from $6,200
external penetration test
I attack your internet-facing systems the way a real intruder would — email, VPN, portals, exposed servers. You get the exploit chain, a live debrief, and a retest of the fixes at no extra charge. Best for compliance deadlines and “are we actually safe” questions.
scope this →
from $3,400
security audit & config review
A guided walk through your accounts, cloud, backups, and email settings to catch the quiet gaps — the shared admin login, the disabled MFA, the backup that hasn't run since March.
scope this →
$1,150 / month
incident-response retainer
When something goes wrong, you already have my number and a callback commitment. I keep a warm map of your environment so I'm not starting from zero mid-crisis. Includes a yearly tabletop drill with your team.
scope this →
$1,900
phishing simulation & staff drill
A realistic, ethical phishing round for your staff, followed by a short, no-shame training session. You'll know who clicks and, more importantly, why — and how to shrink that number.
scope this →
from $4,700
web application assessment
Deep testing of a single app — auth, business logic, injection, access control — the flaws automated scanners miss. Ranked by real impact, with fixes your developers can act on this sprint.
scope this →