Services

Eight services, each one scoped to your environment before you commit.

Every engagement ships with a kickoff call, a fixed scope, a written report containing the technical findings and an executive summary, and a 30-minute debrief. Pricing reflects the scope of work and the complexity of the environment.

Strategy

Bringing AI into a regulated practice, securely.

AI Readiness and Governance Starter

New

AI tools are showing up in regulated practices whether anyone approved them or not. This four-week engagement gets you ahead of that: an inventory of what your staff already uses, policies and training that fit how you actually work, and a vendor path you can defend to an auditor. You come out knowing what to allow, what to block, and what to do when something goes wrong.

Includes

  • Shadow AI inventory and HIPAA-aware risk assessment of current exposure
  • Approved Tools shortlist with vendor evaluations and BAA review
  • AI Acceptable Use Policy and data classification guidance, tailored to your practice
  • Incident Response addendum covering AI scenarios
  • Live staff training session, recorded for new hires, plus a quick-reference card
  • Vendor recommendation and contract review for your first AI tool
  • 60-minute readout with your team, plus 2 weeks of email Q&A after handoff

Ideal for

Practices in regulated industries (healthcare, behavioral health, dental, legal) that are bringing AI into patient communication, operations, or clinical workflow and want to do it responsibly from the start.

Price range

From $4,800 fixed

Typical duration

4 weeks calendar

Get a quote

Compliance

Regulator-ready, audit-grade deliverables.

HIPAA Security Risk Analysis

Most requested

Every covered entity and business associate is required to keep a current Security Risk Analysis on file. I build yours the way the HHS guidance describes: identify where ePHI lives, pair real threats with real vulnerabilities, rate the risk, and write it up so your leadership can act without a translator. The same document answers the SRA question on cyber-insurance renewals.

Includes

  • ePHI asset identification
  • Threat and vulnerability pair analysis
  • Likelihood and impact ratings
  • HHS-compliant written SRA report
  • Prioritized remediation roadmap
  • Debrief call

Ideal for

Healthcare covered entities (medical practices, dental offices, clinics) and business associates that need a documented, audit-ready SRA on file for regulatory review, a cyber insurance renewal, or a vendor compliance request.

Price range

$1,500 to $3,500

Typical duration

3 to 4 days

Get a quote

NIST RMF Controls Assessment

An independent read on where your controls stand against NIST SP 800-53, the federal catalog of security controls. Useful when leadership, an investor, or an auditor wants evidence rather than assurances, and a natural companion to 800-171 readiness for defense suppliers. You get a written gap analysis and the order I would close the gaps in.

Includes

  • System characterization
  • Control gap analysis (SP 800-53)
  • Risk rating per control family
  • Written findings report
  • Prioritized remediation roadmap

Ideal for

Healthcare organizations, financial services firms, and compliance-driven businesses that want a structured, NIST-aligned look at where their security controls stand and a clear order of operations for closing any gaps.

Price range

$2,500 to $6,000

Typical duration

1 to 2 weeks

Get a quote

PCI-DSS SAQ Support

Your bank or processor requires a PCI-DSS Self-Assessment Questionnaire every year, and figuring out which SAQ applies is half the battle. I determine the right one for how you accept cards, find the gaps against PCI-DSS v4.0, and walk you through the questionnaire and Attestation of Compliance so you can submit with confidence.

Includes

  • SAQ-type determination for how you accept cards
  • Gap assessment against the applicable SAQ (PCI-DSS v4.0)
  • Prioritized remediation guidance
  • SAQ and Attestation of Compliance completion support
  • Executive summary
  • Debrief call

Ideal for

Merchants that accept card payments (retail, restaurants, e-commerce, professional services) and need to determine the correct SAQ, close the gaps, and complete their annual self-assessment and Attestation of Compliance.

Price range

$1,500 to $5,000

Typical duration

1 to 3 weeks

Get a quote

Assessment

Fast, pragmatic checks of where your security stands today.

Security Posture Snapshot

Two hours in your environment, five pages of findings, and your top three risks named in plain English along with the regulatory or insurance pressures that apply. The Snapshot exists so you can get an honest outside read before spending real money on a larger engagement.

Includes

  • 30-minute discovery call
  • Two-hour remote walkthrough
  • Five-page executive-friendly findings report
  • Top three risks named with what to do about each
  • Regulatory and insurance landscape relevant to the business
  • Prioritized next-step roadmap
  • 30-minute debrief call

Ideal for

Owners and operators that want a fast, credentialed read on their current security posture before scoping a larger engagement.

Price range

$997 fixed

Typical duration

5 business days

Get a quote

Vulnerability Assessment

The scanner goes first, then I verify every finding by hand before it reaches your report, so nobody on your side wastes a day chasing false positives. You get a severity-ranked list in plain English with the fix order I would follow on my own network, ready for your IT team or managed service provider to act on.

Includes

  • Automated and manual scanning
  • CVSS-scored findings
  • Prioritized remediation roadmap
  • Executive summary
  • 30-minute debrief call

Ideal for

Organizations new to security assessments, those working under time or budget constraints, and companies preparing for a deeper engagement who want a baseline read before they commit to one.

Price range

$500 to $1,500

Typical duration

1 to 2 days

Get a quote

Security Program Review

You have policies and controls; the question is whether they hold together. I review your program against the framework that fits your business (NIST CSF, CIS Controls, or SP 800-53) and hand you a written gap analysis with a prioritized roadmap your team can execute against. It works equally well for tightening an existing program or building a first one correctly.

Includes

  • Policy and procedure review
  • Control gap analysis
  • NIST CSF / CIS Controls / SP 800-53 mapping
  • Written gap analysis
  • Prioritized remediation roadmap

Ideal for

Organizations with an existing security program that want a credentialed outside review, and those building out their first program who want it built correctly from the start.

Price range

$800 to $2,000

Typical duration

2 to 3 days

Get a quote

Phishing Simulation

A controlled campaign that shows how your team responds to a realistic phishing attempt, followed by awareness training aimed at whatever the campaign actually revealed. Leadership gets numbers to act on, and your staff finishes better prepared for the next real attempt.

Includes

  • Custom phishing templates
  • Click and credential capture metrics
  • Awareness training guidance
  • Executive summary
  • Debrief call

Ideal for

Organizations that want to measure and improve employee security awareness, especially those in regulated industries or those that have already experienced a phishing incident and want to make sure it does not happen again.

Price range

$400 to $900

Typical duration

1 day setup, 1 to 2 week campaign

Get a quote

Every engagement

What you always get, no matter the service.

  • Scoped written proposal before work begins
  • Direct access to me as your single point of contact
  • Executive summary readable by non-technical leadership
  • Prioritized remediation roadmap
  • 30-minute debrief call to walk through findings

Pricing philosophy

From a published range to a fixed quote in one Security Gap Review.

The lower end of each range reflects engagements with a tighter scope or a more straightforward environment, while the upper end reflects larger scope, more complex environments, or tighter timelines.

After the 30-minute Security Gap Review, you receive a written proposal with a fixed price and a clear scope statement that locks the engagement before any work begins.

Book a call

A focused 30-minute Security Gap Review.