Education
Where we started, and still most of our work. Colleges, universities, and K-12 districts, carrying student records, research data, and financial aid on budgets that were tight long before any of this began.
Explore education →A university, a school district, a forty-person firm, a fund with a dozen portfolio companies. Each of them holds data attackers want, and none of them has a security department. We act as that department, on a retainer sized to the organization.
The first conversation is free and takes about half an hour. You will come out of it knowing whether we are the right people for the problem.
Three kinds of organization, with one thing in common: they hold data worth stealing and have nobody whose whole job is protecting it.
Where we started, and still most of our work. Colleges, universities, and K-12 districts, carrying student records, research data, and financial aid on budgets that were tight long before any of this began.
Explore education →Law and accounting firms, local media, consultancies, nonprofits, healthcare-adjacent practices. Attackers moved down-market once large enterprises hardened up, and most smaller organizations have not adjusted to being worth the trouble.
Explore small business →Venture and private equity firms carry security risk they never underwrote. We run diligence before the wire goes out and build security across the portfolio afterward, through one relationship instead of one per company.
Explore investor services →There is no year-long contract on the first call. You can stop after any step and keep what you have.
About half an hour with someone senior. You describe what is going on and we tell you what we would look at first and roughly what it would cost. Sometimes the answer is that you are in better shape than you thought.
A fixed-price review scored against a maturity framework, with a roadmap ranked by what would hurt most if it went wrong. The report is yours to keep whether or not you go further.
A named security leader who shows up every month, with compliance, monitoring, and incident response handled under one agreement. Month to month after an initial term.
The judgment work is done by people you will know by name. Round-the-clock monitoring, endpoint protection, and email security come through partners we select and manage under the same agreement.
Senior security leadership on retainer: strategy, risk decisions, vendor evaluation, and reporting to your board or cabinet.
Policy, audit preparation, and compliance work mapped to GLBA, FERPA, HIPAA, SOC 2, FTC Safeguards, PCI DSS, and NIST 800-171.
A scoped review that produces a maturity score and a ranked roadmap, and gives us a working understanding of your environment.
Continuous detection across endpoints, identity, and cloud, with analysts reviewing what the tooling raises, plus an incident response plan written in advance.
Finding the AI tools already in use, writing the policy, training staff on deepfakes and data leakage, and putting controls where the data moves.
Testing that mirrors how attackers work, and an exercise that walks your leadership through an incident before a real one.
You are assigned a security leader who learns your environment. That person runs the quarterly review, answers the auditor, and takes the call during an incident.
We do not make or resell a security product. If the tools you own are adequate, the recommendation is to keep them and configure them properly.
A retainer costs a fraction of a full-time security executive, the assessment is a fixed price, and the numbers are on this site.
The first conversation is free and takes about half an hour. If an assessment makes sense after that, you will know what it covers and what it costs before you decide.