Services
Practical cybersecurity consulting for small teams and organizations without a dedicated security function.
Most of what's on this site is free and always will be. But some problems are easier to solve with someone alongside you — reading your actual setup, asking the awkward questions, and telling you plainly what to fix first.
We take on a small number of engagements at a time. That's deliberate: it keeps the work hands-on rather than templated.
Where we help
Security posture reviews
A structured look at where you stand — accounts and access, endpoints, backups, vendors, and the gaps between them. You get a written summary in plain language, findings ranked by what actually reduces your risk, and a realistic order of operations. Not a 200-page report you'll never open.
Security awareness and training
The single highest-return investment for most small organizations. Phishing recognition, password and MFA hygiene, safe handling of sensitive data — built around how your team really works, not generic slideware.
Policy and documentation
Acceptable use, incident response, access control, data retention. Written so people can follow them, sized to your organization rather than copied from an enterprise template.
Incident preparedness
Deciding who to call, what to disconnect, and what to preserve beforesomething happens. We help you write the runbook and walk through it while the stakes are still hypothetical.
Second opinions
Sometimes you just need someone to sanity-check a vendor's proposal, a tool purchase, or an architecture decision. Short, focused engagements are fine.
How it works
- A conversation. Tell us what's worrying you. No charge, no obligation — and if what you need is outside what we do well, we'll say so.
- A scoped proposal. What we'll look at, what you'll get, what it costs. Fixed scope, no open-ended billing.
- The work. Done collaboratively — you'll understand every recommendation, not just receive it.
- A handoff. Findings, priorities, and next steps you can act on without us.
Who this is for
Small businesses, nonprofits, and teams that have grown past "the IT person handles it" but aren't ready for a full-time security hire. If you have a dedicated security team already, you probably don't need us.
What we don't do
We're straightforward about our limits. We don't do offensive security engagements, penetration testing, or compliance certification audits. If that's what you need, we're happy to point you toward people who do it well.
Start with a conversation
Tell us what's on your mind. If we're not the right fit, we'll tell you that too.