
The Fastest, Clearest Way to Use AI and Secure Your Small Business, Properly.
A 3-day live challenge for owners who don't have time to become IT experts. Learn exactly which cybersecurity controls to implement, in what order, and how to do it efficiently without wasting money, with a working practitioner answering your questions live, including how to actually put AI to work in your business without leaking your customer data.
3 live days · Current State Map + 90-Day Plan · Recordings and templates yours to keep
August 5 to 7, 2026 · 4:00pm to 5:30pm PDT daily
Challenge starts August 5, 2026 · 4:00pm PDT
Why most small businesses stay unprotected
It's not laziness. It's five things in the way.
You already know cybersecurity matters. The problem has never been motivation, it's been five specific blockers. This challenge is built to remove them in order.
Wasted spend
Most owners either buy nothing or buy everything a vendor pitches them. Both are expensive. This challenge shows you exactly which controls actually move the needle, and which line items to cancel.
AI blind spots
Your team is already using AI tools you don't know about. Not because they're careless, because they're trying to get work done. The problem isn't the AI, it's that nobody can see where your customer data, invoices, and contracts are going once they're pasted into a free chatbot that remembers everything. We show you how to find it, and how to fix it in an afternoon.
Missed basics
Most breaches come from a handful of basics being missing. Not exotic threats. Basics. You'll walk out knowing exactly which you have, which you don't, and the fastest way to close each gap.
Wrong order
Buying EDR before you've turned on MFA is like installing an alarm on a house with no doors. We give you the exact implementation order so every dollar and every hour produces real protection.
Endless research
You've already lost weekends Googling 'best small business cybersecurity.' Stop. In 3 days you'll have the answers, the checklist, and someone to ask when you get stuck, including what to do about AI tools your team already uses.
The honest truth
"I know I need to do this. I just don't know where to start."
That's the sentence we hear most from small business owners. Not "I don't care." Not "I don't believe in it." Just, "I don't know where to start, so nothing happens."
Meanwhile every vendor pitches you a different product, every article gives you a different checklist, and your IT person answers in a language you don't speak. On top of that, your team is already using AI tools, ChatGPT, Claude, Copilot, free image generators , often with customer data, financials, or passwords inside them, and you have no policy for it. So the months go by, and you're still exposed on the exact same basics.
The truth is that proper cybersecurity for a small business isn't complicated. It's about a small number of specific controls, done in the right order, without overspending , plus a clear, simple rule for how AI gets used in your business. The only thing that's ever been missing is somebody sitting down with you and showing you exactly what to do.
That's this challenge. 3 days. Clear steps. Live answers. Real implementation, including your AI use policy.
The cost of waiting
What it costs to keep waiting
Nobody sends you a bill for the security you didn't do. It shows up somewhere else.
Your insurance renewal.
Carriers now ask whether you have MFA on email and admin accounts, whether you test backups, and whether you have a written incident plan. Answer wrong and you get a higher premium, a smaller policy, or a declined renewal. Answer inaccurately, and a lot of owners do, because nobody told them what the question meant, and you find out at claim time that the coverage you've been paying for doesn't apply.
Your next contract.
More of your clients are sending security questionnaires now, and the person sending it isn't hostile, they're just doing what their own insurer or lawyer told them to. If you can't answer it, you don't lose the deal loudly. You just stop hearing back.
Your AI exposure, quietly compounding.
Every month without a rule is another month of customer records, contracts, and financials landing in tools you've never evaluated. Not because your team is careless. Because it's faster, and no one told them where the line was.
The weekend you already spent researching this.
That's the cost you've been paying all along. You've been paying it in hours instead of dollars, and it hasn't produced a single implemented control.
The alternative
Three days is cheaper than any of them.
August 5 to 7, 2026 · 4:00pm to 5:30pm PDT daily
Four things that turn "someday" into "done in 3 days."
This isn't a 40-hour course. It's a focused challenge designed around the four things that actually determine whether cybersecurity gets implemented in a small business , including the new AI risks that keep owners up at night.
The 12 controls that matter
Cybersecurity has hundreds of possible controls. For a business your size, twelve of them do 90% of the work. We name all twelve, in order, and show you how to check each one on your setup in minutes, not weeks.
The right order of operations
Doing the right things in the wrong order wastes money. We give you the exact sequence: what to turn on first, what to buy second, what to write down third. Every step compounds. Nothing is filler.
