Skip to main content

SERVICES

One firm, led by incident response.

Explore the practice that fits your needs, then choose an assessment, response engagement, retainer, or training program.

THE PRACTICES

01 · RESPOND

See practice

Incident response & digital forensics

Active incident response, forensic investigations, and threat hunting, with retainers, IR plans, and tabletop exercises to prepare before an incident.

IR-A · RETAINERIR-B · REACTIVE IRIR-C · DIGITAL FORENSICSIR-D · TABLETOPSIR-E · IR PLANIR-F · THREAT HUNTING

Active incident? Call(469) 489-4601

02 · ASSESS

See practice

Penetration testing & security assessment

Authorized penetration testing and validated vulnerability assessments across external and internal networks, Active Directory, and web applications. Scope, rules of engagement, and authorization are defined in writing before testing begins, and post-remediation retesting is available to validate closure.

AST-A · EXTERNAL NETWORKAST-B · INTERNAL & ADAST-C · WEB APPLICATIONAST-D · VULNERABILITY ASSESSMENT

03 · ADVISORY

See practice

Security leadership & risk advisory

Fractional CISO leadership, security strategy roadmaps, governance and risk advisory, and cyber insurance readiness reviews for organizations operating without dedicated security leadership.

ADV-A · vCISO RETAINERADV-B · STRATEGY & ROADMAPADV-C · GOVERNANCE & RISKADV-D · CYBER INSURANCE

04 · MODERN

See practice

Microsoft cloud & modern security

Assessment-led reviews of cloud security posture for organizations whose business runs on Microsoft 365, Azure, and cloud identity. Findings come with concrete remediation steps; implementation is scoped separately or handed back to your IT or MSP.

CLD-A · POSTURE ASSESSMENTCLD-B · M365 & AZURECLD-C · IDENTITY & ACCESSCLD-D · CONTROL ALIGNMENTCLD-E · DETECTION & RESPONSE

HOW CLIENTS ENGAGE STRACE

Six engagement models.

Fixed-scope assessment

Written report, clear deliverables, defined timeline. Used for M365 hardening, NIST-aligned security reviews, cyber insurance readiness, and risk assessments. Typical duration: 2-4 weeks.

Active response engagement

Live engagement with an incident underway. Used for ransomware, BEC, insider threat, cloud compromise, and data exfiltration. Scope defined at incident confirmation.

Remediation project

Hands-on execution of findings from a prior assessment. Used for M365 hardening implementation, security control remediation, and policy development. Scoped per-control or per-deliverable.

Advisory retainer

Standing monthly relationship for organizations without an in-house CISO. Used for executive advisory, ongoing risk reporting, and strategic security input.

Training program

Productized educational engagement. Used for executive briefings, phishing simulation programs, role-based curricula, and small business cyber programs. Delivered in person or remote.

Quarterly review

Ongoing oversight cadence. Used for cloud security maintenance, configuration drift detection, and posture upkeep. Subscription-style with quarterly deliverables.

HOW PRICING WORKS

We quote after a consultation to establish the environment, urgency, deliverables, and timeline. Advisory, assessment, training, and hardening projects use fixed-scope proposals where appropriate; active incidents require an agreed scope-and-rate structure. Selected offerings have public starting prices.

START THE CONVERSATION

Tell us what you're facing. We'll tell you which practice fits.