★ H2CYBER · OFFICIAL ASSESSMENT REPORT ★
MAY 2026 · ISSUE 04
Cyber Risk
Assessment.
Big Tex's Shop · Prosper, Texas · 14 Employees
PREPARED MAY 12, 2026 · NEXT REVIEW JUNE 01, 2026
★ INDEPENDENTLY VERIFIED ★ H2CYBER ★★ MAY 2026 ★ ISSUE 04 ★
H₂
LEVEL 01 EARNED
Overall posture · · Ranked 9 of 412 small businesses on the platform.
IDENTIFY 27%
PROTECT 18%
DETECT 12%
RESPOND 24%
RECOVER 31%
Paul Horn
PRACTITIONER · 30 YEARS
H2Cyber, Prosper, TX
David Bryson
LEAD ENGINEER
Beyond AI, Detroit
★ PREPARED IN ACCORDANCE WITH NIST CSF 2.0 ★
PAGE 01 OF 12
PREPARED FOR BIG TEX'S SHOP
★ H2CYBER · OFFICIAL ASSESSMENT REPORT ★
MAY 2026 · ISSUE 04 · A LETTER FROM YOUR AUDITOR

Memo from your auditor.

Big Tex, you closed May 2026 at 21%, up 0.6 from April, ranked 9 of 412 small businesses on the platform. The single biggest move you made was multi-factor authentication: you marked it Implemented on April 12, and that change alone took your Identify function from 24% to 27%. The rest of the score is roughly where it was at the end of April.

Three things to focus on in June. Backup verification is at 0.4 of 3.0; the backups exist but no one has restored from them in 90 days, and that is the single largest gap. Data-at-rest encryption is in progress; finishing the rollout would move Protect from 18% to roughly 25%. Endpoint detection at 1.6 needs the Cylance install to land. Everything else can wait until July.

REGULATORY CONTEXT

Nothing material changed in your regulatory profile since April. The SEC adviser cyber attestation deadline remains December 31, 2026; you have eight months. State-AG bulletins in your jurisdiction recorded no new requirements for businesses your size.

One item to flag for July: NYDFS is in a 60-day comment period on a proposed update to Section 500.15 (data encryption). You are not registered with NYDFS, so the rule will not bind you, but several of your customers are. We will summarize the change in next month's report if it is adopted.

BY FUNCTION
IDENTIFY · +3 POINTS

Multi-factor authentication moved from In Progress to Implemented on April 12, which is what carried this function. Asset inventory remains your strongest control at 2.9 of 3.0.

RESPOND · +2 POINTS

Your incident response plan moved from Not Implemented to In Progress this month. The plan is drafted; the next step is a tabletop exercise to test it.

RECOVER · +2 POINTS

Recovery planning moved up because you documented your backup retention policy. Backup verification itself remained at 0.4; testing the restore is the move that will carry June.

PRIORITIES FOR JUNE
  • 01Test your backups by restoring a single file from last week's set. The act of testing moves Backup Verification from 0.4 to roughly 1.5 and is the largest available point gain in June.
  • 02Finish BitLocker rollout on the three Windows machines flagged in your Syxsense fleet. This closes Data-at-Rest from 0.8 to 2.5 and lifts Protect by about seven points.
  • 03Schedule the Cylance EDR install for the first week of June. The install itself is half a day; the value is moving Endpoint Detection from 1.6 to 2.4 and lifting Detect from 12% to roughly 18%.
For your records, May 2026.
★ PREPARED IN ACCORDANCE WITH NIST CSF 2.0 ★
GENERATED BY CLAUDE ON AMAZON BEDROCK 01 MAY 2026 NO TRAINING, NO RETENTION
PAGE 02 OF 12
PREPARED FOR BIG TEX'S SHOP