Live answers to your real questions
The reason nothing gets implemented is that owners hit one weird question and stall. On Day 3 you ask anything about your setup, Microsoft or Google, in-office or remote, one person or fifty, and get a specific answer, not a generic one.
AI treated as a control, not a crisis
Every other vendor is either selling you AI panic or telling you to ban it. Neither works. Banning AI doesn't stop AI, it just moves it out of view, and your team keeps using it anyway because it makes their job easier. We show you how to find what's already in use, write one simple rule, and pick tools that don't leak your data, so your team gets the productivity without you gambling the business.
The other half of the AI conversation
Locking AI down isn't the goal. Using it well is.
Most security people will tell you to ban AI. That's the easy answer and it's the wrong one, your competitors are using it, your team is already using it, and telling everyone to stop just means you stop hearing about it. The point of putting guardrails on AI isn't to slow your business down. It's so you can actually lean into it.
Once you know which tools are safe, what data can go where, and what your one rule is, you stop white-knuckling every time someone opens ChatGPT. That's when AI starts paying for itself instead of scaring you.
The work nobody wants to do.
Drafting, summarizing, cleaning up documents, first passes at proposals and emails, the stuff that eats hours and doesn't need a human's best thinking.
Making a small team look bigger.
One person with the right AI setup can produce what used to take three, without hiring.
Knowing which tools are actually safe.
There's a real difference between a free chatbot and a business-tier tool with a data agreement. We show you which is which and what it costs.
Getting your team using it the same way.
AI helps most when everyone's using it, not when one person is quietly good at it. We cover how to get the whole team moving.
Before Day 1 · 15 minutes, no jargon
"Just tell me what to look at first."
Before Day 1 you answer 5 plain questions: how many people, Microsoft or Google, who does your IT, cyber insurance yes or no, and what data would hurt most if it got out. That's the whole prep, 15 minutes on a coffee break. From there the challenge does the heavy lifting, and by the end of Day 3 you'll be further along than most small businesses ever get.
The 3 days
See it. Plan it. Do it.
August 5 to 7, 2026 · 4:00pm to 5:30pm PDT daily
90 min live
See What You Actually Have
I don't even know what we already have in place.
- Learn the five places small business risk actually hides — and why owners never think to look at any of them.
- Get the exact walkthrough for finding which apps and AI tools have access to your email, files, and customer data.
- Learn to spot admin rights that no longer match reality, including the accounts nobody remembers creating.
- Score your business against the 12 controls in plain English. No auditor, no 300-question form, no jargon.
- Name the three pieces of data that would hurt most if they got out — everything else gets prioritized against those.
- No admin access to your own systems? That's finding number one. Get the exact wording to ask your IT provider for it.
The fear of the unknown goes away first. Ninety minutes in, you'll have a scored, color-coded picture of your real exposure — and most owners find it's smaller, more specific, and far more findable than the thing they'd been avoiding.
Shadow AI is the gap nobody's checking. You'll learn exactly where to look to find which AI tools already have access to your business data, and what to do about each one you find.
No screen sharing, no credentials, nothing exposed. You bring what you know, and we tell you what to go look for.
You leave with:
Your Current State Map — 12 controls scored green / yellow / red, your crown-jewel data named, and the exact checklist for finding every app and AI tool touching your business.
90 min live
Know Exactly What to Do, and In What Order
There's a hundred things to do. Where do I actually start?
- Turn your Current State Map into a ranked 90-day plan, sequenced by protection per dollar.
- Learn why order matters — which controls are worthless money until something else is done first.
- Get real time and cost estimates on every item, so nothing surprises you three weeks in.
- Find the security spend to cancel. Most small businesses pay for things that do nothing at their size.
- Write your one-page AI use policy during the session. Not homework. You leave with it finished.
- Learn which AI tools are worth paying for at your size, and what business-tier actually buys you that free doesn't.
- Get the exact questions to ask your IT provider — the ones that reveal whether you're getting what you pay for.
You stop being managed by your own vendors. You'll know the order, the cost, and the reasoning behind every step — and you'll be able to walk this plan into an IT meeting and hold your own for the first time.
AI gets treated like every other control: what to allow, what to block, what to write down. You'll write that rule yourself, and it'll fit on one page your team will actually read.
Bring your renewal quotes and your IT invoices if you have them. Cancelling one line item usually pays for the whole quarter.
You leave with:
A ranked 90-day plan with time and cost per item, your written one-page AI use policy, a cancel list, and the questions to bring to your next IT meeting.
