Two weeks · Fixed fee · Your report to keep
The Operations & Security Assessment
The Operations & Security Assessment is a fixed-fee, two-week review of how your business actually runs: we interview your team, follow real work through the building, review your security settings with you at the keyboard, and deliver a report that puts an annual dollar figure on every inefficiency and risk we find — ranked, with a roadmap.
Fixed fee, set before we start — no surprise invoices. Which tier fits is confirmed in the kickoff call.
- Standard$3,500
- Up to ~15 employees, one location.
- Plus$4,500
- Multiple sites, 25+ employees, or CMMC scoping bundled.
What actually happens during the two weeks?
Kickoff (30 min)
We walk the intake questionnaire together — your processes, tools, and what breaks. You don't fill out homework; we ask, you talk.
Interviews (45 min each, 3–6 people)
Your team walks us through their real day. The gold is in sentences like "I keep my own spreadsheet because…"
The walkthrough (half a day)
We follow one real order, job, or file end-to-end and record every handoff, wait, and re-entry.
Security review (with you driving)
MFA, backups, access, admin accounts — reviewed on your screen, your hands on the keyboard. We run no scanning tools and never attempt to break in. This is a look, not an attack.
The readout (60 min)
You get the report and we walk the roadmap together. You'll know your three most expensive problems by lunch.
What’s in the report?
Assessment report — contents
Every finding as a plain sentence with evidence and an annual dollar figure— "quoting data is re-typed into two systems: ~$8,400/year" — never "synergize your workflows."
An impact-vs-effort ranking: what to fix now, next, later.
Quick wins, including at least one we fix for free during the assessment week.
Do-it-yourself items. Every report includes findings you can fix without us — with instructions. If a report routed everything to our services, you shouldn't trust it. Neither would we.
A plain-English security summary — what would survive a bad week, what wouldn't.
What we did NOT look at, stated explicitly. No scans, no penetration testing, no code review — those need separate written authorization.
Is the assessment worth it if we never hire you again?
That’s the test we hold it to. The report is yours: any competent provider could execute the roadmap. The assessment is built to find annual waste worth several times its fee — and if we get two days in and it’s clear your operation is already tight, we’ll say so at the readout and tell you what we’d watch as you grow.
Frequently asked questions
Will this disrupt our work?
About four hours of your team's time across two weeks, scheduled around your production. The walkthrough follows work you were already doing.
Do we need to prepare anything?
A list of your software, two examples of your most-handled paper form, and honesty. That's it.
What if you find something bad in our security?
We tell you the same day — not in a dramatic reveal at the readout. If we find signs of an active problem, we stop and help you respond before anything else.
We have defense contracts. Does this cover CMMC?
The assessment will flag CMMC/DFARS exposure, but compliance assessment runs under different rules with different evidence standards — that's a dedicated engagement. If you already know you have DFARS clauses, skip straight to Cybersecurity & CMMC.
Who sees our information?
You. Findings, interview notes, and configurations stay in your engagement folder. The report contains no credentials and nothing your competitors could use. We'll sign your NDA.