Everything we do, and how the pieces fit together
Every service below is available on its own. Most firms are better served by one of the two packages, because policies written without assessment findings are generic templates, and a risk report split nine ways is homework. One report, one presentation, one roadmap.
Pricing is not published on this site. Every service has a flat rate, confirmed in writing before any work begins. Download the services catalog below to see it, or ask on a free call.
Microsoft 365 or Google Workspace Security Review
START HERE
Nearly every small firm now runs its business inside Microsoft 365 or Google Workspace: email, files, calendars, client documents. It is also where nearly every small firm is quietly misconfigured, because these platforms ship with defaults built for convenience rather than for firms holding other people’s financial records.
Fake-invoice fraud, diverted closing funds, and tax-season wire fraud almost always begin with a compromised or impersonated mailbox. Multi-factor authentication with a few exceptions carved out is not multi-factor authentication. A sharing setting left open is a client file leaving the building.
What we look at
Multi-factor authentication coverage, including the accounts exempt from it
Conditional access and sign-in policies
Legacy authentication protocols still enabled
Administrative accounts and how many people hold them
Third-party applications granted access to your data
External sharing defaults and guest access
Your configuration against the vendor security baseline
What you receive
A written report grading each area, with every gap explained in plain business language
A prioritized fix list your IT provider can work straight from
A 30-minute call to walk through the findings and answer questions
Delivered within a week. Read-only access, no software installed.
What it does not cover
This review looks at one system. It does not assess your backups, your workstations, your network, your vendors, or whether your staff would recognize a fraudulent email.
We say so plainly in the report rather than let a clean result on one system read as a clean result overall.
Credit toward a package. Move forward with either package within 90 days and the full cost of this review is credited against it. No obligation beyond the review.
TECHNICAL ASSESSMENTS
Nine assessments, organized by the question they answer
01
Can someone pretend to be us?
Email Security Configuration Review:
SPF, DKIM and DMARC enforcement, impersonation protection, and inbound filtering. The fake-invoice and wire-fraud vector, from both directions.
Each is available on its own. Together they are Package One. Scope varies with firm size, number of accounts, and number of locations. Your flat rate is confirmed before anything starts.
02
Can someone get in?
Vulnerability Assessment
Internal and external scanning for known weaknesses, plus endpoint protection, encryption and patching posture — evaluated against your actual business risk rather than a severity score alone.
Dark Web Exposure Check
Whether your firm’s addresses, domains or credentials appear in known breach data, with urgency-ranked resets.
Phishing Resilience Assessment
Simulated email attacks measuring who clicked and who entered credentials, with training recommendations drawn from actual behavior.
03
If they get in, how far do they get?
Microsoft 365 or Google Workspace Security Review
MFA coverage and exceptions, conditional access, legacy authentication, admin accounts, third-party app access and sharing settings, measured against the vendor baseline.
User Access and Permissions Review
Active accounts belonging to former employees, excessive administrative privileges, and offboarding gaps across your systems.
Cloud Storage and Sharing Review
OneDrive, SharePoint, Google Drive and Dropbox: misconfigured storage, overly permissive links, and access gaps.
04
If they get in, how far do they get?
Backup and Recovery Verification
Whether your backups exist, cover the right data, keep a copy offsite, and actually restore. Includes a witnessed test restore. The single biggest factor in surviving ransomware.
Incident Response Readiness Review
Whether the people who would have to act know what to do: contacts, carrier notification, decision authority, and the gaps between the plan and reality.
Two paths forward
Two packages, because the decision should be simple. The deciding question is not budget. It is who owns the work after our report lands.
Package One
The Assessment
A clear-eyed, evidence-based picture of where you stand today, and exactly what to fix first.
