Someone finally owns your security.

Policies, risk reviews, vendor checks, HIPAA readiness, and the cyber insurance renewal, handled by a senior security lead who works alongside your IT provider. The security side of the Operator Program, at a fraction of the cost of a full-time hire.

The gap

Your IT company keeps things running. Who makes the security calls?

In firms of 25 to 150 people, security decisions often land on the office manager, a partner with a spare hour, or an IT provider who was hired to fix laptops.

  • Policies exist on paper, or not at all

    A template from years ago that nobody follows, or nothing written down for the insurer, the auditor, or a client who asks.

  • Vendors get access without a second look

    New software gets client data on the strength of a sales demo. Nobody asks where the data goes or what happens when the vendor has a breach.

  • The bad day has no plan

    When a fraudulent wire request or a ransomware note shows up, nobody knows who calls the insurer, the lawyer, or the clients.

46%

Share of IT providers' customers who lean on that provider as their acting security lead.

Source: Sophos MSP Perspectives survey of 800 managed service providers, Sophos (April 2026).

58%

Share of cyber insurance incidents that were business email compromise or funds transfer fraud in 2025.

Source: 2026 Cyber Claims Report, Coalition (2026).

What we cover

The security work that falls between the cracks.

Sometimes called a virtual chief information security officer (vCISO). We call it part-time security leadership: the decisions, the documents, and the follow-through, without a full-time salary.

A named security lead

One senior person who knows your firm, sets priorities, answers the hard questions from clients and partners, and keeps a 12-month security roadmap moving.

Policies that match how you work

Written for your firm and kept current: access, passwords and multi-factor authentication (MFA), data handling, AI use, remote work, and incident response.

Quarterly risk reviews

What changed, what drifted, and what to fix next, ranked by impact. Written so your IT provider can act on it without a translator.

Vendor security reviews

Before new software gets your client data, we check where the data goes, who can reach it, and what the contract says when something goes wrong.

Incident response readiness

A written plan for the bad day: who decides, who calls the insurer and counsel, and how you keep working. On a 12-month term, tested in a yearly tabletop exercise.

Security on every automation

Every automation we build meets the security floor before it goes live: a permission check, safe handling of its logins, human review for anything touching clients, money, or commitments, and logging. The full security floor.

Alongside your IT

Keep your IT company. Add a security lead.

No rip and replace. We set direction and check the work. Your IT provider keeps doing what they were hired to do, with clearer instructions.

Your IT provider keeps

  • Help desk, password resets, and printers
  • Devices, laptops, and day-to-day support
  • Installing and running the security tools you already have

We bring

  • Security priorities and a 12-month roadmap
  • Policies, risk reviews, and vendor reviews
  • Insurance and client questionnaire answers, with evidence
  • An independent check that the controls are really in place

When an assessment finds a physical gap, such as network, cabling, cameras, or access control, we can scope that project too. It is never the starting point.

By tier

What the security side looks like each quarter.

Every Operator Program tier is one pool of hours you split between AI and security. These are the security pieces in each.

Partner

For firms that report to owners or a board and need someone on call when something goes wrong.

  • Everything in Growth, plus:
  • Incident response on call
  • Quarterly reporting to owners or the board
  • Priority response
$10,000per month

Up to 150 hours per quarter

See Partner
Core

For firms that need a security lead, policies, and a regular check-in.

  • Part-time security leadership
  • Policies kept current
  • Quarterly risk review
  • Next-business-day response
$4,000per month

Up to 60 hours per quarter

See Core

Every tier includes the security floor: an AI acceptable use policy, a permission check on every automation, safe handling of automation logins, human review for anything touching clients, money, or commitments, logging, and a quarterly drift check. On a 12-month term you also get a yearly incident tabletop exercise, a yearly owner security briefing, and a staff training refresh. Help desk is not included.

Who does the work

A senior security lead, not a hand-off.

Your work is led by our principal consultant. The credentials matter because underwriters, auditors, and your clients are the audience for the work.

Certifications
  • CISSP
  • CRISC
  • PMP
  • CompTIA Security+
  • CompTIA Network+
  • CompTIA Project+
  • Microsoft Security and Compliance
  • University of Arizona, AI and Automation
Education
  • M.B.A.
    Business Administration
  • B.S.
    Computer Science
  • B.S.
    Information Technology

Our principal consultant has run enterprise-scale risk assessment programs for regulated organizations, and now brings the same method to firms of 25 to 150 people.

Questions

What firms ask about security.

Is this the same as a vCISO?

Close. A virtual chief information security officer (vCISO) is the common name for a part-time security lead. We do that work, and we also build and secure the AI and automation your firm uses, from the same pool of hours.

Do you replace our IT company or managed service provider?

No. Your IT provider keeps the help desk, devices, and day-to-day support. We set security direction, write the policies, review vendors, and check that the controls are really in place. We write our recommendations so your IT provider can act on them.

Do you monitor our systems around the clock?

No. We do not provide around-the-clock monitoring. Your IT provider or a managed detection provider stays first stop for outages and alerts. We coordinate with them and can help you choose one.

Can we start without a monthly retainer?

Yes. The Blueprint is a fixed-price, 21-day project at $4,500 for firms up to 50 employees or $7,500 for 51 to 150. It includes a risk map, security policy recommendations, and a cyber insurance questionnaire evidence pack. You keep all of it whether or not you continue.

Do you sign a business associate agreement?

Yes. We sign a business associate agreement (BAA) before touching any system with patient data. We provide ours or review yours. No patient data before a signed BAA.

Where do you work?

In person across the Phoenix metro. Remote across Arizona, Nevada, New Mexico, Colorado, Utah, and Southern California.

Security leadership

Give security an owner.

A 30-minute call. Bring your next renewal date, any questionnaire you are stuck on, and what your IT provider handles today. You leave knowing where the gaps are and what to do first.

Where
Phoenix, and remote across the Southwest