What you actually get

Most security assessments end with a hundred-page PDF nobody reads. Ours ends with a score, a short list of what to fix first, and a partner who sticks around to fix it. Deliverables:

What we look at

01

Identity & access

Who can log into what, multi-factor authentication coverage, admin account hygiene, and whether ex-employees are really gone.

02

Email security

Phishing resistance, spoofing protections (SPF, DKIM, DMARC), and the Microsoft 365 mail rules attackers love to abuse.

03

Devices

Laptops and workstations: encryption, updates, screen locks, and what happens if one walks out the door.

04

Data protection

Where your sensitive data lives, who can reach it, and how it's shared — inside and outside the company.

05

Backup & recovery

Whether you could actually recover from ransomware or an accidental deletion — tested, not assumed.

How it works

  1. Kickoff call. 45 minutes. We learn how your business runs and who manages your IT today.
  2. Discovery (weeks 1–2). Mostly read-only review of your configuration. Minimal interruption — most clients spend under three hours total with us during this phase.
  3. Report & roadmap. You get your score, the executive summary, and a prioritized plan. We walk through it together.
  4. Remediation (days 15–90). We implement the fixes — directly, or alongside your existing IT provider. Quick wins usually land in the first two weeks.
  5. Re-score. At the end of the engagement, we measure again so you can see the improvement in numbers.

The honest part: about 90% of what we recommend requires no new software purchases. If you're on Microsoft 365, you already own most of the security stack you need — it's just not turned on. Our job is configuration, not sales.

Who this is for

Businesses with 1 to 100 employees — typically dental and healthcare practices, professional services firms, and financial advisors. If you've ever thought "we're probably fine, but I honestly don't know," this assessment answers that question with evidence.

We're based in Lehi, Utah and work in person across Utah County, Salt Lake County, and Silicon Slopes — and remotely with businesses nationwide. If your practice handles patient data, see how we work with dental and healthcare practices.

Already have IT or an MSP?

Good — keep them. We complement your existing IT provider; we never replace them. They keep things running; we measure and harden security posture. Many engagements end with our roadmap being executed by the client's own MSP, with us verifying the results.

Frequently asked questions

What does the assessment include?

A scored review across identity, email, devices, data, and backup/recovery — plus an executive summary, a technical report, and a prioritized 90-day roadmap.

How long does it take?

About two weeks for the assessment itself; under 25 employees is often 7–10 days. The full engagement, including remediation, runs 90 days.

Will it disrupt our work?

No. Discovery is mostly read-only. Nothing changes until remediation, and changes are scheduled with you.

Do we need to buy new software?

Almost never. The usual exceptions are a SaaS backup for Microsoft 365 and a password manager — each a few dollars per user per month.

What if our score is bad?

Most clients start low — that's the point of a baseline. It's a starting line, not a grade. The roadmap turns the score into a plan.

Find out where you actually stand.

Tell us a little about your business and we'll get back to you soon. Prefer to talk? Call (949) 802-4831, Mon–Fri 9am–5pm MT.