Everything we do, and how the pieces fit together

Every service below is available on its own. Most firms are better served by one of the two packages, because policies written without assessment findings are generic templates, and a risk report split nine ways is homework. One report, one presentation, one roadmap.

Pricing is not published on this site. Every service has a flat rate, confirmed in writing before any work begins. Download the services catalog below to see it, or ask on a free call.

Microsoft 365 or Google Workspace Security Review

START HERE

Nearly every small firm now runs its business inside Microsoft 365 or Google Workspace: email, files, calendars, client documents. It is also where nearly every small firm is quietly misconfigured, because these platforms ship with defaults built for convenience rather than for firms holding other people’s financial records.

Fake-invoice fraud, diverted closing funds, and tax-season wire fraud almost always begin with a compromised or impersonated mailbox. Multi-factor authentication with a few exceptions carved out is not multi-factor authentication. A sharing setting left open is a client file leaving the building.

What we look at

  • Multi-factor authentication coverage, including the accounts exempt from it

  • Conditional access and sign-in policies

  • Legacy authentication protocols still enabled

  • Administrative accounts and how many people hold them

  • Third-party applications granted access to your data

  • External sharing defaults and guest access

  • Your configuration against the vendor security baseline

What you receive

  • A written report grading each area, with every gap explained in plain business language

  • A prioritized fix list your IT provider can work straight from

  • A 30-minute call to walk through the findings and answer questions

Delivered within a week. Read-only access, no software installed.

What it does not cover

This review looks at one system. It does not assess your backups, your workstations, your network, your vendors, or whether your staff would recognize a fraudulent email.

We say so plainly in the report rather than let a clean result on one system read as a clean result overall.

Credit toward a package. Move forward with either package within 90 days and the full cost of this review is credited against it. No obligation beyond the review.

TECHNICAL ASSESSMENTS

Nine assessments, organized by the question they answer

01

Can someone pretend to be us?

  • Email Security Configuration Review:

    SPF, DKIM and DMARC enforcement, impersonation protection, and inbound filtering. The fake-invoice and wire-fraud vector, from both directions.

Each is available on its own. Together they are Package One. Scope varies with firm size, number of accounts, and number of locations. Your flat rate is confirmed before anything starts.

02

Can someone get in?

  • Vulnerability Assessment

    Internal and external scanning for known weaknesses, plus endpoint protection, encryption and patching posture — evaluated against your actual business risk rather than a severity score alone.

  • Dark Web Exposure Check

    Whether your firm’s addresses, domains or credentials appear in known breach data, with urgency-ranked resets.

  • Phishing Resilience Assessment

    Simulated email attacks measuring who clicked and who entered credentials, with training recommendations drawn from actual behavior.

03

If they get in, how far do they get?

  • Microsoft 365 or Google Workspace Security Review

    MFA coverage and exceptions, conditional access, legacy authentication, admin accounts, third-party app access and sharing settings, measured against the vendor baseline.

  • User Access and Permissions Review

    Active accounts belonging to former employees, excessive administrative privileges, and offboarding gaps across your systems.

  • Cloud Storage and Sharing Review

    OneDrive, SharePoint, Google Drive and Dropbox: misconfigured storage, overly permissive links, and access gaps.

04

If they get in, how far do they get?

  • Backup and Recovery Verification

    Whether your backups exist, cover the right data, keep a copy offsite, and actually restore. Includes a witnessed test restore. The single biggest factor in surviving ransomware.

  • Incident Response Readiness Review

    Whether the people who would have to act know what to do: contacts, carrier notification, decision authority, and the gaps between the plan and reality.

Two paths forward

Two packages, because the decision should be simple. The deciding question is not budget. It is who owns the work after our report lands.

Package One

The Assessment

A clear-eyed, evidence-based picture of where you stand today, and exactly what to fix first.

