Risk before severity labels
A scanner's "critical" on an isolated internal box matters less than a long-lived global admin account with no MFA. We rank findings by likelihood and blast radius in your environment, then work top-down.
Approach
No proprietary framework, no maturity wheel, no scare tactics. A short list of operating principles and a process you can follow without a translator.
Principles
A scanner's "critical" on an isolated internal box matters less than a long-lived global admin account with no MFA. We rank findings by likelihood and blast radius in your environment, then work top-down.
A findings list nobody can action is a liability, not a deliverable. Where the fix is in our lane we implement it. Where it isn't, we write the ticket your vendor can execute without a follow-up call.
Reports come in two layers: one page a non-technical owner or board can act on, and the technical detail underneath it for whoever does the work. No jargon used to inflate scope.
A 25-person company doesn't need enterprise controls it can't staff. We recommend the smallest change that meaningfully reduces risk, and we'll tell you when a control is theatre.
Everything gets documented in your systems, under your accounts, with your licensing. No hostage tooling, no undocumented configuration, no dependency on us to understand your own environment.
If your problem is better solved by your existing MSP, a product you already pay for, or a specialist we're not, we'll say so on the first call. It costs us a project and saves you a bad one.
Process
What you run, who touches it, what's forcing the timeline — a customer requirement, an insurance renewal, an incident, or a nagging feeling that nobody's looking. We come out of it with a scope and a number, or a recommendation to go elsewhere.
Read-only review first: identity and admin roles, endpoint fleet and patch state, M365 or Workspace tenant configuration, cloud IAM, network and firewall posture, backup coverage and last successful restore, email authentication, and the human process around all of it. Interviews where documentation doesn't exist — which is most places.
Every finding gets a plain description, real-world impact, an owner, an effort estimate, and a fix. Sorted into what we do this month, this quarter, and what you consciously accept. Accepting a risk on purpose is a legitimate answer; not knowing about it isn't.
Quick wins first — MFA gaps, stale admin accounts, unpatched exposure, missing backups. Then the structural work: SSO, Intune or MDM baselines, segmentation, logging, recovery testing. Changes are staged and reversible, with maintenance windows agreed in advance.
Runbooks, network and identity diagrams, an asset and licence inventory, and the policy set your auditor or insurer will ask for. Written so your next hire or next vendor can pick it up cold.
Posture decays: people leave, tools sprawl, patches lag, someone re-enables legacy authentication. Ongoing engagements cover patch and vulnerability cadence, awareness training, questionnaire support, and a quarterly review against the original findings list.
FAQ
Usually not. An MSP keeps things running; we own security posture and the projects that need deeper specialisation. We work alongside them — and if they're doing something that creates risk, you'll hear it from us directly.
No one can — certification comes from an independent CPA firm's audit, and anyone who claims otherwise is selling you something. We do the readiness work: control design, evidence collection, policy set, gap remediation, and audit support so the audit isn't a surprise.
Scoping calls usually happen within a few business days. Urgent situations — suspected compromise, a deal blocked on a questionnaire, a failed restore — get prioritised. Say so in your first email.
Assessments are fixed-price against a defined scope; projects are quoted per deliverable; ongoing advisory is a flat monthly fee. You get the number before any work starts, and we don't bill discovery as a surprise line item.
Yes, before discovery starts. Send yours or we'll provide one.
Yes. Most of this work is remote by nature. On-site is available in the New York / New Jersey metro area for network, camera, NAS and AV work that genuinely needs hands on hardware.
Next step
Worst case you get a second opinion and an honest answer about whether you have a real problem. Best case we fix it.