Go straight to the source. These official resources let you check the facts for yourself. Each link opens the agency's or standards body's own website.
Resource library
| Resource | From | What you'll find |
|---|---|---|
| NIST CSF 2.0 Small Business Quick-Start Guide | NIST | A practical starting point for small business cybersecurity. |
| NIST Cybersecurity Framework 2.0 | NIST | The framework itself, with guides and examples. |
| NIST Small Business Cybersecurity Corner | NIST | Plain-language guides and training for small businesses. |
| CIS Critical Security Controls | CIS | The 18 prioritized security controls and Implementation Groups. |
| CISA Cyber Guidance for Small Businesses | CISA | Basic security practices and checklists. |
| CISA Cybersecurity Alerts & Advisories | CISA | Current threats and recommended actions. |
| CISA Known Exploited Vulnerabilities Catalog | CISA | Vulnerabilities attackers are actively using. Patch these first. |
| CISA StopRansomware | CISA | Ransomware prevention, response and reporting. |
| FTC Cybersecurity for Small Business | FTC | Business guidance on phishing, ransomware, vendors and more. |
| FTC Safeguards Rule Guide | FTC | Requirements for covered financial businesses. |
| HHS HIPAA Security Rule | HHS OCR | Healthcare security requirements and guidance. |
| NIST SP 800-66 Rev. 2 | NIST | How to implement the HIPAA Security Rule. |
| PCI Security Standards Council | PCI SSC | PCI DSS and merchant resources. |
| Texas AG: Data Breach Reporting | Texas AG | Breach reporting requirements and the official form. |
| Texas AG: Consumer Privacy Rights | Texas AG | Texas privacy laws, including the TDPSA. |
| Texas DIR: Texas Cybersecurity Framework | Texas DIR | Built for state agencies and public colleges; a useful reference model. |
| DoD CIO: CMMC | DoD | Current CMMC program information for defense contractors. |
| FBI Internet Crime Complaint Center (IC3) | FBI | Report cybercrime, business email compromise and online fraud. |
Where to report a cyber incident
- Cybercrime, fraud or business email compromise: file a report with the FBI IC3. If money was wired, also call your bank immediately.
- Ransomware: see CISA StopRansomware for reporting and response steps.
- Texas breach affecting 250+ residents: notify the Texas Attorney General within 30 days.
- NexGenGuard clients: call us right away at 210-979-1886.
Cybersecurity glossary
- Conditional Access
- Microsoft 365 rules that allow or block sign-ins based on conditions such as the user, device, location or risk.
- CUI
- Controlled Unclassified Information: sensitive government information that isn't classified but must be protected.
- DMARC, SPF, DKIM
- Email authentication records that help stop criminals from sending email that pretends to come from your domain.
- EDR
- Endpoint Detection and Response: software on each computer that watches for suspicious behavior and can stop and isolate threats.
- Encryption
- Scrambling data so only someone with the right key can read it, on a device, in email or in transit.
- ePHI
- Electronic protected health information, as defined by HIPAA.
- Immutable backup
- A backup copy that can't be changed or deleted for a set period, even by an attacker with admin access.
- Incident response plan
- A written plan for who does what when a security incident happens.
- Least privilege
- Giving each person only the access they need to do their job.
- MDR
- Managed Detection and Response: EDR plus a team of security analysts who monitor alerts and respond around the clock.
- MFA
- Multi-factor authentication: a second proof of identity, such as a phone prompt, in addition to a password.
- Patch management
- Keeping operating systems and software updated so known security holes are closed.
- Phishing
- Fake emails, texts or calls designed to trick people into clicking links, sharing passwords or sending money.
- Phishing-resistant MFA
- MFA methods, such as security keys or passkeys, that can't be relayed by a fake login page.
- Ransomware
- Malware that locks or steals your data and demands payment.
- RTO / RPO
- Recovery Time Objective (how fast you need to be back up) and Recovery Point Objective (how much data you can afford to lose).
- SIEM
- Security Information and Event Management: a system that collects and analyzes security logs from many sources.
- SOC
- Security Operations Center: a team that monitors and responds to security events, often 24/7.
- Vulnerability
- A weakness in software or configuration that an attacker could exploit.
- Zero trust
- A security approach that never assumes a user or device is safe just because it's inside the network; every access is verified.
Last reviewed: October 2026. Laws and standards change; always confirm with the official source.
