Approach

How we work

No proprietary framework, no maturity wheel, no scare tactics. A short list of operating principles and a process you can follow without a translator.

Principles

Six things we hold to

Risk before severity labels

A scanner's "critical" on an isolated internal box matters less than a long-lived global admin account with no MFA. We rank findings by likelihood and blast radius in your environment, then work top-down.

We do the remediation

A findings list nobody can action is a liability, not a deliverable. Where the fix is in our lane we implement it. Where it isn't, we write the ticket your vendor can execute without a follow-up call.

Plain English, both directions

Reports come in two layers: one page a non-technical owner or board can act on, and the technical detail underneath it for whoever does the work. No jargon used to inflate scope.

Fit the business, not the framework

A 25-person company doesn't need enterprise controls it can't staff. We recommend the smallest change that meaningfully reduces risk, and we'll tell you when a control is theatre.

You keep the keys

Everything gets documented in your systems, under your accounts, with your licensing. No hostage tooling, no undocumented configuration, no dependency on us to understand your own environment.

We say no

If your problem is better solved by your existing MSP, a product you already pay for, or a specialist we're not, we'll say so on the first call. It costs us a project and saves you a bad one.

Process

What an engagement looks like

Scoping call

~30 minutes · no charge

What you run, who touches it, what's forcing the timeline — a customer requirement, an insurance renewal, an incident, or a nagging feeling that nobody's looking. We come out of it with a scope and a number, or a recommendation to go elsewhere.

Discovery & assessment

Typically 1–3 weeks

Read-only review first: identity and admin roles, endpoint fleet and patch state, M365 or Workspace tenant configuration, cloud IAM, network and firewall posture, backup coverage and last successful restore, email authentication, and the human process around all of it. Interviews where documentation doesn't exist — which is most places.

Findings & plan

One document, two layers

Every finding gets a plain description, real-world impact, an owner, an effort estimate, and a fix. Sorted into what we do this month, this quarter, and what you consciously accept. Accepting a risk on purpose is a legitimate answer; not knowing about it isn't.

Remediation

Scheduled around your business

Quick wins first — MFA gaps, stale admin accounts, unpatched exposure, missing backups. Then the structural work: SSO, Intune or MDM baselines, segmentation, logging, recovery testing. Changes are staged and reversible, with maintenance windows agreed in advance.

Documentation & handover

Always included

Runbooks, network and identity diagrams, an asset and licence inventory, and the policy set your auditor or insurer will ask for. Written so your next hire or next vendor can pick it up cold.

Maintenance

Optional, recommended

Posture decays: people leave, tools sprawl, patches lag, someone re-enables legacy authentication. Ongoing engagements cover patch and vulnerability cadence, awareness training, questionnaire support, and a quarterly review against the original findings list.

FAQ

Fair questions

Do you replace our MSP?

Usually not. An MSP keeps things running; we own security posture and the projects that need deeper specialisation. We work alongside them — and if they're doing something that creates risk, you'll hear it from us directly.

Can you get us SOC 2 certified?

No one can — certification comes from an independent CPA firm's audit, and anyone who claims otherwise is selling you something. We do the readiness work: control design, evidence collection, policy set, gap remediation, and audit support so the audit isn't a surprise.

How fast can you start?

Scoping calls usually happen within a few business days. Urgent situations — suspected compromise, a deal blocked on a questionnaire, a failed restore — get prioritised. Say so in your first email.

What does it cost?

Assessments are fixed-price against a defined scope; projects are quoted per deliverable; ongoing advisory is a flat monthly fee. You get the number before any work starts, and we don't bill discovery as a surprise line item.

Will you sign an NDA?

Yes, before discovery starts. Send yours or we'll provide one.

Do you work with companies outside the New York / New Jersey metro area?

Yes. Most of this work is remote by nature. On-site is available in the New York / New Jersey metro area for network, camera, NAS and AV work that genuinely needs hands on hardware.

Next step

Start with the 30-minute call.

Worst case you get a second opinion and an honest answer about whether you have a real problem. Best case we fix it.