Your business runs on trust.
Let's keep it that way — steady, not scrambling.
Steady State Cyber Advisory helps small businesses without an in-house IT team find their gaps, fix what matters most, and stop treating cybersecurity like a fire waiting to happen.
Practical security work, sized for a business without a security team.
No enterprise jargon, no scare tactics — just a clear picture of your risk and a plan to close the gaps that actually matter.
Risk & Gap Assessment
A full review of where your business is exposed — systems, data handling, and the workflows that touch client information — ranked by what to fix first.
Phishing & Awareness Training
Simulated phishing campaigns and staff training built around the scams your industry actually sees, including wire-fraud attempts.
Email Authentication Hardening
SPF, DKIM, and DMARC configured correctly, so your domain can't be spoofed to impersonate you or your staff.
Policy Development
Clear, usable policies for acceptable use, incident response, and data retention — written for a team that isn't full of security people.
vCISO-Lite Advisory
Ongoing monthly access to a security advisor — for the decisions, vendor questions, and "is this normal?" moments that come up between engagements.
Vendor & Third-Party Review
A second set of eyes on the platforms and vendors that touch your data — escrow systems, MLS integrations, and the rest of your stack.
From first call to a documented plan, in about three weeks.
Built to move around your team's schedule, not the other way around.
Discovery call
A short conversation about your systems, your team, and what keeps you up at night.
Information gathering
You send what you have — network setup, current tools, existing policies (if any).
Technical review
Email authentication, external exposure, patch posture, backups, and access controls.
Findings & report
A prioritized, plain-language report — what's urgent, what can wait.
Readout meeting
We walk through it together and agree on next steps.
What things cost.
Project work is quoted as a fixed fee once we've scoped it on a discovery call — the ranges below reflect typical engagement size. No surprise invoices.
| Service | Typical range | |
|---|---|---|
| Risk & Gap Assessment | Full review with a prioritized findings report | $3,500–$7,500 |
| Phishing Sim + Awareness Training | Setup plus an initial campaign and staff session | $2,000–$4,500 |
| Policy Development | AUP, incident response & data retention policy set | $2,000–$4,000 |
| Starter BundleMOST BOOKED | Assessment + policy development + training, bundled | $5,000–$9,000 |
| Hourly / Ad Hoc | For work outside a fixed scope | $150–$225 / hr |
vCISO-Lite Advisory
Ongoing access for policy upkeep, vendor questions, and security decisions — roughly 4–10 hours a month.
Awareness Training Administration
Keep phishing simulations and staff training running on a regular cadence, hands-off for your team.
Final pricing depends on company size, systems in scope, and timeline — confirmed in writing before any work begins.
Security advice from someone who does this for a living — not just on the side.
Steady State Cyber Advisory is run by a CISSP-certified security professional who leads cybersecurity operations for a manufacturing organization by day, with a background in intelligence analysis and enterprise information security. This isn't a side hustle learning as it goes — it's practiced judgment, made available to businesses that could never justify a full-time hire.
- CERTIFICATIONCISSP
- EDUCATIONM.S., Cybersecurity
- EDUCATIONB.A., Intelligence Studies
- BACKGROUNDIntelligence analysis & enterprise information security
- CURRENT ROLELeads cybersecurity for a manufacturing organization
- AFFILIATIONAdvisory board, university intelligence studies program
Tell us what you're worried about. We'll tell you where to start.
A discovery call is free and runs about 20 minutes — no pressure, no jargon.