What you actually get
Most security assessments end with a hundred-page PDF nobody reads. Ours ends with a score, a short list of what to fix first, and a partner who sticks around to fix it. Deliverables:
- A scored baseline of your current environment — 29 controls across five security domains — so you can measure improvement instead of guessing.
- An executive summary written for owners and office managers, not engineers.
- A technical report your IT provider or MSP can act on directly.
- A prioritized 90-day roadmap — quick wins first, bigger projects scheduled realistically.
- Hands-on remediation — we don't just hand you the list; we work through it with you.
What we look at
Identity & access
Who can log into what, multi-factor authentication coverage, admin account hygiene, and whether ex-employees are really gone.
Email security
Phishing resistance, spoofing protections (SPF, DKIM, DMARC), and the Microsoft 365 mail rules attackers love to abuse.
Devices
Laptops and workstations: encryption, updates, screen locks, and what happens if one walks out the door.
Data protection
Where your sensitive data lives, who can reach it, and how it's shared — inside and outside the company.
Backup & recovery
Whether you could actually recover from ransomware or an accidental deletion — tested, not assumed.
How it works
- Kickoff call. 45 minutes. We learn how your business runs and who manages your IT today.
- Discovery (weeks 1–2). Mostly read-only review of your configuration. Minimal interruption — most clients spend under three hours total with us during this phase.
- Report & roadmap. You get your score, the executive summary, and a prioritized plan. We walk through it together.
- Remediation (days 15–90). We implement the fixes — directly, or alongside your existing IT provider. Quick wins usually land in the first two weeks.
- Re-score. At the end of the engagement, we measure again so you can see the improvement in numbers.
The honest part: about 90% of what we recommend requires no new software purchases. If you're on Microsoft 365, you already own most of the security stack you need — it's just not turned on. Our job is configuration, not sales.
Who this is for
Businesses with 1 to 100 employees — typically dental and healthcare practices, professional services firms, and financial advisors. If you've ever thought "we're probably fine, but I honestly don't know," this assessment answers that question with evidence.
We're based in Lehi, Utah and work in person across Utah County, Salt Lake County, and Silicon Slopes — and remotely with businesses nationwide. If your practice handles patient data, see how we work with dental and healthcare practices.
Already have IT or an MSP?
Good — keep them. We complement your existing IT provider; we never replace them. They keep things running; we measure and harden security posture. Many engagements end with our roadmap being executed by the client's own MSP, with us verifying the results.
Frequently asked questions
What does the assessment include?
A scored review across identity, email, devices, data, and backup/recovery — plus an executive summary, a technical report, and a prioritized 90-day roadmap.
How long does it take?
About two weeks for the assessment itself; under 25 employees is often 7–10 days. The full engagement, including remediation, runs 90 days.
Will it disrupt our work?
No. Discovery is mostly read-only. Nothing changes until remediation, and changes are scheduled with you.
Do we need to buy new software?
Almost never. The usual exceptions are a SaaS backup for Microsoft 365 and a password manager — each a few dollars per user per month.
What if our score is bad?
Most clients start low — that's the point of a baseline. It's a starting line, not a grade. The roadmap turns the score into a plan.
Find out where you actually stand.
Tell us a little about your business and we'll get back to you soon. Prefer to talk? Call (949) 802-4831, Mon–Fri 9am–5pm MT.