90 min live · hands-on
Make It Doable, and Know When You're Done
How do I know when I've done enough?
- See what "done" actually looks like for a business your size — the finish line nobody in this industry ever draws for you.
- Walk multi-factor authentication end to end: the exact steps, the right order, and the mistakes that lock owners out of their own accounts.
- Learn the difference between done properly and done on paper — the version that holds up when something actually happens.
- Fill in your one-page Incident Playbook with your real phone numbers, during the session.
- Get an honest line drawn: which controls you can genuinely maintain yourself, which need tooling, and which need a human watching. No pitch — just which is which.
- Bring your specific setup to open Q&A: Microsoft or Google, in-office or remote, one person or fifty. Leave with nothing unanswered.
Cybersecurity stops being a bottomless pit. You'll see the edges of it — what finished looks like, what it costs, and what's honestly yours to carry versus what isn't. Owners describe this as the first time the whole thing felt survivable.
Your Incident Playbook covers the AI scenarios too: what happens when someone pastes the wrong thing into the wrong tool, who you call, and what you do in the first ten minutes.
Nothing here requires you to be technical. If you can log into your email, you can do this.
You leave with:
Your one-page Incident Playbook filled in, a clear definition of done for a business your size, and an honest line between what you handle and what you don't.
The 12 controls. And the 6 we start with.
We assess your business against the full 12-control framework. But six of them close the doors attackers actually walk through, so we implement those first. Get these six in place, properly, not just checked off, and you're already ahead of most small businesses. The sixth one is new: a simple AI-use rule so your team doesn't accidentally train a chatbot on your customer data.
The full 12: multi-factor authentication, endpoint protection, tested backups, least-privilege access, AI use governance, incident response, email security, patch management, security awareness, logging and monitoring, vendor access review, and asset inventory. That's the framework. But six of them close the doors attackers actually walk through, so we implement those first.
The challenge is built around getting you through these six in the right order, starting with the ones that cost nothing and take an hour, and ending with the ones that need a small budget and a plan. By Day 3 you'll know exactly where each of the 12 controls stands in your business, and which 6 are already handled.
The first 6 controls
A second lock on every account that matters.
Multi-factor authentication on email, banking, admin, cloud.
Real protection on every computer and phone.
Modern endpoint protection on every device.
Backups you've actually restored from, not just backups that exist.
Regularly tested restore process.
Clear rules for who has access to what.
Least-privilege access with a periodic review.
Clear rules for how your team uses AI, and a way to see if they're followed.
AI use policy, approved-tool list, and shadow-AI check.
A one-page plan for what to do when something goes wrong.
Written incident response playbook.
Tax preparers · Accountants · Financial advisors · Medical practices
If you handle client financial, tax, or health data, this isn't optional for you.
You likely already have a written security plan obligation, IRS Publication 4557, the FTC Safeguards Rule, GLBA, or HIPAA. You may already have the document. The problem is what's not in it.
That plan almost certainly predates AI. Your staff pasting client data into a free chatbot is a gap in a plan you are already required to maintain, and "we didn't know they were doing it" is not a defense that has ever worked.
The challenge covers this directly. You'll leave with an AI use policy written to fit inside your existing written plan, not a bolt-on document that contradicts it. You'll also leave knowing which of the 12 controls map to obligations you already carry.
What's included
Everything you need to actually implement, for $7.
3 live challenge days with a working practitioner, bring your questions, get real answers.
Your Current State Map across the 12 controls that actually matter for a business your size.
Your 90-Day Implementation Plan, sequenced by impact, with time and cost estimates.
The step-by-step guides for the most common quick wins (MFA, email hardening, access cleanup, backup testing).
The one-page Incident Playbook, what you and your team do the moment something looks wrong.
A plain-English AI Use Policy and a Shadow AI checklist, so your team can use AI safely without leaking data.
Session recordings and templates you keep forever, reuse every time you hire, change tools, or renew insurance.
You'll leave with a current state map, a 90-day implementation plan, and working controls in place, plus a free follow-up strategy call if you get stuck implementing.
Who it's for
Is this challenge for you?
Two quick checks. If the left column sounds like you, this is built for your business.
This is for you if…
- You own or run a small business (roughly 1 to 100 people).
- You know cybersecurity needs to happen, and you want to actually get it done, not just read about it.
- You don't have (or don't want to become) an in-house IT expert.
