Shared passwords. No MFA. One person holding everything together informally. That's a liability, not a system.
We build the security foundation your business should already have — then document everything so your team can operate it without us.
01 / The problem
Three problems we see in nearly every business this size
No one knows who has access to what
Accounts get created, shared, and forgotten. Nobody can produce a current list of who can touch what — until something goes wrong and someone has to find out the hard way.
If that one person leaves, nothing is documented
One person carries the passwords, the setup steps, and the exceptions in their head. There's no written record for whoever has to pick it up next.
You can't prove compliance to anyone who asks
Insurers, auditors, and vendors are asking harder questions before they'll renew a policy or sign a contract. Right now you have nothing in writing to hand them.
02 / How it works
A three-step process, in order
STEP 01 · Discovery
We audit what exists, map the gaps, and deliver a written remediation roadmap. You own the report, whatever you decide to do next.
STEP 02 · Implementation
We configure multi-factor authentication, role-based access, and least-privilege controls across your systems, and deliver full documentation.
STEP 03 · Oversight (optional)
A monthly retainer where we run weekly, monthly, quarterly, and annual reviews so nothing quietly drifts back to where it started.
03 / Packages
Three packages, one order
SECURITY BASELINE DISCOVERY
$4,000
Flat fee · 2–3 weeks
- —Full account and access audit
- —Gap analysis across users, roles, devices, and software
- —Risk-prioritized findings — critical vs. non-critical
- —Written remediation roadmap with a phased timeline
- —30-minute findings call
- —You own the report regardless of what you do next
SECURITY BASELINE IMPLEMENTATION
Starting at $18,000
8–10 weeks · quoted after Discovery
- —MFA enforcement across all accounts and platforms
- —Role-based access controls configured and enforced
- —Least privilege applied across users and systems
- —Access control policy
- —Onboarding and offboarding procedures
- —Role-based access matrix
- —Admin runbook for day-to-day operations
- —Knowledge transfer session with your internal point of contact
SECURITY OVERSIGHT RETAINER
$3,000–$4,000 / mo
30-day notice after day 60
- —Weekly — access log review, anomaly flagging
- —Monthly — user and role audit, written report delivered
- —Quarterly — policy review, permission cleanup, controls assessment
- —Annually — full security posture review, policy updates, next-year recommendations
All engagements begin with Discovery. Implementation is quoted after Discovery is complete. The retainer begins after Implementation. No exceptions — this protects your timeline and your budget. Questions before you commit? Email Kelvin.
04 / Fit
Who this is for — and who it isn't
A fit
- +50–150 employees with no formal IT department
- +One person informally managing access and accounts
- +No documented onboarding or offboarding process
- +A cyber insurance renewal coming up
- +A vendor or client contract requiring security compliance
- +You've had an incident, or a close call, and want it fixed
Not a fit
- −Organizations with an existing IT or security team
- −Pre-revenue or early-stage companies
- −Anyone looking for hourly break-fix support
- −Managed service provider relationships
05 / About
Who you're actually hiring

Kelvin Davis / Principal · Phoenix, AZ
15+ years building secure systems across Boeing, Honeywell Aerospace, and CorVel — a senior cloud and DevOps engineer, not a salesperson.
Most organizations this size have the same gaps: informal access, no documentation, nothing to show an insurer or a vendor. This practice exists to close those gaps directly, without selling you a managed service contract you don't need.
06 / See if we're a fit
Tell us where things stand
A few questions about your business. Real review, no SDR, no calendar bot.