Snapshot Scorecard
Timeline: 1 to 2 weeks
A visibility-level read on where your controls stand against CIS Controls v8.1.2 and NIST CSF 2.0, what's likely to surface in a cyber insurance renewal, and what's worth a deeper look. You receive a scorecard with severity-rated findings and a short remediation roadmap.
Typical investment: $12,000 to $20,000
Schedule a scoping call→TIER 2
★ The Core EngagementComprehensive Assessment
Timeline: 3 to 5 weeks
The core engagement. Documentation review, technical assessment, structured interviews with your team and with your IT provider, and a review of your MSP contract and service-level commitments against what's actually being delivered. You receive a full deliverable set built around five core documents: an Executive Report for your leadership, a Full Assessment Report, a Risk Register, a Remediation Roadmap, and a CIS Controls v8.1.2 Scorecard. Where the scope reaches them, the set also carries an MSP Assessment Summary, a Cloud Migration Assessment, a Vulnerability Assessment, a Hardware and Device Inventory Summary, a Secure Score Reconciliation, and a Platform Decision Memo. The engagement closes with a briefing session for your leadership.
Typical investment: $35,000 to $45,000
Schedule a scoping call→Ongoing Oversight
Timeline: Quarterly retainer
For firms that want an independent read as a standing part of their governance. Quarterly reassessment, roadmap tracking, cyber insurance questionnaire review, and as-needed advisory during MSP transitions, M&A, or regulatory events.
Typical investment: $50,000 to $75,000 per year
Schedule a scoping call→