Cybersecurity & Risk Review
An honest picture of your real exposure — written for leadership, without jargon or unnecessary alarm.
fixed fee
- Organizations that have never had a formal cybersecurity review
- Anyone unsure whether current tools and practices are adequate
- Organizations that have experienced an incident or near-miss
- Anyone who needs to demonstrate readiness to insurers, funders or partners
What it covers
- 01
Microsoft 365 security configuration
Settings, defaults and the gaps that accumulate over years.
- 02
Identity and access management
Who can reach what, and who still can after they left.
- 03
Multi-factor authentication
Coverage, gaps, and the accounts that quietly bypass it.
- 04
Backup and recovery
Whether backups exist, and whether anyone has ever tested a restore.
- 05
Endpoint and email security
Device protection and phishing exposure.
- 06
Vendor and MSP responsibilities
What your provider is actually contracted to do.
- 07
Cyber insurance readiness
The questions insurers ask, and how you would answer them today.
What you receive
Plain-language findings summary
What was reviewed and what was found, written for leadership.
Risk summary by urgency
Issues ranked by urgency and impact.
Practical recommendations
Specific, actionable steps grounded in your tools and budget.
Board-ready executive summary
Optional, for presenting risk priorities to your board.
Sometimes the roadmap points at something we happen to build.
When it does, we say so plainly and you are free to ignore it. Advisory clients get our products at the same published price as everyone else — there is no bundled discount, because a discount would give us a reason to recommend software you do not need.
See the productsWe hold no product affiliations with Microsoft, any MSP, or any software vendor, and we take no referral commissions. The most common recommendation we make is to spend less, not more.
Ready to get clarity?
Start with a thirty-minute conversation. No obligation.