Find out where your business is exposed — before someone else does

Practical security assessments run by a working cybersecurity professional. Clear findings, prioritized fixes, scoped to your business.


Start here: assessments

Fixed-scope engagements with a written report and a prioritized list of what to fix first. Most businesses start with one of these.

Ransomware Readiness Assessment

Backup restore test, segmentation check, patch posture, and IR plan review. The single most valuable check for a small business — and the best place to start.

Email Security Assessment

SPF/DKIM/DMARC audit, Microsoft 365 or Google Workspace filtering review, and an impersonation-gap check. Email is how most attacks start.

MFA / Identity Hardening Audit

MFA and conditional-access review, legacy-auth check, and admin-role cleanup. Pairs naturally with the email assessment.

Compliance Gap / Cyber Insurance Questionnaire Support

HIPAA, PCI, or state breach-notice gap check, or help completing a cyber-insurance questionnaire honestly.

Posture / Checklist Review

A broad security health check against a practical baseline. A good annual recurring touchpoint.

Incident Response Tabletop Exercise

A facilitated walkthrough of a realistic incident with your leadership team. Reveals gaps a checklist can’t.

Specialized & project work

  • Threat hunt (scheduled project engagement)
  • Digital forensics — litigation, insurance, investigations
  • Executive exposure assessment (with the individual’s own consent)

When you’re ready: ongoing coverage

Once you know where you stand, monitoring keeps watch so problems get caught early instead of discovered late.

  • Managed detection & response — auto-containment + human response window
  • Monitoring essential — alerting + monthly report
  • IR retainer — response window + discounted incident rates

Every engagement is scoped to your business. Tell me what you’re dealing with and I’ll send a quote.