Security consulting · churches · nonprofits · small business

A Security Architect for organizations
too small to hire one. By the project.

Most organizations we meet are not missing tools. They are missing the person who decides which risks actually matter, writes it down, and is reachable at 2am when something goes wrong. That is the job. We do it by the project, at a fixed scope, in plain English — and we tell you when you do not need us.

No retainer required · Fixed scope, fixed price · Call or text (940) 281-6672

Fixed scopeYou get the scope, the price and the deliverable before anything starts. No open-ended hours.
Plain EnglishEvery deliverable is written to be read by a board or a pastor, not only by an IT person.
We say noIf a control you already have covers it, we say so. Selling you something you do not need costs us the relationship.

The scoping session comes first, and it is free.

Thirty minutes. We ask how your organization actually runs — who handles money, who has admin access, what happened the last time something went wrong, what your insurer already asked you. Then we tell you which of the engagements below is worth doing, in what order, and what it costs. If the answer is "none of them yet", that is what you will hear.

Engagements

Security Posture Review
from $2,500
  • Where your risk actually is — ranked, not a 200-item scanner dump
  • Identity and access: who can reach money, donor data, and payroll
  • Email authentication (SPF/DKIM/DMARC) and spoofing exposure
  • External attack surface — what the internet can already see
  • Backup reality check: not "do you have backups" but have they been restored
  • A written report a board can read, and a prioritized fix list
Start with a scoping session
Incident Response Readiness
from $4,500
  • A named incident commander and deputy — the single most common gap
  • One agreed vocabulary, so nobody argues about terms mid-incident
  • Your regulatory clocks written down: what must be reported, to whom, in how long
  • Your insurer's 24-hour number, and what their funded response actually covers
  • An out-of-band channel for when email is the compromised thing
  • A tabletop exercise with your real people, and a written lessons-learned
Schedule a scoping session
Cyber-Insurance Readiness
from $1,500
  • We sit down with the questionnaire with you
  • Close the gaps it exposes before you attest to them
  • An evidence packet for renewal — the thing insurers actually ask for
  • Honest answers only: an application that overstates your controls is worse than a decline
Start with a scoping session

Ongoing monitoring is a separate thing, and it is a product rather than a project — that is Org Guard. Many organizations do one engagement here and then keep the monitoring running.

The thing most reviews get wrong

A scanner will hand you two hundred findings and no judgement. The work that matters is deciding which three of those two hundred would actually end your organization, and which hundred and ninety-seven are noise you can safely carry. That judgement is the deliverable. Everything else is a list.

The second thing: a control nobody has tested is not a control. Backups that have never been restored, an alert channel nobody has ever received a message on, a policy that exists as a PDF. We check whether the thing works, not whether it is documented.

Schedule a scoping session.

Thirty minutes, free, no obligation. You leave knowing what we would do, in what order, and what it would cost — whether or not you hire us.

Schedule a scoping session

Or call the Security Architect directly — (940) 281-6672

security@familysentinel.org

Common questions

What does a security consulting engagement include?

It starts with a free scoping session to understand your organization. From there, an engagement typically covers an email-security assessment, a posture review, and hardening of your Google Workspace or Microsoft 365 — focused on the risks that actually matter to you, with the fixes prioritized and walked through.

How is consulting different from Org Guard monitoring?

Consulting is a focused engagement: we assess your security, decide what matters, and help you close the gaps. Org Guard is ongoing monitoring that watches your email every day afterward. Many organizations start with a consulting engagement and then keep monitoring in place.

Do we need to already have security tools in place?

No. Most organizations we meet are not missing tools — they are missing the person who decides which risks matter and in what order. We work with whatever you already have, and recommend only what earns its place.

What size organizations do you work with?

Small businesses, nonprofits, and organizations that do not have a dedicated security team but still have real risk to manage. If you are not sure whether you are a fit, the scoping session is free.

Related guides