Skip to content
FAQ

Straight answers.

The questions business owners ask us most — about security, compliance, IT, and what working with us looks like. Don't see yours? Ask us directly.

FAQ

Getting started

Book a strategy call
What does FUNCSHUN do?+

We're a Miami-based cybersecurity firm. We help small and growing businesses adopt AI safely and stay protected, with AI readiness and governance, security consulting, employee training, incident response, compliance support (FTC Safeguards, PCI, HIPAA, CMMC), and the managed IT underneath it all.

What size businesses do you work with?+

Small and mid-sized businesses — typically teams that are too big to wing it on security but don't have a full-time security staff. Many of our clients are CPAs, tax preparers, and other firms regulated under the FTC Safeguards Rule.

Do you only work with businesses in Miami?+

No. We're headquartered in Miami and serve South Florida on-site, but most of our security work is delivered remotely, so we support growing teams across the U.S.

How long have you been in business?+

Since 2011. We started as a managed IT provider and evolved into a dedicated cybersecurity firm, so we understand both the day-to-day IT and the security layer on top of it.

How much does it cost?+

Managed services are billed per user, per month at a flat rate — no ticket caps and no surprise overages. Consulting, compliance, and project work are scoped to your environment and quoted up front, so you see the full price before anything is signed.

We think we've been hacked. What should we do?+

Call us right away using the hotline on our Incident Response page. A responder is on the line in under 15 minutes, and you don't need to be an existing client or have a contract in place. Don't wipe or power off affected machines — that can destroy evidence.

Can you help us get or keep cyber insurance?+

Yes. Carriers now require controls like MFA, EDR, backups, and an incident response plan. We put those in place and help you answer renewal questionnaires accurately.

Do you offer security awareness training for employees?+

Yes. Most breaches start with a person — a phished password or a fake invoice. We train your team to spot and report those attacks before they turn into incidents.

How do we get started?+

Book a free 15-minute strategy call with a senior engineer — no obligation. If you'd like a quick look first, run our free external scan to see what attackers can see about your business.

FAQ

Cybersecurity

More on Cybersecurity
What happens if we're breached mid-engagement?+

Our incident response team is part of the same practice — the 24/7 hotline, containment, and recovery are built into the program, with a retainer option for guaranteed response SLAs.

Do you replace my cyber insurance?+

No — we help you qualify for it and pass renewals. Our controls map directly to the MFA, EDR, backup, and IR requirements carriers now demand.

What if we already have an IT provider?+

Common. We can run as a co-managed security layer alongside an internal team or existing MSP, owning the security stack while they keep day-to-day support.

How fast can you respond to an active incident?+

Endpoints are auto-isolated by EDR in minutes. A human responder is engaged inside 15 minutes for confirmed incidents, with our IR runbook ready to execute.

Do you handle compliance reporting?+

Yes — evidence collection, policy documents, and auditor-ready reports are built into the engagement. See our compliance service for framework specifics.

FAQ

Incident response

More on Incident response
Do we need to be an existing client to call?+

No. We take emergency engagements from new clients. Call the hotline and we'll have a responder on the line and a scoping call started while paperwork moves in parallel.

How does the retainer work vs. an emergency engagement?+

A retainer locks in response SLAs, pre-approved rates, and a documented runbook for your environment — so when something happens, we skip negotiation and go straight to containment. Emergency engagements are available without a retainer, but billed at on-demand rates with a longer ramp.

Will you work with our cyber insurance carrier?+

Yes. We coordinate directly with carriers and breach counsel, follow approved-panel workflows when required, and document everything to support your claim.

What if we don't have EDR or centralized logging in place?+

We deploy our EDR and forensic tooling on day one of the engagement. You get visibility we'd normally build over weeks, in hours.

How fast can you start?+

A responder is on the call in under 15 minutes, and containment actions typically begin within the first hour. The exact timeline depends on access — retainer clients move faster because we already have it.

What happens after the incident is contained?+

You get a written post-incident report, an executive briefing, and a remediation roadmap. From there, most clients move onto our managed cybersecurity program so the same thing doesn't happen twice.

FAQ

Managed IT

More on Managed IT
What's actually included in the flat rate?+

Help desk, monitoring, patching, security stack, vCIO planning, and onboarding/offboarding. Hardware, licenses, and major projects are quoted separately and transparently.

Can you support both Mac and Windows?+

Yes — fully. Cross-platform fleets are the norm for us, including MDM, identity, and security tooling on both.

Do you handle our cloud migrations?+

Yes — Microsoft 365 tenant moves, server retirements, file-share to SharePoint/OneDrive, and Azure/AWS workloads are core services.

How do you bill?+

Per-user, per-month flat rate. No ticket caps, no surprise overages, and price changes only at renewal with notice.

FAQ

Compliance

More on Compliance
We're a DoD subcontractor — do we need CMMC?+

If you handle FCI or CUI, yes. Level 1 covers FCI; Level 2 is required for CUI and involves a C3PAO assessment. We get you ready for both — see our CMMC page for detail.

Can you act as our vCISO?+

Yes — we provide a fractional CISO, run the controls, manage auditors, and own evidence collection across the frameworks you need.

What if we need multiple frameworks?+

Controls overlap substantially. We map a single control set to every framework so you collect evidence once and report many times.

Do you support FTC Safeguards for auto dealers and lenders?+

Yes — including the Qualified Individual requirement, the risk assessment, and the written security program the Rule now mandates.

FAQ

FTC Safeguards Rule

More on FTC Safeguards Rule
Does the Safeguards Rule apply to us?+

If you're a non-bank business significantly engaged in financial activities — auto dealers, mortgage brokers, payday and consumer lenders, tax preparers, collection agencies and more — yes. Many covered businesses don't realize they qualify until an incident or a lender asks.