- You'd rather have someone tell you the right order than spend more weekends researching.
This isn't for you if…
- You're a large enterprise with a full internal security team already running.
- You want a certification course or a deep technical training.
- You want to buy a report and never actually implement anything.

Your host
A working practitioner, not a marketer.
I'm Marquis Carroll, founder of MSC Security. I don't teach cybersecurity for a living. I run a security operation for a living. My team defends credit unions, defense contractors working under CMMC, utilities, and small professional services firms. Right now. This week. That's the difference between me and most people selling you a course.
I built this challenge because I kept hearing the same sentence from owners: "I know I need to do this, but I don't know where to start." So I took the exact process we run with paying clients, map the current state, prioritize the right controls, sequence the implementation, and compressed it into three live working sessions.
You're not getting a curriculum someone built in 2019 and has been reselling since. You're getting what we're doing for clients this quarter, including the AI conversation every single one of them is now having.
From past attendees
What owners say after the challenge.
One challenge · No upsell wall
Everything you get
- 3 live challenge days + Q&AIncluded
- Current State Map (12 controls)Included
- 90-Day Implementation PlanIncluded
- Step-by-step quick-win guidesIncluded
- One-page Incident PlaybookIncluded
- Recordings + templates, yours to keepIncluded
$7 is intentional. We'd rather fill the room with owners who actually implement than sell a course to a handful. There's no upsell wall and no pitch deck at the end, but I'll be honest about what happens after: on Day 3 I'll tell you which of the 12 controls you can maintain yourself and which ones need tooling or someone watching them. Some of you will want help with that second list. Most of you won't need it. Either way you leave with the plan and the controls, and that's yours regardless.
August 5 to 7, 2026 · 4:00pm to 5:30pm PDT daily
Questions
Answered honestly.
I'm not technical, will I be able to follow this?+
Yes. This challenge is built specifically for owners who are not technical. Every concept is explained in plain English before we ever touch a setting. When we say "MFA," we say "a second lock beyond your password." If you can run a small business, you can absolutely follow along, and by Day 3 you'll be confidently implementing the basics yourself.
Why only 3 days? Isn't cybersecurity bigger than that?+
Cybersecurity as a field is huge. But implementing the right basics for a small business isn't, most owners can get 90% of the way there in a few focused days if someone tells them what to do and in what order. That's the whole point of this challenge: efficiency. You're not becoming a security expert. You're getting properly protected as fast as possible.
What time do the sessions run?+
Sessions run 4:00pm to 5:30pm PDT daily on August 5, 6, and 7, 2026. Plan for roughly 90 minutes to 2 hours per day including live Q&A. Every session is recorded and posted the same day, so if you have to miss one, nothing falls behind.
What if I can't make one of the live sessions?+
Every session is recorded and posted the same day. You can submit your questions in advance and we'll answer them live on the call, then you watch the reply on your schedule. Nobody falls behind.
We already have an IT provider. Do we still need this?+
Especially then. IT and security are different jobs, and most owners don't know what to ask their IT provider for, so nothing changes. Come to the challenge, get the list and the sequence, then walk it into your next IT meeting. Your provider will thank you.
What about AI? Is that covered?+
Yes, and both halves of it. On the security side we show you how to find shadow AI use, write a one-page policy, pick safer tools, and train your team on what data never goes into a chatbot. But we also cover the part most security people skip: where AI is genuinely worth using in a business your size, which paid tiers are worth the money, and how to get your team using it consistently. The goal isn't to lock AI down. It's to use it without gambling your business.
Is this going to tell me to stop using AI?+
No, the opposite. Banning AI doesn't stop AI, it just moves it somewhere you can't see. Your team is already using it and your competitors definitely are. This challenge is about setting it up so you can use it aggressively and still sleep at night. If you came here hoping for permission to shut it all down, this isn't that.
Is $7 really the whole price? What's the catch?+
$7 is the whole price. No upsell wall, no "unlock the real content for $497." We keep the price this low on purpose, we'd rather help a room full of owners actually implement cybersecurity than sell a course to a handful. Some attendees choose to work with us afterward. Most don't. Both are fine.
In 3 days, AI and security both stop being "someday."
You'll walk out with a map of where you stand today, a sequenced plan for the next 90 days, and real controls implemented in your business, not a stack of research and good intentions. For $7, choose the efficient way.
August 5 to 7, 2026 · 4:00pm to 5:30pm PDT daily