Questions before reaching out

What to expect before a project starts.

Short version

The work is scoped, priced, authorized, tested, and handed off in writing.

Do you work on one-time projects?

Yes. We handle one-time projects for defined technical problems, and we offer ongoing support, maintenance, management, and vCISO engagements when continuing ownership is valuable.

Do I need to sign up for a monthly plan?

No. One-time projects and recurring services are both available. Every engagement has a written scope, price, included work, response expectations, and completion or cancellation terms.

How much does the work cost?

Price depends on scope, access, risk, timing, and the condition of the current environment. After a short review, we can propose a fixed project price, a paid discovery step, or an hourly support session. No work begins until the price and scope are accepted.

Do you provide free assessments?

A short fit call can help determine the next step. Reviews that require tenant access, evidence gathering, analysis, or a written report are paid work with their own deliverables.

Do you offer emergency or 24-hour support?

The site does not promise 24-hour coverage. For an urgent request, describe the business impact and deadline. We will confirm availability before committing to a response time.

Do you work on site?

Remote work is available for projects that can be completed securely without a visit. If physical access is needed, include the location in the inquiry so we can confirm whether on-site work is available.

Can you work with our current IT provider or web vendor?

Yes, when responsibilities and access are clear. Vendor coordination can be included in scope, and the handoff can identify which party owns each service or follow-up task.

How do you handle administrator access and credentials?

Credentials are never requested through the public form. Approved work should use named accounts, least-privilege access, MFA, secure transfer methods, and an offboarding step when the platform supports them.

Can you certify that we are compliant or secure?

No general review can guarantee security or certify compliance by itself. We can review controls in a written scope, document findings, help remediate configuration problems, and provide validation evidence. Audit or certification needs may require a qualified specialist.

Do you provide penetration testing?

Active penetration testing is not offered as a standard open-ended service. Any active security testing requires explicit written authorization, a tightly defined scope, and confirmed technical capability for the requested methods.

Do you offer fractional security leadership or vCISO services?

Yes. A vCISO engagement can establish and run a defined security-program cadence, including the risk register, roadmap, policy and exception work, vendor coordination, leadership reporting, and evidence tracking. The agreement states the included systems, responsibilities, deliverables, decision authority, response expectations, and exclusions.

Will you use our project as a public case study?

Private business information, client names, screenshots, and results are not published without written permission. Synthetic or public-data examples are labeled as such.

What needs to be fixed or finished?

Send a short description of the problem, the result you need, and any timing that matters.

Start a project inquiry