Find out where your business is exposed — before someone else does
Practical security assessments run by a working cybersecurity professional. Clear findings, prioritized fixes, scoped to your business.
Start here: assessments
Fixed-scope engagements with a written report and a prioritized list of what to fix first. Most businesses start with one of these.
Ransomware Readiness Assessment
Backup restore test, segmentation check, patch posture, and IR plan review. The single most valuable check for a small business — and the best place to start.
Email Security Assessment
SPF/DKIM/DMARC audit, Microsoft 365 or Google Workspace filtering review, and an impersonation-gap check. Email is how most attacks start.
MFA / Identity Hardening Audit
MFA and conditional-access review, legacy-auth check, and admin-role cleanup. Pairs naturally with the email assessment.
Compliance Gap / Cyber Insurance Questionnaire Support
HIPAA, PCI, or state breach-notice gap check, or help completing a cyber-insurance questionnaire honestly.
Posture / Checklist Review
A broad security health check against a practical baseline. A good annual recurring touchpoint.
Incident Response Tabletop Exercise
A facilitated walkthrough of a realistic incident with your leadership team. Reveals gaps a checklist can’t.
Specialized & project work
- Threat hunt (scheduled project engagement)
- Digital forensics — litigation, insurance, investigations
- Executive exposure assessment (with the individual’s own consent)
When you’re ready: ongoing coverage
Once you know where you stand, monitoring keeps watch so problems get caught early instead of discovered late.
- Managed detection & response — auto-containment + human response window
- Monitoring essential — alerting + monthly report
- IR retainer — response window + discounted incident rates
Every engagement is scoped to your business. Tell me what you’re dealing with and I’ll send a quote.