Phase 1: Scope
A conversation about what you have. Free, and nothing is touched.
Nobody can price remediation without knowing what's broken. So we don't try. The scoping conversation is free. The assessment is priced from that conversation. The remediation work is priced from the assessment findings. You approve each step before it starts, and neither price moves once agreed.
You sign twice. Everything in between is work you've already read and approved.
A conversation about what you have. Free, and nothing is touched.
The deep read, done by hand across identity, perimeter, network and detection.
Every finding written up, priced, and approved or struck line by line.
The approved design executed, piloted where it can be, logged throughout.
QA on every changed item, a full report, and the keys back.
Half a day. No cost, no obligation.
A conversation about what you have. Circuit provider, firewall, how identity is handled, whether MFA is enforced and on what, what runs on premises versus in the cloud, what's been worrying you.
This stage is conversation only. No access, no scanning, nothing touched. Hands-on work starts once there's a signed agreement, which protects both of us.
That conversation is enough to size the assessment — user count, number of sites, how many firewalls, cloud-only or hybrid. You get a written assessment scope and a fixed price for it.
You sign, or you don't. Nothing has cost you anything up to this point.
One to five days depending on scope.
The deep read. Done by hand, not by running a scanner and forwarding the PDF.
Every part of Intune, Entra, and Azure, walked manually. Secure Score and what's actually behind the number. Conditional Access policies — what exists, what's missing, what's misconfigured. MFA coverage and its gaps. Admin accounts, who holds them, and whether they should. License assignment against what's actually in use.
Domain and email authentication — whether SPF, DKIM, and DMARC are configured and enforced — and what your public-facing services look like from outside.
Whether MDR or XDR is in place and whether it's tuned. Whether detections exist for the things that matter: risky sign-ins, impossible travel, privilege escalation.
Your firewall directly. Which ports are open and why. Who can reach the management interface, from the WAN or the LAN. How many admin accounts and who they belong to. Whether MFA protects them. IPS and DDoS protection status.
A scan across every IP. Rogue DHCP servers, switches, access points, phones, printers, anything answering. Those devices then get checked for default credentials and open management access, because that's where the quiet problems live.
High availability, redundant circuits, what happens when the primary path fails.
Every finding becomes a written item with five parts:
The finding itself, stated plainly enough that you can hand it to someone else and have them understand it.
The actual risk, not a severity label.
What would be changed, and how.
What changes for the people who work there.
The exit path if it causes a problem.
You review the full set and mark what you want done. Anything you decline gets struck.
The assessment engagement ends here.
You own the findings and the Design document whether or not you go further. If you want to hand it to internal staff or another vendor, it's yours — that's what you paid for.
The approved Design items become the remediation scope, priced against a list you've already read line by line.
If you proceed within 60 days, the assessment fee is credited against the remediation engagement.
The assessment pays for itself the moment you decide to act on it.
The design gets executed.
Changes go to a pilot group first unless the change is inherently global. A Conditional Access policy can be piloted; a DNS change can't.
Work happens when it makes sense for your business — after hours, early morning, whichever day is slow. You get a detailed change log recording what was changed, when, and who it affected.
Everything is reviewed and QA'd before handoff. Nothing gets marked complete because the ticket says so.
Every item marked for change gets a QA review. Screenshots and logs are captured where they're needed as evidence.
You receive a full report of the work performed, with an executive summary for people who need the outcome rather than the detail.
An admin walkthrough is available as an add-on. It's not bundled because it takes real time and not everyone wants it.
After handoff, your administrators have access to the environment again. That means a bounded support window rather than an open-ended guarantee: for thirty days after completion, we'll investigate anything that appears to trace back to the work performed. Beyond that, changes made by others make it impossible to attribute a problem honestly. Further work is welcome and gets scoped separately.
Two prices, two boundaries.
Fixed at the scoping conversation. It covers the full review plus the Design document.
Fixed at Design sign-off. Items you approve are in scope. Items you decline are out. Anything discovered or requested after sign-off requires a written amendment with its own price, so you're never surprised by an invoice.
If the environment turns out materially worse than the scoping conversation suggested, that surfaces during the assessment — before remediation is priced, before work begins, and while you can still decide how much of it to take on.
Half a day, no access, no obligation. You leave with a written assessment scope and a fixed price for it.