TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one agreement Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Who We Serve  /  Small & Medium Business

A senior security executive on retainer, for companies that can't hire one full time.

You're not ready for a full-time CISO and you might never be. What you need is someone senior who owns the outcome, shows up every month, and handles the things that keep landing on whoever happens to be closest. That's a retainer: a $2,500 assessment to start, $5,000 a month for the program, and the full price list is below.

88%
of breaches at small and mid-size businesses involved ransomware, against 39% at large organizations.
Verizon, 2025 Data Breach Investigations Report
43%
of security incidents involved shadow AI, more than double the year before.
IBM, Cost of a Data Breach Report 2026
35%
of small organizations say their cyber resilience is inadequate, a share that has grown sevenfold since 2022 while large organizations' has nearly halved.
World Economic Forum, Global Cybersecurity Outlook 2025
The thing nobody is watching

Your employees are already using AI. The question is whether your company knows how.

Nobody ran a procurement process for this. Someone signed up for a chatbot, it worked, and word got around. By now customer lists and contracts have probably been pasted into tools no one at the company has reviewed. That is the risk profile of most small companies right now, whether or not anyone has looked.

FIND IT

Shadow AI discovery

We find which AI tools are in use across browsers, extensions, endpoints and your SaaS estate, and which accounts they were signed up with. The inventory is usually a surprise, and it is the fastest thing we can give you.

GOVERN IT

Policy and training people follow

An acceptable use policy written in plain English, an approval path for new tools, and training that covers what staff now face: cloned voices on the phone, video that looks like the CEO, and phishing emails with no spelling mistakes to give them away.

DEFEND IT

Controls where the data moves

Data loss prevention around AI tools, least-privilege access to anything AI can reach, and vendor review of the AI features your existing suppliers quietly switched on last year without asking you.

Before you turn on Copilot

Copilot and Gemini don't create new permissions; they surface the ones your tenant already has, including every sharing mistake since it was set up. Cleaning that up before the rollout is a small job, and Microsoft's own guidance says to do it first. We check it before anyone switches the assistant on.

Your customers have started asking

AI questions are showing up in enterprise security questionnaires, and auditors are now asking for evidence of data-flow controls around AI integrations. A policy saying "don't paste customer data into ChatGPT" gets no credit as a control. If you sell to anyone larger than you, this is about to become a sales problem.

Pricing

Published rates

Prices are listed rather than quoted on request.

Cyber Risk Assessment
Where nearly everyone starts. One engagement, no commitment afterwards.
$2,500one timeDelivered in 10 business days
  • External attack surface review
  • Security controls, identity and MFA assessment
  • Endpoint, backup and recovery assessment
  • Vendor risk and compliance gap analysis
  • Cyber insurance gap review
  • Executive risk report and 90-day roadmap
AI Security Bundle
For companies that want the AI work on its own. It is also included in the Security Leadership Program below.
$2,500–$5,000/ monthPriced on company size and scope
  • AI risk assessment and shadow AI discovery
  • AI usage and governance policy
  • AI data protection and vendor risk review
  • Staff training on deepfakes, phishing and data leakage
  • AI incident response procedures
  • Quarterly AI risk review
  • Executive AI risk dashboard
Our main offer
Security Leadership Program
Enterprise cybersecurity leadership for companies that aren't ready for a full-time CISO.
$5,000/ monthAgainst $250,000+ for the equivalent hire
  • Monthly executive security review
  • Security roadmap, risk register, board reporting
  • SOC 2, HIPAA, NIST and CMMC readiness
  • Policy management, security questionnaires, vendor risk
  • Architecture review, vulnerability management, SOC oversight
  • Incident response plan and tabletop exercise
  • Cyber insurance renewal prep and control validation
  • AI governance included

The path most companies take is assessment, then roadmap, then retainer, and there's no obligation to move along it. Retainers run month to month after an initial term. Monitoring, endpoint and identity detection, and email security are quoted on top depending on your environment, because those costs depend on how many users, endpoints, and mailboxes you have.

What you're buying

What the retainer covers

CISA makes this point about smaller organizations: you may not have a formal CIO or CISO, but those functions still have to be owned at an executive level by somebody. In practice they get spread across several people, and things end up half done.

01

Someone owns it

A named person, in your monthly leadership meeting, accountable for the answer when a client, an insurer or your board asks a hard question.

02

The questionnaires stop being your problem

Enterprise security reviews get answered by us, on your behalf, with evidence attached. For a firm selling to larger customers, this is often the fastest return on the retainer.

03

Your insurer gets real answers

We prepare the renewal and validate the controls you're attesting to, so the policy you're paying for responds when you need it.

04

Your MSP keeps doing its job

We work alongside whoever runs your systems rather than replacing them. In practice that means a kickoff call with your provider, agreed lines on who owns what, and no reselling of what they already sell you. They keep things running; we're accountable for whether it's defensible.

Industries

Who this is for

We work best with businesses between roughly ten and five hundred people, where somebody owns technology as part of a broader job and nobody owns security outright.

Professional services

Law firms, accounting practices, consultancies. You hold your clients' most sensitive material, and increasingly they're the ones asking you to prove you can protect it.

Client questionnairesSOC 2Privilege & confidentiality

Media & publishing

Local television, radio, digital news and production houses. If the broadcast chain is compromised, the failure happens on air.

Production systemsSource protectionContinuity

Nonprofits & mission-driven

Foundations, associations, community organizations. Donor data and grant records, defended on an overhead budget everybody scrutinises.

Donor dataGrant complianceVolunteer access

Healthcare-adjacent

Dental groups, therapy practices, billing companies, medical suppliers. HIPAA applies to you, and most practices have never had anyone walk them through what it requires.

HIPAABusiness associate agreementsPHI handling

Financial & insurance services

Independent advisors, agencies, mortgage brokers, lenders. The FTC Safeguards Rule reaches further than most owners expect, and enforcement has picked up.

FTC SafeguardsGLBAPCI-DSS

Multi-site operators

Franchises, clinics, dealerships, regional service companies. Every location is its own network, and the ones nobody visits tend to have the oldest equipment.

Site-to-siteWireless auditsStandard policy
What we find

What usually breaks

The same five failures show up in company after company, and none of them are exotic. This is where an assessment looks first.

01

No one is accountable

Security lives with an office manager, a founder, or an outsourced help desk whose contract covers uptime and nothing else.

02

Everything runs on cloud defaults

Microsoft 365 and Google Workspace arrive configured so everything works for everyone on day one. Years later, legacy sign-in is still enabled and sharing is still wide open, because nobody was ever asked to change it.

03

AI showed up without a decision

Nobody approved it, nobody inventoried it, and the accounts it runs on aren't company accounts, which means there's no logging and no way to get the data back.

04

Compliance arrives as a surprise

A client sends a questionnaire, or an insurer asks for evidence, and suddenly a framework you'd never heard of is a condition of doing business.

05

Backups exist but were never tested

Most companies have backups. Fewer have tested a restore in the last year, and the first test usually happens during an incident.

Start with the assessment.

$2,500, ten business days, and a ranked list of what to do. If you want us to execute the roadmap afterwards we'll talk about a retainer. If you'd rather take it to someone else, the report is still yours.