For firms of 25 to 150 people: an AI and security plan in 21 days.

The 21-Day Do More With Less Blueprint finds where AI and automation can give your team hours back, where your security has gaps, and what to do first. It takes about 2 hours of your time, and one fix is live before we hand you the plan.

Why firms start here

Three problems that do not fix themselves.

Firms of 25 to 150 people are busy, careful, and short on time. Sorting out AI and security usually waits for a free afternoon that never comes.

  • AI is already in use, without guardrails

    Staff are pasting client work into chatbots to save time. There is no written policy, no approved tool list, and no record of what data has already gone out.

  • Security decisions need an owner

    Your IT provider keeps systems running day to day. Policies, risk decisions, and vendor reviews need someone who owns them. We take that on and work alongside your IT team.

  • Renewal questionnaires are fire drills

    The cyber insurance form arrives, someone hunts for screenshots, and the answers are a best guess. Next year it starts again from zero.

What you get

Seven deliverables, yours to keep.

Everything is written in plain language for owners and partners, with enough detail that your IT provider can act on it without a translator.

AI and security readiness score

A score from 0 to 100 across five areas: AI usage control, data exposure, identity and multi-factor authentication (MFA), backup and recovery, and insurance readiness.

Risk map

Every finding ranked by how likely it is and how much it would hurt, with a named owner for each one.

Quick wins list

Fixes that take a day or less and cost little or nothing. Often the cheapest risk reduction on the whole list.

AI and security policy recommendations

Which AI tools are approved, what data can go into them, and the handful of security policies your firm is missing.

12-month roadmap

What to do each quarter for the next year, in order, with rough effort and cost, so the plan survives a busy season.

Specification for your first automation

The first automation worth building, written as a spec: trigger, steps, data touched, permissions, and how to test it.

Cyber insurance questionnaire evidence pack

Your controls mapped to the questions insurers ask, with the screenshots and documents to back each answer.

A quick win, already live

Before the final readout, your AI policy is adopted and one small automation or security fix is live.

Read a sample report

A full sample Blueprint for a fictional 42-person insurance agency, so you know what lands on your desk on day 21.

Open the sample
Included at no extra cost

Three extras that make the plan stick.

  • A customized AI acceptable use policy, ready to signWritten for your firm and your tools. Your team signs it, and it becomes the rule.
  • A 20-minute recorded staff training on using AI safelyYour staff watch it once. They learn what is fine to paste into an AI tool and what never is.
  • 30 days of email support after the readoutQuestions come up once you start on the roadmap. Send them in and we answer.
The 21 days

Three weeks, about 2 hours of your time.

We do the digging. Your part is a 45-minute kickoff, a 15-minute check-in, and a 60-minute readout. Your IT provider spends a little time granting read-only access.

Week 1

Intake and a quick win

A 45-minute kickoff with the owner or managing partner. We get read-only access, survey how staff use AI today, and pick one small fix or automation to put live right away. The AI policy goes out for signature.

You see
Draft AI acceptable use policy and the quick win underway
Week 2

Assessment and automation spec

We review identity and MFA, email, backups, data sharing, and AI tool settings, and gather evidence for the insurance questionnaire. We pick the first automation worth building and write its spec. A 15-minute check-in confirms we have it right.

You see
Early findings and the automation chosen
Week 3

Readout

A 60-minute readout with your leadership, and your IT provider if you like. We walk through the score, the risk map, and the roadmap, and hand over every file. The quick win is already live.

You get
All seven deliverables, the bonuses, and 30 days of email support
How we handle your access and data Access is read-only wherever possible during the Blueprint, and it is removed at the end. If any system holds patient data, we sign a business associate agreement (BAA) first: we provide ours or review yours, and no patient data reaches us before it is signed. You own your accounts, automations, and documentation, and you keep them if you leave. We keep our own reusable templates and methods.
Price

One flat price, set by headcount.

No hourly meter and no surprise invoice. You know the number before the first call.

Up to 50 employees
$4,500flat

21 days. About 2 hours of your time, total.

  • All seven deliverables
  • All three bonuses
  • A quick win live before the readout
51 to 150 employees
$7,500flat

21 days. About 2 hours of your time, total.

  • All seven deliverables
  • All three bonuses
  • A quick win live before the readout
151 employees and up
From $12,000scoped on a call

Same seven deliverables, scoped to your size: more sites, more systems, more people to interview. We set the fixed price on a 30-minute call.

  • All seven deliverables
  • All three bonuses
  • A quick win live before the readout
The fee comes back if you keep going The full Blueprint fee is credited toward the first quarter of an Operator Program retainer if you sign within 30 days of the readout. See the Operator Program.
Limited by design We take on 4 Blueprints a month. Blueprints start on the 1st and the 15th of each month. Your work is led by our principal consultant, so the number stays small.
Two ways to pay Pay in full, or 50% at the start and 50% at the readout.
Questions

Before you book the call.

We have more than 150 employees. Can we work with you?

Yes. Over 150 employees? The Blueprint starts at $12,000 and we set the fixed price on a 30-minute call. Larger firms usually start with the Partner tier of the Operator Program or a custom scope.

Who is the Blueprint for?

Owners and managing partners of firms with 25 to 150 people where client data and insurance matter: insurance agencies, law firms, behavioral health practices, engineering firms, and medical and dental practices. It fits best when your team already uses AI informally and nobody owns security full time.

What access do you need?

Read-only admin access to your email and file platform, your identity and MFA settings, and your backup console, plus last year's cyber insurance application if you have it. Your IT provider grants it. Access is read-only wherever possible and removed at the end. If any system holds patient data, we sign a business associate agreement (BAA) before we touch it. You own your accounts, automations, and documentation.

Does this work with our IT provider?

Yes. We work alongside them, not instead of them. They keep the help desk and devices. We write the roadmap and the automation spec so they can act on them, and they are welcome at the readout.

What happens after the readout?

You get 30 days of email support. You can hand the roadmap to your IT provider, or ask us to keep building and securing through the Operator Program. The full Blueprint fee is credited toward the first quarter of an Operator Program retainer if you sign within 30 days of the readout.

How do we pay?

Pay in full, or 50% at the start and 50% at the readout. A Blueprint client never pays the Operator Program onboarding fee.

Is the Blueprint a HIPAA risk analysis?

No. For practices that handle patient data, the Blueprint is a readiness assessment, not a full HIPAA Security Rule risk analysis. The full risk analysis is delivered in the Operator Program during the first quarter.

What if we do not sign a retainer?

That is fine. The Blueprint is built to stand on its own: the roadmap, policies, evidence pack, and automation spec are yours whether or not we work together again. There is no follow-on commitment.

Do we have to do the Blueprint before the Operator Program?

Most clients start with the Blueprint. Firms with a recent assessment can start the Operator Program directly. Starting without a Blueprint adds a $4,000 onboarding fee, waived on a 12-month term.

We take on 4 Blueprints a month.

Start on the 1st or the 15th. Book the call first.

A 30-minute call to see if the Blueprint fits your firm. We ask about your team, your tools, and your next insurance renewal.

Where
Phoenix, and remote across the Southwest