The full assessment, all four questions

  • Email security configuration review

  • Vulnerability assessment, internal and external

  • Dark web exposure check with urgency-ranked resets

  • Phishing resilience baseline

  • Microsoft 365 or Google Workspace security review

  • User access and permissions review

  • Cloud storage and sharing review

  • Backup and recovery verification with test restore

  • Incident response readiness review

Delivered as one unified report

  • Five-minute executive summary

  • Asset and data inventory

  • Risk-rated findings with business impact

  • Prioritized 30/60/90-day roadmap

  • 60-minute findings presentation with live questions

Right for you if

  • You have a capable IT provider or in-house staff who will do the remediation

  • You already have written policies and need them validated, not written

  • Someone in your firm already owns compliance

  • You need a current, evidence-based picture for a specific deadline

You have hands. What you need is eyes.

Package Two

The Security Program

Everything in The Assessment, plus the written program and the trained staff your regulators, carriers and clients expect.

A written program, drafted from your actual findings

  • Written Information Security Plan (WISP)

  • Acceptable Use Policy (AUP)

  • Incident Response Plan (IRP)

  • Implementation guides, employee summaries and acknowledgment forms

  • A one-page first-response card for each key person: who calls whom, in what order, and what not to do in the first hour

Your human defense layer

  • Live, in-person security awareness training built around your own phishing baseline

  • Follow-up phishing simulation to measure improvement

  • Certificates of completion for staff records

  • Year one of the Annual Security Review cycle, scheduled before we finish

Right for you if

  • You have no IT staff, or an IT provider who handles break-fix only

  • You have no written security program, or a template nobody has read

  • Your staff have never had real security training

  • A carrier, regulator or client is asking for a defensible program, not a scan

Nobody owns this yet. That is the gap.

Why one report instead of nine. The assessments produce a single unified document, not a stack of disconnected summaries. Policies written without assessment findings are generic templates. A risk report split nine ways is homework. One report, one presentation, one roadmap.

Policy Development

Under federal law your firm may already be a financial institution. The FTC Safeguards Rule requires a written security program of covered businesses — CPA and accounting firms, tax practices and insurance agencies alike — and IRS Publication 4557 points tax professionals to the same document.

  • Written Information Security Plan

    The foundational written program, including the vendor oversight the Rule requires. Standalone engagements include a scoping questionnaire and environment interview so the plan reflects your actual operations rather than a template.

  • Incident Response Plan

    Who does what when a breach is suspected: steps, contacts, notification timelines, and regulatory and insurance obligations.

  • Acceptable Use Policy

    How employees may use company systems, email and business data. Clear expectations, documented, with an acknowledgment form.

  • Remote Work Security Policy

    Home networks, personal devices, public Wi-Fi, cloud storage and video conferencing, customized to your tools and your team.

All policy engagements include an implementation guide, an employee-facing summary, and one round of revisions.

Security awareness training

Live, interactive, in-person sessions built around your industry and your own phishing results. A phishing simulation is run roughly two weeks beforehand and included, so the session always reflects your firm rather than generic corporate video. Best suited to firms of ten or more staff.

  • Phishing simulation run about two weeks before the session

  • Live, interactive session built on your own results

  • Certificates of completion for staff records

The Annual Security Review

Security is not a one-time project, and neither is compliance. Controls drift on their own, without anyone doing anything wrong:

  • Someone leaves and their account stays active

  • A new application gets connected to your email with nobody reviewing what it can reach

  • New hires arrive who were not there for the training

  • An MFA exception is granted temporarily and never removed

  • A backup job starts failing quietly

  • A sharing link gets set to anyone with the link, for one project, permanently

A firm that assesses once and never returns has a binder and a false sense of security. The annual cycle includes refreshed assessments, an updated risk report with year-over-year comparison, policy updates, a training refresh with a new phishing simulation, a repeat backup restore verification, and two scheduled check-in calls.

Included for year one with Package Two, and available to Package One clients on its own.

PRICING

Every price we charge, in one document

We publish our pricing. Every service in the catalog has its price printed next to it, with package pricing by firm size, so you can see where you land before you ever call. Your exact flat rate is confirmed in a quote after your free consultation and never changes without a scope change you approve in advance.

Not sure which of these you need?

That is what the free consultation is for. We will talk through your environment and which package or individual service is genuinely the best value for where you are. If a package is not right for you today, we will say so. If a single review is all you need this year, that is what we will recommend.