Services & pricing · Hulbert, Oklahoma

tell me what you're protecting — I'll price the test right here.

Every engagement below carries the number up front, the retest that comes with it, and a report I'll read back to you out loud. No sales dance, no “contact us for pricing” maze — pick the thing that fits, and let's put a date on the calendar.

★★★★★ the clinics, credit unions & shops that keep my number “she found the wire-fraud door in a morning.”

the engagements

five ways I look at your systems

Fixed-scope work with the price in the open. If your environment is bigger or stranger than what's listed, we scope it on a free 30-minute call — I'd rather size it honestly than hand you a number I'd have to walk back.

01 — external penetration test

the doors facing the internet

I go after everything an outsider can reach — your email, VPN, portals, exposed servers — and chain the weaknesses together the way a motivated intruder would. You watch the interesting parts live, not just read about them.

  • Full external attack surface mapped and tested
  • Live debrief plus a one-page summary for the board
  • Retest of your fixes included — no extra invoice
02 — security audit & config review

the quiet gaps nobody's checked

A guided walk through your accounts, cloud, backups, and email settings. This is where I catch the shared admin login, the mailbox that lets anyone forward mail out, and the backup that hasn't actually run since March.

  • Identity, cloud, backup & email configuration reviewed
  • Findings ranked by real-world risk, not color codes
  • A short fix list your one IT person can actually work
03 — incident-response retainer

my number, ready before you need it

When something goes wrong, you already have me on speed dial and a callback commitment in writing. I keep a warm map of your environment so I'm not starting from zero at 2am, and we run a tabletop drill together once a year so it isn't the first time we've practiced.

  • Two-hour callback when an incident is live
  • Environment mapped ahead of time, kept current
  • Yearly tabletop drill with your team included
04 — phishing simulation & staff drill

find out who clicks, kindly

A realistic, ethical phishing round sent to your staff, followed by a short, no-shame training session. You'll learn who clicks and — the part that matters — why, so we can shrink that number instead of just naming names.

  • Custom lures built around your real business
  • Click and report rates, no individual shaming
  • A 45-minute live training your staff won't dread
05 — web application assessment

the app nobody's ever looked at hard

Deep, hands-on testing of a single application — authentication, business logic, injection, access control — the flaws that automated scanners quietly skip. Everything's ranked by real impact, with fixes written so your developers can act on them this sprint.

  • Manual auth, logic & access-control testing
  • Developer-ready fixes, not vague warnings
  • Retest of the patched findings included

on every engagement

what comes standard, no matter which you pick

The price on each service already includes these — they're not add-ons and they're never a surprise line on the invoice.

01

rules in writing first

Before any testing, we agree the scope, the off-limits systems, and the hours in a signed rules-of-engagement doc. Nothing goes loud without your sign-off, and I stay in contact the whole way through.

02

a report two people can read

One page for the folks who sign checks, detailed steps for the folks who fix things — then I get on a call and read it back with you so nothing gets lost in translation.

03

the same tester, start to finish

You don't get handed to a junior after the sale. The person on your scoping call is the person doing the testing and the person you'll reach if something breaks later.

A security tester working at a dark desk lit by pink-accented terminal screens

how an engagement runs

from first call to clean evidence

  1. 1

    we scope it together

    A free 30-minute call to pin down what's in bounds, what your deadline is, and which service actually fits. You get the flat price before anything starts.

  2. 2

    I test, you stay in the loop

    Careful, hands-on work inside the agreed hours — no reckless stress tests. Anything urgent, you hear from me the same day, not in the report a week later.

  3. 3

    we read the findings together

    You get the written report plus a live walkthrough. I translate every finding into a plain, ranked fix list your team can start on right away.

  4. 4

    I retest your fixes

    Once you've patched, I re-check the findings and update the report — so you're left with clean evidence to hand an auditor, a board, or a customer.

bolt-ons

small extras teams often add

These stack onto any engagement above. Prices are flat unless your setup is unusual — in which case we'll say so on the scoping call rather than after the fact.

Add-on services and prices
Add-onWhat you getPrice
internal network test I test from inside your walls — the “what if someone's already on the network” question. Pairs naturally with the external test. from $3,900
policy & response plan A short, readable incident-response plan and a handful of security policies written for a small team — not a 90-page binder nobody opens. $1,400
extra retest round Beyond the retest already included — for when fixes roll out in stages and you want fresh evidence after each one. $850
board / examiner briefing A 45-minute live session where I present the findings and answer questions from your board, auditor, or examiner directly. $650
bespoke scope Cloud tenant reviews, larger estates, unusual tech — anything that doesn't fit the list above. We size it honestly on a call first. request a quote

what you can count on

the promises behind the price

No boilerplate — just the commitments I hold myself to on every engagement, whichever one you choose.

48h typical time from last test to your report
2h retainer callback when an incident is live
1 : 1 you always talk to the person doing the work
book a scoping call
call book a call