San Antonio managed IT & cybersecurity · 24/7 support available for opt-in clients Call 210-979-1886  ·  info@nexgenguard.com
Resource Center

Resource library & glossary

Direct links to official agencies and standards bodies, plus plain-English definitions of common security terms.

Go straight to the source. These official resources let you check the facts for yourself. Each link opens the agency's or standards body's own website.

Resource library

ResourceFromWhat you'll find
NIST CSF 2.0 Small Business Quick-Start GuideNISTA practical starting point for small business cybersecurity.
NIST Cybersecurity Framework 2.0NISTThe framework itself, with guides and examples.
NIST Small Business Cybersecurity CornerNISTPlain-language guides and training for small businesses.
CIS Critical Security ControlsCISThe 18 prioritized security controls and Implementation Groups.
CISA Cyber Guidance for Small BusinessesCISABasic security practices and checklists.
CISA Cybersecurity Alerts & AdvisoriesCISACurrent threats and recommended actions.
CISA Known Exploited Vulnerabilities CatalogCISAVulnerabilities attackers are actively using. Patch these first.
CISA StopRansomwareCISARansomware prevention, response and reporting.
FTC Cybersecurity for Small BusinessFTCBusiness guidance on phishing, ransomware, vendors and more.
FTC Safeguards Rule GuideFTCRequirements for covered financial businesses.
HHS HIPAA Security RuleHHS OCRHealthcare security requirements and guidance.
NIST SP 800-66 Rev. 2NISTHow to implement the HIPAA Security Rule.
PCI Security Standards CouncilPCI SSCPCI DSS and merchant resources.
Texas AG: Data Breach ReportingTexas AGBreach reporting requirements and the official form.
Texas AG: Consumer Privacy RightsTexas AGTexas privacy laws, including the TDPSA.
Texas DIR: Texas Cybersecurity FrameworkTexas DIRBuilt for state agencies and public colleges; a useful reference model.
DoD CIO: CMMCDoDCurrent CMMC program information for defense contractors.
FBI Internet Crime Complaint Center (IC3)FBIReport cybercrime, business email compromise and online fraud.

Where to report a cyber incident

  • Cybercrime, fraud or business email compromise: file a report with the FBI IC3. If money was wired, also call your bank immediately.
  • Ransomware: see CISA StopRansomware for reporting and response steps.
  • Texas breach affecting 250+ residents: notify the Texas Attorney General within 30 days.
  • NexGenGuard clients: call us right away at 210-979-1886.

Cybersecurity glossary

Conditional Access
Microsoft 365 rules that allow or block sign-ins based on conditions such as the user, device, location or risk.
CUI
Controlled Unclassified Information: sensitive government information that isn't classified but must be protected.
DMARC, SPF, DKIM
Email authentication records that help stop criminals from sending email that pretends to come from your domain.
EDR
Endpoint Detection and Response: software on each computer that watches for suspicious behavior and can stop and isolate threats.
Encryption
Scrambling data so only someone with the right key can read it, on a device, in email or in transit.
ePHI
Electronic protected health information, as defined by HIPAA.
Immutable backup
A backup copy that can't be changed or deleted for a set period, even by an attacker with admin access.
Incident response plan
A written plan for who does what when a security incident happens.
Least privilege
Giving each person only the access they need to do their job.
MDR
Managed Detection and Response: EDR plus a team of security analysts who monitor alerts and respond around the clock.
MFA
Multi-factor authentication: a second proof of identity, such as a phone prompt, in addition to a password.
Patch management
Keeping operating systems and software updated so known security holes are closed.
Phishing
Fake emails, texts or calls designed to trick people into clicking links, sharing passwords or sending money.
Phishing-resistant MFA
MFA methods, such as security keys or passkeys, that can't be relayed by a fake login page.
Ransomware
Malware that locks or steals your data and demands payment.
RTO / RPO
Recovery Time Objective (how fast you need to be back up) and Recovery Point Objective (how much data you can afford to lose).
SIEM
Security Information and Event Management: a system that collects and analyzes security logs from many sources.
SOC
Security Operations Center: a team that monitors and responds to security events, often 24/7.
Vulnerability
A weakness in software or configuration that an attacker could exploit.
Zero trust
A security approach that never assumes a user or device is safe just because it's inside the network; every access is verified.

Last reviewed: October 2026. Laws and standards change; always confirm with the official source.

Ready for IT that just works?

Book a free consultation or IT security audit. No sales team, no pressure — just straight answers.