Sentry CTO

Sentry Inspect · 30 days

Stop guessing what your risk actually is.

Thirty days examining your people, processes, and technology across nine areas, then an hour with your leadership walking through exactly what we found and what it would cost you.

The report is yours whether or not you ever hire us. Take it to another provider, hand it to your insurer, or work the list yourself.

Wondering what comes after? See what managed IT services and cybersecurity services actually include.

Why this is a paid engagement.

The most common objection we hear is some version of “so I have to pay just to get a quote?” It is a fair thing to ask, and it deserves a straight answer.

You are not paying for a quote. You are paying for thirty days of skilled work that produces a documented, specific picture of where your business is exposed, the same document we would use to design a plan, delivered to you regardless of what you decide afterwards.

We could give you a number without doing any of that. Every provider who quotes you in a single meeting is doing exactly that, and what they are really quoting is a standard package sized to your headcount. It might be close. You would have no way to tell, because neither would they.

We do not quote managed services to organizations we have not examined. Not as a sales technique, because the number would be a guess, and you deserve to know how we arrived at it.

The nine areas

What we actually examine.

Not just a vulnerability scan. Scanning finds technical flaws; it cannot tell you that the person who approves wire transfers has never been trained to spot a fraudulent one.

01

People & Access

Who can get into what, and what happens when they leave.

02

Data Protection

Whether your information is actually recoverable and actually private.

03

Business Continuity

How long you would be down, and whether you have ever tested that.

04

Devices

The computers your work happens on, and what they are allowed to run.

05

Network

What is between your business and the open internet.

06

Applications

The software and cloud services your business actually depends on.

07

Policies & Response

What is written down, and who does what when something happens.

08

Management Oversight

Whether leadership can see the truth about its own risk.

09

Physical Security

Who can walk up and touch your equipment.

Want a preview? Our free self-assessment walks the same nine areas in about three minutes. It is a much thinner version of this, but it will show you the shape of the thing.

Take the free version

The thirty days

What actually happens.

  1. Before we start

    A short call, then a scope

    We confirm how many people actually touch your systems, which is almost always more than the payroll number, and agree the price in writing before anything begins.

  2. Week 1

    Technical scanning begins

    We deploy scanning across your network, endpoints, cloud applications, and identity systems. This runs quietly in the background for the full engagement rather than as a one-off snapshot, because a single scan misses anything intermittent.

  3. Weeks 1–3

    We talk to your people

    Interviews with leadership and with staff, including whoever pays invoices, whoever onboards new hires, and whoever people actually ask when something breaks. This is where we learn how the business really operates, which is rarely how the documentation says it does.

  4. Weeks 3–4

    Analysis

    Scan results get cross-checked against what people told us and against your existing policies. Contradictions between those three are usually the most valuable thing we find.

  5. Day 30

    The briefing

    About an hour with your leadership. We walk through what we found, what it would cost you if it were exploited, and what we would do about it in the first 30, 90, and 180 days. You keep the written report either way.

What you get

An honest picture of how your business actually runs.

Most owners have never seen their own operation described from the outside: what depends on whom, what would stop if a person left, where money and data move, and which assumptions nobody has ever checked. That picture is the real deliverable. The documents are how you keep it.

A written assessment report
Observations, findings, and recommendations across all nine areas, each rated by severity and how often we saw it. Written to be read by a business owner, with the technical detail in appendices for whoever needs it.
A 30 / 90 / 180-day action plan
Sequenced by what reduces the most risk soonest. The first thirty days target the highest-severity items; ninety builds the framework; one hundred and eighty covers policy, training, and the management routines that keep it from drifting back.
An executive briefing
About an hour, presented to whoever needs to hear it, owners, partners, a board, a leadership team. Most of our clients tell us this is the first time everyone in the room had the same picture of the company's risk.

Price

$1,500

for 10 users or fewer

$150

per user above 10

A user is anyone who touches company systems, employees, contractors, volunteers, seasonal staff. We agree the count and the price in writing before we begin, so there is no adjustment later.

“Sentry CTO is an excellent company for Cyber Security. Niles is by far the most knowledgeable expert in this industry. I have used their services and they have helped me to discover weaknesses in my current CRM. They have also done a business assessment which revealed that passwords and accesses were not where they should have been. I highly recommend this company.”
Jeff Brandlin

Before you commit to anything

Fifteen minutes first.

We will ask what prompted you to look, roughly how many people you have, and what is already in place. If an assessment does not make sense for you right now, we will say so and tell you what we would do instead.

No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.