Service
Security Foundation
Four weeks to find and fix the biggest security gaps.
- Starting price
- From $4,800 fixed fee
- How it works
- One-time project, four weeks, fixed price
- What changes the price
- Fixed fee for a single organization with a common identity provider. Complex environments — several tenants, legacy domains, more than roughly ten sites — are quoted higher after a short scoping call.
What problem this solves
We check the four things that cause most of the damage at your size: who can sign in, what shape the laptops are in, whether your backups actually restore, and what happens first when something goes wrong. You get written findings, the evidence behind them, and a ranked list of fixes you can hand to anyone — us or someone else.
What we take off your team's plate
- 01
Who can sign in to what
Every account with admin powers, every account without a second login step, every shared password, and every former employee who can still get in.
- 02
The state of your laptops
Which machines are updated, encrypted and protected — and which ones nobody knew existed.
- 03
Do the backups actually work?
We don’t trust the green checkmark. We restore real data, time it, and write down what happened.
- 04
A ranked list of what to fix
Every problem ranked by risk and effort, with who should do it, roughly how long it takes, and what it prevents in plain language.
- 05
Answers for your insurer
We line the findings up against the questions insurers usually ask, so the form isn’t guesswork.
This is right if
- Companies filling out a cyber-insurance application or renewal questionnaire
- Leadership or a board asking a security question nobody can currently answer
- Businesses that grew fast and never revisited access after the growth
- Companies that want a fixed-price project before signing up for anything monthly
This is the wrong choice if
- Hacking simulations — we don’t try to break in, and this isn’t a substitute for that
- Passing a formal audit — see Compliance Readiness for that
- Something happening right now — see Incident Response
How it goes
- Week 1
We get access, talk to your people, and pull data on accounts, devices and backups.
- Week 2
We review it by hand, test a real restore, and dig into anything that doesn’t add up.
- Week 3
We draft and rank the findings, then walk your person through them.
- Week 4
Final report, the list of fixes, and an hour with your leadership team to explain it.
Questions we get
- What do we actually receive at the end?
- A written report with the evidence, a ranked list of fixes in a spreadsheet, and a walkthrough. It’s all yours to keep and send to an insurer or your board.
- Can you do the fixing too?
- Yes, either as a separate project or as part of ongoing support. We price it separately so the findings stay honest.
- Is this the same as hiring hackers to test us?
- No. That kind of test tries to break in. This checks whether the basics are in place and working. At your size, the basics usually matter more, and cost less.
Not sure what you need?
Answer a few questions and we'll suggest the service that fits — or tell you plainly if we're not the right company for this.