Aegis - Cybersecurity & Resilience

Cybersecurity & Resilience

Most small-business losses don't start with a hack. They start with a convincing email — a changed bank account, a spoofed executive, a fake invoice. Aegis hardens your systems, trains your people, watches around the clock and rehearses the recovery.

The problem we solve

The most common way small businesses lose money to cybercrime isn't a sophisticated breach — it's a convincing email: a fake vendor invoice, a spoofed executive, a changed bank account. Aegis is built around that reality. We harden your systems and identities, put financial controls in place (callback rules, dual approval on payments), train and test your employees against the phishing they actually receive, monitor around the clock, and back everything up so a bad day is a bad day — not the end of the business.

Every engagement starts with an SMB Security Assessment ($4,500; +$1,500 per additional organization): an eight-domain audit, an architecture recommendation, and a 0–180 day roadmap. Monthly plans combine a base fee with per-user pricing so the cost tracks your actual headcount, and multi-entity families — shared offices, shared tenants, shared finances — are managed as one program. When something does happen, an incident response plan and retainer mean you know who to call and what happens next.

How it works

  1. 01

    Starts with

    A convincing email

    Fake invoice, changed bank details

  2. 02

    Checkpoint

    Hardened systems + trained people

    Phishing tested, not lectured

  3. 03

    Checkpoint

    Financial controls

    Callback rule, dual approval

  4. 04

    You end up with

    Monitored & recoverable

    Backups tested, plan rehearsed

Most small-business losses start with an email, not a hack. Every layer here is aimed at that reality.

What's included

  • Security architecture assessment & hardening
  • Financial fraud controls (callback rule, dual approval)
  • Employee security education & phishing simulations
  • 24/7 monitoring & alerting
  • Managed backup & disaster recovery
  • Incident response planning & retainers
  • Multi-entity program management for company families
  • Compliance alignment (SOC 2 / HIPAA-ready)

Ideal for

  • Multi-company families sharing offices, tenants, and finances
  • Construction & trades firms wiring money to subcontractors
  • Businesses recovering from wire fraud or phishing incidents
  • Healthcare & professional services with compliance exposure
  • Owners who need security handled without an internal IT team
  • Teams that have never had security training

À la carte

Security services you can buy on their own

Not every business needs a full monthly plan on day one. These attach to any Aegis tier, or stand alone — priced individually so you can start where the risk actually is.

  • vCISO Advisory Retainer

    Fractional security leadership: four hours a month of roadmap ownership, leadership reporting, vendor decisions, and client questionnaire support.

    $3,300/mo

  • Emergency Incident Response

    For clients without a retainer. 10-hour minimum. Retainer clients pay $250/hour with a guaranteed response window.

    $350/hr

  • Incident Response Retainer

    A guaranteed four-hour response window and a pre-agreed $250/hr incident rate instead of $350 — billed monthly whether you use it or not.

    $1,250/mo

  • Dark Web & Domain Monitoring

    Monthly watch for leaked employee credentials and newly registered lookalike domains impersonating your business.

    $250/mo

  • Vulnerability Scanning Program

    Recurring authenticated scans with tracked remediation and re-scan verification. A continuous hygiene control, not a penetration test.

    $450/mo

  • Cyber Insurance Readiness Review

    Answer your insurer’s security questionnaire accurately and close the gaps first — so a claim is not denied for a control you said you had.

    $3,500one-time

  • Security Policy Set

    Six plain-language policies people actually read: acceptable use, access control, data handling, incident response, payment verification, vendor onboarding.

    $1,800one-time

  • Incident Tabletop Exercise

    A facilitated half-day simulation with leadership — fake invoice, ransomware, or lost executive laptop — run against your actual response plan.

    $2,200one-time

  • Security Questionnaire Response

    We answer the security questionnaire your general contractor or enterprise customer sent — accurately, with evidence, in your voice.

    $750per questionnaire

  • Vendor & Third-Party Risk Review

    Assess up to five subcontractors or software vendors who can reach your data or your money — the attack path into your business you do not control.

    $1,200one-time

  • SMB Framework Readiness

    CIS Controls IG1/IG2 or NIST CSF readiness sized for a small business — the tier between the $4,500 assessment and enterprise SOC 2 work.

    $7,500one-time

Technologies

Microsoft 365 security stackEndpoint detection & response (EDR)Security awareness training platformsManaged backup & disaster recoverySIEM & alert monitoring

Ready to get started?

Let's discuss your project and find the right solution for your needs. Consultation fee credited toward any purchase.

$750 – $3,000·Monthly plans + per-user