What is the Qualified Individual?+

The Rule requires a single named person responsible for your information security program. We serve as, or support, your Qualified Individual on a fractional basis — including the periodic reporting to your board or senior leadership that the Rule mandates.

What are the nine required elements?+

A risk assessment, access controls, a data inventory, encryption, secure development practices, MFA, secure disposal, change management, and monitoring/logging — all wrapped in the WISP, with continuous monitoring or annual testing.

What's the risk of ignoring it?+

The FTC can pursue enforcement, and many cyber-insurance carriers and lenders now require attestation. Beyond penalties, a breach without a documented program is far harder — and costlier — to defend.

FAQ

PCI DSS

More on PCI DSS
What does a PCI ISA actually bring?+

An Internal Security Assessor is an individual certified through the PCI Security Standards Council's ISA program to assess PCI DSS controls. Having one lead your program means the same rigor a QSA applies — scoping judgment, evidence standards, and control interpretation — guiding your team well before you face an external assessor.

Do we need a QSA, or can we self-assess?+

It depends on your card volume and acquirer. Most small and mid-sized merchants validate with a Self-Assessment Questionnaire (SAQ) and an Attestation of Compliance; Level 1 volumes require a QSA-signed Report on Compliance. We determine your path and prepare you for whichever applies.

How do we reduce PCI scope?+

Segmentation, and not storing card data you don't need. We isolate the cardholder data environment and push as much of your network out of scope as possible — which lowers both your risk and the cost of staying compliant.

What changed with PCI DSS 4.0?+

More prescriptive authentication (including MFA), expanded logging, targeted risk analyses, and new controls for e-commerce payment scripts. Several requirements became mandatory in 2025 — we make sure you're already meeting them.

Is there an official HIPAA certification?+

No — no government body 'certifies' HIPAA compliance, so be wary of anyone selling a HIPAA certificate. What regulators expect is a current risk analysis and implemented safeguards. We get you genuinely compliant and able to prove it.

We're a vendor, not a provider — does HIPAA apply?+

If you create, receive, store, or transmit PHI on behalf of a covered entity, you're a Business Associate and directly liable under HIPAA. We scope your obligations and put the right BAAs and controls in place.

How often do we need a risk analysis?+

At least annually and after any major change to systems or operations. A missing or stale risk analysis is the single most-cited gap in OCR enforcement, so we keep yours current and documented.

What happens if there's a breach?+

We help you run the four-factor breach risk assessment, meet the notification timelines, and document the response — so a security event doesn't compound into a compliance failure.

Do we actually need CMMC?+

If you're in the DoD supply chain and touch Federal Contract Information or CUI, yes. Level 1 covers FCI; Level 2 is required for CUI and is verified by a C3PAO. Primes are flowing these requirements down to subcontractors now, so it rarely stops at the top tier.

What's the difference between Level 1 and Level 2?+

Level 1 is 15 basic safeguards for FCI, self-assessed annually. Level 2 maps to the 110 controls in NIST SP 800-171 and, for most CUI, requires a third-party (C3PAO) assessment every three years.

What is an SPRS score?+

It's the Supplier Performance Risk System score the DoD uses to gauge your NIST 800-171 posture. We calculate it honestly, build a POA&M for any open items, and support submission — overstating it is a False Claims Act risk we help you avoid.

How long does readiness take?+

Most small and mid-sized contractors reach Level 2 readiness in three to six months, depending on starting posture and whether you need a CUI enclave. We sequence the work so contract deadlines aren't at risk.

FAQ

AI advisory

More on AI advisory
What does "AI readiness" actually mean?+

It means you know which AI tools your team uses, you've decided what data those tools are allowed to see, you have a written policy people follow, and you've picked a first use case worth paying for. The AI Readiness Assessment gets you all four.

What is "agentic AI," and should we worry about it?+

Agentic AI doesn't just answer questions — it takes actions: sending email, updating records, moving files. That's powerful and risky in equal measure. We give agents only the access they need, require approval for sensitive actions, and log everything they do.

Is our data safe with these AI tools?+

It depends on the plan and the settings — which is exactly what the assessment checks. We default to business tiers (Microsoft Copilot, ChatGPT Enterprise, Claude, Google Workspace AI) where your data isn't used for training, and wrap them in your existing identity and data-loss controls.

Do we have to commit to one AI vendor?+

No. We build so you can switch providers as the market shifts, without rewriting your workflows.

What does it cost?+

The AI Readiness Assessment is a fixed fee, quoted up front after a short call. Pilots are scoped and priced from the assessment's findings, and ongoing support is a monthly retainer.

FAQ

Business phone

More on Business phone
How does this work with our existing Microsoft 365 tenant?+

We plug directly into your tenant using Direct Routing or Operator Connect — no rip-and-replace. Your users keep their existing Teams identity and just gain a real phone number, calling plan, and PSTN connectivity.

Do users need a separate softphone app?+

No. That's the whole point — calls ring inside Microsoft Teams on desktop, mobile, and web. One app for chat, meetings, calling, and SMS means less training, fewer licenses, and no app-switching.

Can we keep our existing phone numbers?+

Yes — porting from any major US carrier or legacy PBX is included, with cutovers scheduled outside business hours so customers never hit a dead line.

Will it work for our contact center?+

Yes — our Teams-certified contact center adds queues, SLAs, supervisor dashboards, omnichannel, and CRM screen-pops without forcing agents out of Teams.

What about international calling and remote staff?+

Local numbers in 100+ countries, competitive international rates, and full call analytics — all governed by the same Teams policies and Conditional Access rules you already enforce.

Get started

Still have a question?

Fifteen minutes with a senior engineer gets you a straight answer about your environment — not a sales pitch.

15-minute call · senior engineer · no obligation