A focused set of services, built for compliance-covered firms

Security assessments, compliance readiness, policy development, and security awareness training. Every engagement is flat-rate, defined in scope, and performed only under written authorization. Full pricing for every service is published in our downloadable catalog.

Start here: the Email Security Snapshot

Fixed price · delivered within one week · zero setup on your end

If you've never worked with a security consultant before, this is the engagement to start with. Using only publicly visible information, no access to your systems, no software installed, no time from your staff, we assess whether attackers can impersonate your firm's email domain and send email as your firm to your own clients.

You receive a written report grading your domain's spoofing protection, step-by-step remediation instructions your IT provider can implement in an afternoon, and a 30-minute call to walk through the findings. No obligation beyond the Snapshot. If everything checks out, we'll tell you that and shake hands.

Two packages, because the decision should be simple

Package One tells you exactly where you stand. Package Two builds the complete, documented program your regulators, carriers, and clients expect. Both are quoted flat-rate by firm size in a free consultation.

Package One

Security Assessment & Risk Report

A clear-eyed, evidence-based picture of where you stand today, and exactly what to fix first.

Six technical assessments

  • Vulnerability assessment (internal + external)

  • Microsoft 365 or Google Workspace review

  • Email security configuration review

  • User access & permissions review

  • Dark web exposure check

  • Phishing resilience baseline

Delivered as one unified Risk Assessment Report

  • Five-minute executive summary

  • Asset & data inventory

  • Risk-rated findings with business impact

  • Safeguards Rule / Pub. 4557 gap map

  • Prioritized 30/60/90-day roadmap

  • 60-minute findings presentation with live Q&A

Best for: compliance standing, insurance renewals, and a remediation roadmap.

Package Two

Complete Security Program

Everything in Package One, plus the written program and trained staff your regulators, carriers, and clients expect.

Written security program, drafted from your actual findings

  • Written Information Security Plan (WISP)

  • Acceptable Use Policy (AUP)

  • Incident Response Plan (IRP)

  • Implementation guides, employee summaries, and acknowledgment forms

Your human defense layer

  • Live, in-person security awareness training built around your phishing baseline

  • Follow-up phishing simulation to measure improvement

  • Certificates of completion for staff records

Best for: a complete, defensible, documented security program.

Why one report instead of six. Package One's assessments produce a single unified document, not a stack of disconnected summaries. Policies written without assessment findings are generic templates; a risk report split six ways is homework. One report, one presentation, one roadmap.

Package add-ons. The Cloud Storage & Sharing Review, the Backup & Recovery Review, and the Remote Work Security Policy can be added to either package, with a bundling discount quoted at consultation.

The Annual Security Review

Security isn't a one-time project, and neither is compliance. The Annual Security Review keeps everything you built current, on a defined schedule, not an on-call retainer. Scope adjusts to the package you completed.

  • A refreshed round of technical assessments

  • An updated risk assessment report with year-over-year comparison

  • Policy review and updates

  • A training refresh with a new phishing simulation

  • Two scheduled check-in calls

Individual services

Every service is available standalone, quoted flat-rate in a free consultation. If you need three or more, a package will save you money.


Technical Assessments

  • Email Security Snapshot

SPF, DKIM, and DMARC review to prevent domain spoofing - the fake-invoice and wire-fraud vector. External only; zero setup.

  • Vulnerability Assessment

Internal and external scanning for known weaknesses, plus a check of endpoint protection, encryption, and patching posture, evaluated against your actual business risk, not just a severity score.

  • Microsoft 365 Security Review

MFA status, conditional access, sharing settings, and security defaults, benchmarked against Microsoft standards.

  • Google Workspace Security Review

Admin settings, MFA enforcement, third-party app access, and sharing permissions, benchmarked against Google standards.

  • User Access & Permissions Review

Active accounts of former employees, excessive admin privileges, and offboarding gaps across your systems.

  • Dark Web Exposure Check

Whether your firm's email addresses, domains, or credentials appear in known data breaches, with urgency-ranked resets.

  • Phishing Resilience Assessment

Simulated email attacks measuring who clicked and who entered credentials, with training recommendations from actual behavior.

  • Cloud Storage & Sharing Review

OneDrive, SharePoint, Google Drive, and Dropbox: misconfigured storage, overly permissive links, and access gaps.

  • Backup & Recovery Review

Whether your backups exist, cover the right data, keep a copy offsite, and actually restore when tested. The single biggest factor in surviving ransomware.


Policy Development

  • Written Information Security Plan (WISP)

The foundational written security program the FTC Safeguards Rule requires of covered financial services businesses: CPA and accounting firms, tax practices, and insurance agencies alike. For tax professionals, IRS Publication 4557 points to the same document. Covers the vendor oversight the Rule requires. Standalone engagements include a scoping questionnaire and environment interview so the plan reflects your actual operations, not a template.

  • Acceptable Use Policy (AUP)

How employees may use company systems, email, and business data: clear expectations, documented, with an acknowledgment form.

  • Incident Response Plan (IRP)

Who does what when a breach is suspected: steps, notification timelines, and regulatory and insurance obligations.

  • Remote Work Security Policy

Home networks, personal devices, public Wi-Fi, cloud storage, and video conferencing, customized to your tools and team.


Security Training

  • Security Awareness Training

Live, interactive, in-person sessions built around your industry and your actual phishing results, with no generic corporate videos. Includes certificates of completion.

All policy engagements include an implementation guide, an employee-facing summary, and one round of revisions.

Want the full picture, prices included?

Our services catalog lists every service with its published price, shows a sample report finding in the exact format you'd receive it, and explains how every engagement works. Download it and you'll know what you're buying before we ever talk.