TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one agreement Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Education · Small Business · Portfolio Companies

Cybersecurity for the organizations that can't afford to fail.

A university, a school district, a forty-person firm, a fund with a dozen portfolio companies. Each of them holds data attackers want, and none of them has a security department. We act as that department, on a retainer sized to the organization.

The first conversation is free and takes about half an hour. You will come out of it knowing whether we are the right people for the problem.

48%
of all breaches now involve ransomware, up from 44% a year earlier.
Verizon, 2026 Data Breach Investigations Report
85%
of ransomware attacks on education used a stolen or phished identity to get in.
Sophos, State of Ransomware in Education 2026
88%
of breaches at small and mid-size businesses involved ransomware, against 39% at large enterprises.
Verizon, 2025 Data Breach Investigations Report
Who we serve

Who we work with

Three kinds of organization, with one thing in common: they hold data worth stealing and have nobody whose whole job is protecting it.

Education

Where we started, and still most of our work. Colleges, universities, and K-12 districts, carrying student records, research data, and financial aid on budgets that were tight long before any of this began.

GLBA SafeguardsHECVATNIST 800-171FERPA
Explore education

Small & Medium Business

Law and accounting firms, local media, consultancies, nonprofits, healthcare-adjacent practices. Attackers moved down-market once large enterprises hardened up, and most smaller organizations have not adjusted to being worth the trouble.

SOC 2FTC SafeguardsPCI-DSSHIPAACyber insurance
Explore small business

Investors & Portfolio Companies

Venture and private equity firms carry security risk they never underwrote. We run diligence before the wire goes out and build security across the portfolio afterward, through one relationship instead of one per company.

Pre-close diligencePortfolio programsBoard reporting
Explore investor services
How it works

A conversation, then an assessment, then a retainer if it makes sense.

There is no year-long contract on the first call. You can stop after any step and keep what you have.

STEP 1

A free consultation

About half an hour with someone senior. You describe what is going on and we tell you what we would look at first and roughly what it would cost. Sometimes the answer is that you are in better shape than you thought.

STEP 2

A cyber risk assessment

A fixed-price review scored against a maturity framework, with a roadmap ranked by what would hurt most if it went wrong. The report is yours to keep whether or not you go further.

STEP 3

A retainer, if you want one

A named security leader who shows up every month, with compliance, monitoring, and incident response handled under one agreement. Month to month after an initial term.

Services

What we do

The judgment work is done by people you will know by name. Round-the-clock monitoring, endpoint protection, and email security come through partners we select and manage under the same agreement.

Virtual CISO & Advisory CIO

Senior security leadership on retainer: strategy, risk decisions, vendor evaluation, and reporting to your board or cabinet.

Governance, Risk & Compliance

Policy, audit preparation, and compliance work mapped to GLBA, FERPA, HIPAA, SOC 2, FTC Safeguards, PCI DSS, and NIST 800-171.

Cyber Risk Assessment

A scoped review that produces a maturity score and a ranked roadmap, and gives us a working understanding of your environment.

24/7 Monitoring & Response

Continuous detection across endpoints, identity, and cloud, with analysts reviewing what the tooling raises, plus an incident response plan written in advance.

AI Security & Governance

Finding the AI tools already in use, writing the policy, training staff on deepfakes and data leakage, and putting controls where the data moves.

Penetration Testing & Tabletops

Testing that mirrors how attackers work, and an exercise that walks your leadership through an incident before a real one.

Why TriVigil

Why clients stay

The same person every month

You are assigned a security leader who learns your environment. That person runs the quarterly review, answers the auditor, and takes the call during an incident.

Nothing to sell you

We do not make or resell a security product. If the tools you own are adequate, the recommendation is to keep them and configure them properly.

Priced for your size

A retainer costs a fraction of a full-time security executive, the assessment is a fixed price, and the numbers are on this site.

Find out where you stand.

The first conversation is free and takes about half an hour. If an assessment makes sense after that, you will know what it covers and what it costs before you decide.