FAQ

Questions, answered plainly.

The things businesses most often ask us before getting started. Don't see yours? Get in touch — we're happy to talk it through.

The basics
We're a small business — are we really a target for cyberattacks?

Yes. Most attacks aren't personal; they're automated, scanning the internet for any system with a known weakness. Smaller businesses are often hit precisely because they assume they're too small to bother with and haven't hardened their defenses. The question isn't whether you'll be targeted — it's whether you'll be ready when you are.

We already have an IT person or managed IT provider. Why would we need you?

IT and security are related but different jobs. Your IT team keeps systems running and available; security work is about finding the gaps an attacker would exploit — a specialized skill set, and one that benefits from an independent set of eyes. We work alongside your existing IT, not in place of it, and hand them a clear list of what to fix.

Isn't professional security testing out of reach for a business our size?

You can start with a single, focused assessment rather than committing to a large program — you don't need to build an enterprise-sized security function to be meaningfully safer. And in almost every case, a focused engagement costs a small fraction of what a single breach or failed compliance audit would.

Our services & process
What's the difference between a penetration test and a vulnerability scan?

A vulnerability scan is automated, meaning it produces a list of known weaknesses a tool detected. A penetration test is hands-on: we safely attempt to exploit those weaknesses the way a real attacker would, showing what someone could actually access and how issues chain together. Scans are useful for ongoing hygiene; a test tells you what your real-world risk is.

Will testing disrupt our day-to-day operations?

Avoiding disruption is part of the job. Before any work begins we agree on scope and ground rules, schedule anything sensitive for low-impact windows, and stay in contact with your team throughout. Our goal is for your business to run normally while we work.

What do we actually receive at the end of an engagement?

A prioritized, plain-language report — an executive summary anyone can act on, plus the technical detail your IT team needs. Every finding comes with a clear explanation of the risk and step-by-step remediation. We walk you through it live, and we'll retest after you've made fixes to confirm the gaps are closed.

How much does an engagement cost?

It depends on scope: the size of your environment, how deep the testing goes, and any compliance requirements all factor in. But here's what shapes the number: we work exclusively with small and mid-size businesses, so every engagement is sized to your business, not scaled down from an enterprise template. Firms built for large enterprises carry the overhead — and the price floors — to match, and that cost lands on every client they take. Because small and medium sized clients are who we're built for, ours often pay noticeably less for the same rigor, at a fixed price agreed up front.

Compliance, confidentiality & coverage
Our cyber-insurance renewal includes a security questionnaire we can't fully answer. Can you help?

This is one of the most common reasons businesses call us. We assess your current controls, help you close the gaps the insurer cares about, and make sure you can answer the questionnaire accurately. Answering honestly matters — misrepresenting your controls can void a claim later.

What areas do you serve, and do you work on-site?

We serve small and mid-size businesses across Washington, D.C., Maryland, and Virginia. Physical security assessments are done on-site at your locations; most cybersecurity work can be done remotely, with on-site visits whenever they're useful.

How do you keep what you find confidential?

Confidentiality is fundamental to this work. We operate under signed non-disclosure agreements, handle findings securely and on a need-to-know basis, and we don't publish client names or details without permission. The whole point of hiring us is to surface sensitive issues privately, before anyone else finds them.

Still have a question?

Ask us directly