What the free assessment covers
In about an hour, on site or remote, we look at the controls that stop the most common attacks on small businesses:
- Identity: MFA coverage, admin accounts, former employees with access, password practices.
- Email: phishing filtering, SPF, DKIM and DMARC, suspicious forwarding rules.
- Devices: operating system support, patching, encryption, endpoint protection.
- Backups: what is backed up, where copies live, and whether a restore has ever been tested.
- Network: firewall, Wi-Fi segmentation, remote access and exposed services.
- Compliance fit: which rules apply to you, such as HIPAA, the FTC Safeguards Rule or PCI DSS, and what your cyber insurer is likely to ask.
What you get
A short written report with your risk score, the top gaps in priority order, what each one would take to fix, and a flat monthly or project price if you want us to handle it. There is no obligation, and the report is yours to use with any provider.
Free assessment vs. formal compliance risk assessment
The free assessment is a fast, practical review. Regulated businesses also need a formal, documented risk assessment: HIPAA requires a security risk analysis, and the FTC Safeguards Rule requires a written risk assessment for most covered firms. The formal version inventories every system that holds sensitive data, rates each risk, maps it to the rule’s requirements and produces the documentation an auditor or investigator will ask for. It is quoted as a fixed-price project and often paired with vulnerability scanning and penetration testing.
Want a head start? Take the free 2-minute security check first.
Signs it’s time for Cybersecurity Risk Assessment
- You are not sure every account has MFA.
- A cyber-insurance renewal is coming up.
- You handle patient, financial or card data and have never had an assessment.
- You are switching IT providers and want a baseline.
- You have had a phishing scare or a compromised account.
If two or more of these sound familiar, take the free security check or book a free cybersecurity assessment.
How our Cybersecurity Risk Assessment process works
Book
Pick a time. Tell us your team size and any compliance requirements.
Review
About an hour, on site or remote, with read-only access where needed.
Findings
Written report with your risk score and top gaps, in priority order.
Plan & price
A flat price to fix the gaps, if you want us to. No obligation.
What’s included
- Identity and MFA review
- Email security and domain authentication check
- Device, patching and encryption review
- Backup and recovery review
- Network, firewall and remote access review
- Compliance applicability summary
- Written, prioritized findings
- Flat-price remediation quote, no obligation
Who it’s for
- Businesses with 5 to 50 users
- Healthcare, financial, insurance and professional firms
- Businesses renewing cyber insurance
- Anyone who has never had a security review
What affects the price
Every quote is flat and in writing. These are the factors that move the number:
| Factor | Why it matters |
|---|---|
| Initial assessment | Free, including written findings. |
| Formal compliance risk assessment | Fixed-price project scoped to HIPAA or FTC Safeguards requirements. |
| Security testing | Vulnerability scans and penetration tests quoted by scope. |
| Remediation | Flat monthly managed plan or fixed-price project. |
Assessments across Eagle County
We run assessments for practices in Edwards and Vail, financial and insurance offices in Avon and Eagle, and lodging, retail and trades businesses throughout the valley.
“Todd has helped get our team protected at a level we had no idea existed. As an Insurance Agency, we know the importance of protecting our clients data, Todd has taken that to a new level!”
Frequently asked questions
Is the cybersecurity assessment really free?
Yes. The initial assessment and written findings are free with no obligation. Formal compliance risk assessments, penetration tests and remediation work are quoted separately at a fixed price.
How long does a cybersecurity risk assessment take?
The free assessment takes about an hour of your time, on site or remote, and you receive written findings within a few business days. A formal HIPAA or FTC Safeguards risk assessment typically takes one to three weeks depending on size.
What is the difference between a risk assessment and a penetration test?
A risk assessment reviews your systems, policies and controls to identify and prioritize risks. A penetration test actively attempts to exploit weaknesses to prove what an attacker could actually do. Most compliance programs need both.
Do I need a risk assessment for cyber insurance?
Carriers rarely require a formal assessment, but they ask detailed questions about MFA, backups, EDR and training. An assessment tells you whether your honest answers are “yes,” and what to fix if they are not.
What do I need to prepare for the assessment?
Nothing complicated: a rough count of users and devices, who manages your email and website, and your cyber-insurance application if you have one.
brand