Free · 20 minutes · by phone · no obligation

Pick a time.
We call you.

A plain-English checkup of your organization's security, with a working Security Architect — churches, nonprofits, and small teams on Google Workspace or Microsoft 365. We'll look at what's already protecting you, what isn't, and what to do about it, whether or not that involves us. Nothing to install, nothing to prepare.

Book your call

No times picked yet — tap up to three above.

Prefer to just call? (940) 281-6672 — a person answers.

Booked. Your checkup request is in — we'll call you at one of your chosen times, and confirm the exact time the day before. Nothing else to do; if anything changes, just call (940) 281-6672.

What the 20 minutes looks like

  1. 1We look, together. A quick pass over your real posture — MFA coverage, administrator access, how a payment-change request gets verified, whether your domain can be spoofed, and where an insurance questionnaire would catch you out.
  2. 2Three things to do this week. Free, specific, in plain English — the same advice whether or not you ever become a client.
  3. 3Whether monitoring makes sense. If it does, onboarding is one guided admin call. If something else is the better answer — a platform setting, a finance-office rule — we'll say so. We publish where others are the better fit.

The person on the call is a working Security Architect — the same person who reviews serious alerts for our members. Not a sales team; we don't have one.

What you leave with

If it turns into the Cyber-Insurance Readiness Checkup, here's the full deliverable set.

Beyond the 12-control scorecard: an incident classification & containment authority card (who may act, at each tier), a RACI / decision-authority matrix, a contact sheet with security.txt deployed to your own site, an insurance policy review, a 3-2-1-1-0 backup verification with restore-test evidence, a logging-prerequisites check, and a holding-statement template. Full detail: cyber-insurance readiness →

Deliverables adapted from Dynamic Incident Response by Joshua Wright, © 2026 SANS Institute, licensed CC BY 4.0. Mapped to NIST CSF 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).

Preparation is the hardest security spending to justify — a normal week produces no visible result — and by most accounts the cheapest hour you will spend on an incident, right up until the week you need to know who decides and whether the backup actually restores.

For Texas organizations: Texas law (SB 2610, 2025) bars exemplary (punitive) damages in a data-breach lawsuit against a business with fewer than 250 employees that maintained a cybersecurity program conforming to a recognized framework. This is general information, not legal advice — confirm how it applies to you with your attorney.