ServicesColumbia, SC and the Midlands
One free assessment. Then only what you need.
Three services, in order. The first is free. Every step is scoped and approved in writing before it starts.
Before anything starts
Nothing happens without written authorization
Every engagement starts with a signed scope, including the free assessment. It spells out:
- What’s covered: the specific networks, Wi-Fi, email domain, and accounts.
- What isn’t: anything your business doesn’t own or control, like landlord or internet-provider equipment.
- When: the dates and time windows for on-site and remote work.
- Who approved it: an owner or manager with the authority to say yes.
- How your data is handled, and what happens if something urgent turns up.
If you have an IT provider, they get the plan in writing first. You can pause or stop the work at any time.
Scope of work
- In scope
- Office network, Wi-Fi network “Office-Main”, email domain, Microsoft 365 accounts
- Out of scope
- Landlord and internet-provider equipment, vendor systems
- When
- Remote checks Monday. On-site Tuesday, 6–9 PM.
- IT provider
- Notified in writing
- If urgent
- Work stops and you get a call right away
Signed by an owner or manager
Free security assessment
- Cost
- Free
- On-site
- About 2–3 hours
- Results
- Within a week
A vulnerability assessment finds your weak spots and ranks them by how serious they are. Nothing on your systems is changed.
What I check
- From the outside. What anyone on the internet can see and reach, and whether your email domain can be faked.
- Your network. Computers, servers, printers, and network equipment with known flaws or missing updates.
- Wi-Fi. Password strength, encryption, unknown access points, and whether guests are kept off the office network.
- Accounts. How your email and user accounts are set up, including two-step sign-in and admin access, compared against published security baselines.
- Leaked passwords. Staff email addresses that show up in known data breaches.
- Phishing. A harmless practice email, approved by leadership in advance, to see how many people click.
What you get
- A one-page scorecard with your five numbers
- Your top three risks, ranked by severity
- A walkthrough of the results, in person or by phone
The scorecard shows what’s wrong and how serious it is. Step-by-step fixes are part of remediation.
Scans use safe settings, fragile equipment can be left out, and heavier checks can run after hours.
Remediation
- Cost
- Quoted per project
- Pricing
- Flat, not hourly
- Based on
- What was found
I fix what the assessment found, starting with the most serious risks.
After the assessment, you get a written proposal with a flat price based on what was found and the size of your business. Fix only the critical issues or everything at once. Nothing starts until you approve it in writing.
Typical work
- Close anything exposed to the internet that shouldn’t be, like open remote access
- Turn on two-step sign-in for email and other key accounts
- Stop others from sending email in your name
- Install missing updates and plan replacements for computers past end of support
- Tighten Microsoft 365 or Google Workspace settings
- Secure your Wi-Fi and separate guest access
- Reset exposed passwords and remove old or unused accounts
- Short, practical staff training if the phishing results call for it
Each fix is checked before the project closes, and you get a short record of what changed.
Working with your IT provider
I can work alongside them. I can hand over the findings, or handle the security work while they keep running your day-to-day IT.
Not included
Responding to an active breach, compliance sign-off, and work on systems your business doesn’t control. If you need one of those, I’ll tell you and help you find the right people.
Ongoing monitoring
- Cost
- Flat monthly fee
- Based on
- Business size
- Report
- Monthly, one page
New flaws are found every month. Monitoring catches the ones that affect you before they become problems.
What’s included
- A monthly re-scan of your network and of what’s visible from the internet
- Alerts when staff email addresses show up in new data breaches
- Regular re-checks of your email and account security settings
- A one-page monthly report: what’s new, what’s fixed, and what to do next
- Straight answers when you have a security question
Monitoring means scheduled checks and alerts. It isn’t round-the-clock watching or emergency response.
FAQ
Common questions
Is the assessment really free?
Yes. No cost and no obligation. It lets you see my work before you decide whether to pay for anything.
Will it disrupt my office?
It’s designed not to. Scans use safe settings, fragile equipment can be left out, and heavier checks can run after hours.
What access do you need?
A network connection while I’m on-site, a read-only login for your email and accounts, and a couple of small settings your IT contact adds beforehand. All of it is listed in the scope.
We already have an IT company. Do we need this?
An independent check is useful either way. I’m not there to replace them. They’re told before any work starts, and I can share findings with them.
What if you find something serious?
If there are signs someone is already in your systems, I stop and tell you right away. Breach response is separate work, and I’ll help you get the right people involved.
Is this a compliance audit?
No. It’s a security assessment, not a certification or legal review. The results can still support compliance work you’re doing.
Do you work outside Columbia?
I’m based in Columbia and work across the Midlands. If you’re farther out, ask.
Start with the free assessment.
No cost, no obligation, and nothing happens without your written approval.