Skip to content

Security Baseline · Step 01

Know exactly where you stand — and what to do first.

The free, low-friction baseline that starts every engagement: a clear-eyed look at your security with a prioritized plan you can actually act on, and the entry point to Managed Security. No jargon, no fear, no 200-page report that sits on a shelf — just the truth about your risk and a roadmap to fix it.

Step one of the program

A baseline built on real data, not guesswork.

Every program starts with a baseline. We scan your environment for a data-driven starting point, then add a hands-on review — so the findings reflect how your business actually works, not a one-size-fits-all checklist.

The result: a faster, more accurate read on your risk and a plan you can actually follow.

Free security-score scan to start
Fast clear findings, not a wait
Plain English you can act on
  1. 01BaselineWe find out where you actually stand and what matters first — a clear picture and a prioritized plan, not a 200-page audit.
  2. 02ProtectWe harden the things attackers go for: identities, email, devices, backups, and the common ways in.
  3. 03MonitorWe watch for real threats across your security signals and escalate the ones that matter — managed detection and response coverage with our team handling the response.
  4. 04RecoverWe keep you ready for the bad day: ransomware and outage preparation, tested backups, and a clear path back to running.
  5. 05ImproveWe keep raising the bar — a recurring roadmap, an honest record of what’s accepted, and reporting you can actually read.

A real managed security program — five plain-English steps, run for you.

How it works

Assess. Prioritize. Roadmap.

No automated scan-and-dump. We look at how your environment actually works, then tell you what to do about it.

  1. 01

    Assess

    Understand where you stand

    We review your infrastructure, cloud, identity setup, and policies against real-world attack patterns — not just a generic standard.

  2. 02

    Prioritize

    Focus on what matters

    Not every finding is urgent. We rank issues by business impact, exploitability, and effort — so you know what to fix first and what can wait.

  3. 03

    Roadmap

    A plan you can follow

    You get a prioritized plan with rough costs and timelines, presented in language your leadership can understand and act on.

What we can look at

Pick the depth that fits the question you’re asking.

Infrastructure & cloud

  • Network and segmentation review
  • Cloud configuration check
  • Backup and recovery readiness
  • Vulnerability scan with real-world prioritization
  • A clear picture of where the gaps are

Microsoft 365 & identity

  • Identity and access configuration
  • Sign-in and access policy review
  • Email security settings (SPF, DKIM, DMARC)
  • File-sharing controls
  • Making the security features you’re paying for actually work

Insurance-readiness gap check

  • Where you stand against the controls carriers ask about
  • Policy and documentation review
  • Technical control verification
  • A quick read on third-party risk
  • A prioritized plan, quick wins first

What you receive

Built for technical staff and leadership alike.

Every baseline includes a clear set of deliverables — the kind you can hand straight to your team or your board.

What’s included

  • A plain-English summary with your security score and the headline findings
  • Detailed findings ranked by how much they actually matter
  • A prioritized plan — what to fix first, with effort and rough cost
  • A gap check against the controls your insurer asks about
  • Quick wins you can act on right away
  • Current-state diagrams of your setup
  • Slides your leadership team can actually use

Not included by default

  • General IT help desk support
  • On-site support
  • Incident-response retainers
  • Compliance-certification ownership
  • Legal or regulatory program ownership

Security Advisory is an add-on inside a managed engagement, not a standalone tier. If we’re not the right fit, we’ll point you to someone who is.

Most requested

Cyber-insurance readiness review

Getting denied for cyber insurance? Paying inflated premiums? We map your current controls against what carriers ask about and give you a clear plan to get approved at the best rate.

  • A gap check against what carriers require
  • Multi-factor authentication, endpoint protection, email security, and backup verification
  • A plan with timelines and rough costs
  • Help filling out the application questionnaire
Book a discovery call

Security Advisory

Security leadership, without the full-time hire.

Security Advisory gives you a dedicated security advisor who knows your business — for strategy, vendor decisions, board updates, incident guidance, and keeping the whole program on track.

It’s an add-on inside a managed engagement, not a standalone tier — added once we’re running your Managed Security program so the advice is grounded in how your environment actually works.

Discuss Security Advisory

The rest of the program

Where the baseline leads.

Steps 02–03 · Protect + Monitor

Managed Security

We run the day-to-day protection so you don’t have to — the path most baselines lead to.

Step 05 · Improve

Evidence & insurance readiness

Pass the cyber-insurance questionnaire — and back it up with real controls. Evidence drawn from the security we actually run.

Stop guessing about your security.

A baseline gives you clarity — what’s working, what’s not, and exactly what to do next. Start free, then book a call and we’ll scope what comes next for your business.