Frequently asked questions

Straightforward answers, including the ones people are afraid to ask.

We focus on small and midsize businesses with roughly 5–50 employees — organizations that manage real security risk but don't have a dedicated security team.

No. We're not a general IT provider. We focus specifically on cybersecurity and can work alongside your existing IT company or provider.

Yes. Reviewing and improving Microsoft 365 security settings is a common part of our engagements.

Yes. We review and help improve Google Workspace security configurations as well.

The assessment reviews areas such as identity and access, MFA, email security, device security, backups, network security basics, policies, and employee awareness, and results in a prioritized roadmap.

Timing depends on scope, but most assessments are completed within one to three weeks from kickoff to final report.

You receive a security posture score, an executive summary, prioritized risk findings, a security scorecard, and a 30/60/90-day roadmap in a management-friendly report.

Yes, if you'd like us to. Our Security Remediation service turns approved findings into implemented improvements. You can also choose to address findings yourself or through your existing IT provider.

Yes. We regularly coordinate with in-house IT staff or outside IT providers to implement changes within an agreed scope.

Not as a standard part of our current services. If your organization specifically needs penetration testing, let us know and we can discuss whether it fits your situation.

Our current services focus on periodic review, reporting, and improvement rather than 24/7 security operations monitoring.

We can help you build stronger general security practices that often support compliance efforts, but we don't claim expertise in any specific regulatory framework unless explicitly agreed as part of an engagement.

We can help guide next steps within the scope of our engagement, but we are not a 24/7 incident-response or breach-remediation firm. For active incidents, you should also involve appropriate legal counsel and specialized responders as needed.

Cybersecurity cannot be guaranteed. Our goal is to identify and reduce risk through appropriate security controls, ongoing review, and practical improvements.

Cost depends on your number of users and devices, the systems involved, and the scope of work. Our assessment packages start at $499, and ongoing Cyber Care plans start at $299/month. Final pricing is confirmed before work begins.

Find out where your business stands.

Start with a practical cybersecurity assessment and get a clear roadmap for what to fix next.