Services

Five offerings for mid-market companies that need security leadership without a full-time hire.

Services

Five offerings. Each one a product you can buy. I don’t lead with the menu — I lead with your trigger (insurance renewal, audit, a bad questionnaire, a near-miss) and map the offering to it.

1. Fractional CISO

You need a named security officer of record, not a part-time consultant who disappears after the assessment.

What you get: Risk assessments, a ranked roadmap, board-ready reporting, insurance and customer questionnaires answered, and ongoing program ownership on a monthly retainer — five to twenty hours a week.

When to call: You don’t have a CISO, the board or your insurer is asking for one, and you can’t justify the salary.

2. Compliance readiness

SOC 2, HIPAA, ISO — whatever the audit or renewal demands. I build the program and stay on as the accountable owner.

What you get: Gap assessment, policy framework, evidence collection, audit support, and a living program — not a binder that goes on a shelf.

When to call: A customer contract, an insurer, or a regulator is requiring proof you don’t have yet.

3. Cyber insurance readiness

Pre-bind assessments and post-bind improvement plans. Brokers and underwriters need this, and it’s the fastest door into a new engagement.

What you get: A plain-language risk picture tied to your coverage, a prioritized fix list, and documentation that survives underwriter scrutiny.

When to call: Renewal is coming, premiums are climbing, or coverage is getting narrower.

4. IT and security alignment

The differentiator. I speak infrastructure and security in the same sentence.

What you get: A clear view of the gap between what your MSP delivers and what the business actually needs — then a plan to close it. High IT spend, low confidence is the entry point.

When to call: You’re paying for IT but still feel exposed, or your MSP and your security story don’t match.

5. Incident readiness

Tabletop exercises, response planning, the conversation nobody wants to have until they do.

What you get: A tested response plan, a tabletop with your team, and a clear chain of command for the day something breaks.

When to call: You have no plan, or the plan you have has never been tested.

What I don’t do (day one)

I don’t manage your Office 365, babysit your servers, or turn wrenches for the sake of it. That’s MSP work — and I have a Rolodex for it. My specialty is getting companies locked down, hardened up, and assessed. If wrench-turning becomes necessary, I’ll handle it or bring in a 1099 — but it’s not the product.

Start a conversation →