The full assessment, all four questions
Email security configuration review
Vulnerability assessment, internal and external
Dark web exposure check with urgency-ranked resets
Phishing resilience baseline
Microsoft 365 or Google Workspace security review
User access and permissions review
Cloud storage and sharing review
Backup and recovery verification with test restore
Incident response readiness review
Delivered as one unified report
Five-minute executive summary
Asset and data inventory
Risk-rated findings with business impact
Prioritized 30/60/90-day roadmap
60-minute findings presentation with live questions
Right for you if
You have a capable IT provider or in-house staff who will do the remediation
You already have written policies and need them validated, not written
Someone in your firm already owns compliance
You need a current, evidence-based picture for a specific deadline
You have hands. What you need is eyes.
Package Two
The Security Program
Everything in The Assessment, plus the written program and the trained staff your regulators, carriers and clients expect.
A written program, drafted from your actual findings
Written Information Security Plan (WISP)
Acceptable Use Policy (AUP)
Incident Response Plan (IRP)
Implementation guides, employee summaries and acknowledgment forms
A one-page first-response card for each key person: who calls whom, in what order, and what not to do in the first hour
Your human defense layer
Live, in-person security awareness training built around your own phishing baseline
Follow-up phishing simulation to measure improvement
Certificates of completion for staff records
Year one of the Annual Security Review cycle, scheduled before we finish
Right for you if
You have no IT staff, or an IT provider who handles break-fix only
You have no written security program, or a template nobody has read
Your staff have never had real security training
A carrier, regulator or client is asking for a defensible program, not a scan
Nobody owns this yet. That is the gap.
Why one report instead of nine. The assessments produce a single unified document, not a stack of disconnected summaries. Policies written without assessment findings are generic templates. A risk report split nine ways is homework. One report, one presentation, one roadmap.
Policy Development
Under federal law your firm may already be a financial institution. The FTC Safeguards Rule requires a written security program of covered businesses — CPA and accounting firms, tax practices and insurance agencies alike — and IRS Publication 4557 points tax professionals to the same document.
Written Information Security Plan
The foundational written program, including the vendor oversight the Rule requires. Standalone engagements include a scoping questionnaire and environment interview so the plan reflects your actual operations rather than a template.
Incident Response Plan
Who does what when a breach is suspected: steps, contacts, notification timelines, and regulatory and insurance obligations.
Acceptable Use Policy
How employees may use company systems, email and business data. Clear expectations, documented, with an acknowledgment form.
Remote Work Security Policy
Home networks, personal devices, public Wi-Fi, cloud storage and video conferencing, customized to your tools and your team.
All policy engagements include an implementation guide, an employee-facing summary, and one round of revisions.
Security awareness training
Live, interactive, in-person sessions built around your industry and your own phishing results. A phishing simulation is run roughly two weeks beforehand and included, so the session always reflects your firm rather than generic corporate video. Best suited to firms of ten or more staff.
Phishing simulation run about two weeks before the session
Live, interactive session built on your own results
Certificates of completion for staff records
The Annual Security Review
Security is not a one-time project, and neither is compliance. Controls drift on their own, without anyone doing anything wrong:
Someone leaves and their account stays active
A new application gets connected to your email with nobody reviewing what it can reach
New hires arrive who were not there for the training
An MFA exception is granted temporarily and never removed
A backup job starts failing quietly
A sharing link gets set to anyone with the link, for one project, permanently
A firm that assesses once and never returns has a binder and a false sense of security. The annual cycle includes refreshed assessments, an updated risk report with year-over-year comparison, policy updates, a training refresh with a new phishing simulation, a repeat backup restore verification, and two scheduled check-in calls.
Included for year one with Package Two, and available to Package One clients on its own.
PRICING
Every price we charge, in one document
We publish our pricing. Every service in the catalog has its price printed next to it, with package pricing by firm size, so you can see where you land before you ever call. Your exact flat rate is confirmed in a quote after your free consultation and never changes without a scope change you approve in advance.
Not sure which of these you need?
That is what the free consultation is for. We will talk through your environment and which package or individual service is genuinely the best value for where you are. If a package is not right for you today, we will say so. If a single review is all you need this year, that is what we will recommend.