves your systems.
- Who can reach it? Not who should. Who can. Which accounts hold administrative rights? Which vendor has a standing connection to your network? Whether a departed employee’s credentials still authenticate.
- What did you know, and when? This is the risk analysis. Dated, current, and covering the environment you actually run rather than the one a template assumed.
- What did you do about it? This is risk management — the requirement that sits immediately after risk analysis in the Security Rule, at §164.308(a)(1)(ii)(B). Findings are converted into fixes with owners, dates, and evidence.
A business can look like everything is working, but still miss all four of these points. This often happens when IT is managed solely for uptime, even if providers deliver on their promises.
What a breach costs when you cannot show your work
IBM’s Cost of a Data Breach Report 2025 — the most recent edition available as of this writing — puts the global average cost of a breach at $4.44 million. The United States average reached $10.22 million, an all-time high, which IBM attributes in part to higher regulatory fines, detection, and escalation costs. Healthcare remained the most expensive sector at $7.42 million, its fourteenth consecutive year at the top. Across all industries, organizations averaged 241 days to identify and contain a breach: 181 days to find it, another 60 to shut it down.
It is important to read these numbers carefully. They come from organizations of all sizes, many much bigger than most small businesses, so $10.22 million is not a direct prediction for SMBs. The main point is that higher costs in the US mostly come from regulatory and legal expenses, which standard IT does not cover.
Also, if a control is only checked during the last assessment, it is not checked again for the rest of the year. Uptime reports do not indicate whether these controls have weakened over time.
The deadline moved; the obligation did not.
If you are waiting for new regulations before taking action, it is time to rethink that plan.
The proposed overhaul of the HIPAA Security Rule — published in the Federal Register on January 6, 2025, and the first substantial rewrite since 2013 — would make most previously “addressable” safeguards mandatory, including encryption, multi-factor authentication, vulnerability scanning, and a documented asset inventory. It drew roughly 4,745 public comments and heavy pushback from the heavy industry over cost.
It is still a proposed rule. It has not been finalized. HHS’s updated regulatory agenda has pushed final action to at least July 2027 and reclassified the rulemaking as a long-term action. Anyone telling you that you are already out of compliance with “the new HIPAA security rules” is describing something that does not yet exist.
Which is exactly the trap. The delay changes nothing about your obligations, because the current Security Rule remains fully in force and enforceable — and it is the current rule that produced every settlement described above. OCR has gone further, confirming that its enforcement initiative now extends past risk analysis into risk management. The question is shifting from “Do you have the document?” to “Can you show what you did about it?”
Even though new rules are delayed, enforcement is still happening under current laws. Use this extra time to improve your compliance program instead of putting things off.
And none of this is only a healthcare story. SOC 2 asks an auditor to sample evidence across an observation period, not to audit a policy on the day you wrote it. PCI DSS, ISO 27001, NIST, CMMC, HITRUST — every one of them converges on the same demand from a different direction: show your work in the environment where the work actually happens.
Standard IT versus defensible IT
The real difference is not about effort or skill, but about how you measure IT performance and what you do with those results.
What compliance-first IT looks like in practice.
This difference is at the heart of Emry Networks' mission. Standard IT services fix day-to-day problems, but we focus on managing risk. Most providers care most about uptime, but we measure success by your security and audit readiness.
We follow a clear rule: focus on real systems, not just ideas. Instead of guessing, we do thorough assessments. Looking at a policy template shows what you plan to do, but checking live systems, user accounts, and controls shows what is really happening. These differences are common and often lead to regulatory findings.
The work runs on a model we call the Emry Assurance Roadmap.
The Regulatory Discovery — the Red Zone
We conduct a full analysis of your environment against applicable regulatory frameworks, resulting in a Risk Status Report that clearly identifies all gaps between current practices and required standards. The report is presented in accessible language, providing a transparent assessment of organizational vulnerabilities.
Security Hardening — the Transition
We implement a comprehensive security stack—including CrowdStrike EDR, managed encryption, secure and tested backups, and managed detection and response—to transition the business from an at-risk to a defensible posture. Backup, cloud, and continuity services are integrated as core components of managed IT, rather than treated as separate offerings.
Continuous Management — the Green Zone
We provide continuous monitoring, staff training on current phishing and social engineering threats, and routine assessments for compliance drift. As systems evolve and personnel or vendors change, controls may degrade. Compliance is an ongoing state, not a one-time achievement.
Each year, we check over 500 controls in real client environments. This sets us apart: we make sure controls work in practice, not just on paper.
Most consultancies finish their work after the audit and report. We stay to help fix issues. For example, when a healthcare group with several locations prepared for a HIPAA audit, our ongoing support helped them achieve audit-ready status in 90 days by implementing real improvements in their operations.
If you already use a compliance automation platform, keep using it as your main record. These platforms report what you tell them. Our job is to assess the actual state of your systems and address any discrepancies. These are separate tasks, and checking the real systems is often missing in regulatory cases.
Our team has over 35 years of combined experience in securing regulated environments. It includes a founder skilled in law-enforcement cyber investigations and large-scale healthcare cybersecurity, plus architects and engineers who have led Zero-Trust projects for Fortune 100 companies and handled incident response in finance and healthcare.
What to do in the next thirty days
You do not need to hire us to start improving compliance. You can take these six steps on your own, and each one is free or costs very little.
- Inventory what touches regulated data. Every system, including the SaaS tool someone expensed. If it is not on the list, it is not being protected.
- Find out who has admin and why. Then find out which vendors hold a standing connection to your network, and what it reaches.
- Date your risk analysis. If you cannot find it, or it predates the systems you currently run, that is the finding a regulator would write. Fix that first.
- Turn findings into a remediation log. Owners, dates, status. This is the artifact that answers “what did you do about it,” and almost nobody has one.
- Verify a restore, not a backup job. A backup that has never been restored is a hypothesis, not a control.
- Ask your provider what they measure. If the answer is uptime and ticket response, you now know precisely which question is going unanswered — and it is not their fault. It was never the question they were hired to answer.
If these tips make you worry, that is a good sign. It is much better to notice issues now than to find out during a regulatory investigation.
Frequently asked questions
Sources
- HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations,” press release, April 23, 2026 — settlement amounts, affected individuals, corrective action plan terms, and risk analysis findings.
- HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles HIPAA Investigation of MMG Fusion, LLC Breach Affecting 15 Million Individuals,” press release, March 5, 2026 — findings, settlement amount, and three-year corrective action plan.
- Verizon, 2026 Data Breach Investigations Report — breach volume, initial access vectors, ransomware and third-party prevalence, human element, and CISA KEV remediation rates and timelines.
- IBM, Cost of a Data Breach Report 2025 (conducted by Ponemon Institute) — global and US average breach cost, healthcare sector average, and breach lifecycle. Latest edition available at the time of writing.
- HHS Office for Civil Rights, HIPAA Security Rule Notice of Proposed Rulemaking, Federal Register, January 6, 2025; and HHS Unified Regulatory Agenda — proposed status, comment volume, and revised July 2027 final-action target.
- 45 CFR §164.308(a)(1)(ii)(A) and §164.308(a)(1)(ii)(B) — HIPAA Security Rule risk analysis and risk management requirements.
Every exact figure above is attributed to its primary source and reflects the most recent published edition available at the time of writing; regulatory status was verified as current at publication and may change
Read more from our team
Explore insights on compliance and security.
Ready to strengthen your compliance?
Get hands-on assessment and guidance from our compliance experts.

