Sentry CTO

About

We were selling cybersecurity. We were not really doing it.

That realisation is why this company works the way it does now, and it is the most useful thing we can tell you about ourselves.

Sentry CTO started in 2017 in Prescott. Niles Benghauser grew up here, earned his CompTIA A+ certification at fifteen and Network+ shortly after, worked for other local IT providers, and eventually concluded he could do the customer service part considerably better.

For the first several years we did what most managed IT providers do. Support, patching, antivirus, backups. When clients asked whether we did cybersecurity, we said yes, and we believed it.

The uncomfortable part

At some point that answer stopped feeling true.

Looking honestly at what we were delivering, it was managed IT with endpoint protection on top. That is a genuinely useful service. It is not cybersecurity, and the gap between the two was widening every year as attacks got better organised.

Nobody had been misled deliberately. That almost made it worse. We had been describing our service the way the whole industry describes it, and the whole industry was describing it inaccurately.

So we spent about a year fixing it. Training, joining a program built around selling and delivering layered security properly, rebuilding what we offered from the ground up.

We eventually parted ways with that program. We disagreed with how it was run, and we wanted an assessment methodology that was genuinely ours rather than a template. But it taught us the thing we were missing, which was not the technology. It was how to explain risk to a business owner in terms that let them make an actual decision.

Where that leaves us

We now sell one thing we can defend completely: an examination of what is actually happening in your business, followed by a plan, followed, if it makes sense for both of us, by running your technology properly.

We are not the cheapest option in Arizona, and we lose deals on price. We have made our peace with that. What we will not do is win one by describing something as cybersecurity when it is not, because we have already been on that side of the conversation and we did not like it.

What we actually hold to

Five values, and where they have cost us.

Values are only worth publishing if they have been expensive at least once.

Uncompromising integrity

The reason this company exists in its current form. When we realised we were selling something we could not honestly call cybersecurity, we changed what we sold rather than how we described it.

During one client's onboarding they had a full outage after hours. It was not caused by us. We did not charge for the work.

Attention to detail

Most of what we find in assessments is not exotic. It is an account nobody closed, a backup nobody tested, a setting nobody checked. Detail is the whole job.

Continuous innovation and optimisation

The stack we deployed three years ago is not the stack we deploy now, because the attacks changed. Reviewing that honestly means occasionally concluding we have been doing something the wrong way.

Embrace change

This one is aimed at us before it is aimed at clients. Rebuilding our own service around real security meant giving up work we knew how to sell for work we had to learn.

A positive place to work

Small teams are fragile. We hire ahead of need rather than after it, and we keep the work queue short deliberately. A backlog is a symptom, not a badge.

How we operate

Plainly stated.

A few things worth knowing before you talk to us, since they come up eventually anyway.

Security monitoring is 24/7. The help desk is not.
Monitoring and response run continuously, every day. Help desk hours are 8am to 5pm, Monday to Friday. Urgent issues outside those hours reach someone.
We keep the queue short on purpose
Unlimited support with flat-rate billing means we are paid to eliminate problems rather than to process tickets. A short queue is the model working.
Urgent means urgent
Genuinely urgent issues get worked immediately rather than queued behind whatever arrived first. We would rather earn that reputation than publish a number we have to defend on a bad day.
We hire before we need to
Adding people after the strain shows means clients feel it first. We would rather carry the cost early.
We will tell you when to keep your current provider
Sometimes the right answer is that your existing arrangement is fine for one part and inadequate for another. That is a normal outcome of the first call.

The next step

The best way to judge us is to watch us work.

That is genuinely most of what the 30-day assessment is for. Thirty days is long enough to see how we communicate and whether you want us around, and long enough to decide you do not.

No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.