Skip to content
Tidebreak Advisory

Services

Three engagement tiers with scope set in a short scoping conversation. Each is a fixed fee, stated in the engagement letter. The typical-investment band per tier is below; the exact fee depends on the size and complexity of your environment.

Engagement tiers

TIER 1

Snapshot Scorecard

Timeline: 1 to 2 weeks

A visibility-level read on where your controls stand against CIS Controls v8.1.2 and NIST CSF 2.0, what's likely to surface in a cyber insurance renewal, and what's worth a deeper look. You receive a scorecard with severity-rated findings and a short remediation roadmap.

Typical investment: $12,000 to $20,000

Schedule a scoping call

TIER 2

★ The Core Engagement

Comprehensive Assessment

Timeline: 3 to 5 weeks

The core engagement. Documentation review, technical assessment, structured interviews with your team and with your IT provider, and a review of your MSP contract and service-level commitments against what's actually being delivered. You receive a full deliverable set built around five core documents: an Executive Report for your leadership, a Full Assessment Report, a Risk Register, a Remediation Roadmap, and a CIS Controls v8.1.2 Scorecard. Where the scope reaches them, the set also carries an MSP Assessment Summary, a Cloud Migration Assessment, a Vulnerability Assessment, a Hardware and Device Inventory Summary, a Secure Score Reconciliation, and a Platform Decision Memo. The engagement closes with a briefing session for your leadership.

Typical investment: $35,000 to $45,000

Schedule a scoping call

TIER 3

Ongoing Oversight

Timeline: Quarterly retainer

For firms that want an independent read as a standing part of their governance. Quarterly reassessment, roadmap tracking, cyber insurance questionnaire review, and as-needed advisory during MSP transitions, M&A, or regulatory events.

Typical investment: $50,000 to $75,000 per year

Schedule a scoping call

Tier 2 · Comprehensive Assessment

What you receive

The deliverable is a set of documents your leadership can act on, not a single PDF. Some are produced in every assessment. Others depend on what your scope includes. Throughout, the people we interview appear by their role, never by name.

In every assessment

Executive Report

A short, answer-first read for leadership: the posture headline, the themes that matter, and the decisions in front of you.

Full Assessment Report

The complete record. Every finding written up, mapped to the frameworks, with the evidence behind it.

Risk Register

Each finding scored for likelihood and impact, with the reasoning shown, sorted into priority tiers.

Remediation Roadmap

The fixes sequenced by what has to happen first, with owner, effort, and whether each is achievable on your current licensing or needs new spend.

CIS Controls v8.1.2 Scorecard

Your standing against the CIS Controls v8.1.2 IG2 safeguards. Safeguards we could not assess from the evidence are marked as such, not assumed.

When your scope includes them

MSP Assessment Summary

Your IT provider's contract and service-level commitments read against what is actually being delivered, with the metrics you can hold them to.

Secure Score Reconciliation

Your Microsoft Secure Score restated once the third-party tools you already run are credited, isolating the gap no tool covers.

Vulnerability Assessment

A planning-grade read of software and version exposure across your fleet, prioritized, with end-of-life products called out.

Hardware and Device Inventory Summary

A device census with refresh-cycle and management-state gaps surfaced against your asset register.

Platform Decision Memo

When a core system is reaching end-of-support: a candidate-by-candidate comparison and a decision framework, with the choice left to you.

Cloud Migration Assessment

The design, compatibility read, and cost projection for moving a legacy platform off premises, with a supporting cost-model workbook.