Services

Security scoped before it starts, and a plan you keep.

We work with small and mid-sized manufacturers, retailers, financial firms, and defense contractors, roughly 10 to 250 people. Senior-led engagements, a fixed scope, and a written deliverable that is yours whether or not you hire us again.

Book a free consultation

How we work

Senior-led, fixed-scope engagements with a written deliverable.

No reseller kickbacks. No software resale margins. No “managed” contracts that quietly renew.

If you don’t get value from the assessment, you don’t pay for the next phase.

The work is the product.

Our Approach

Trust and consistency are key.

You work with a senior practitioner from kickoff through deployment. No handoffs to junior staff. No rotating analysts you’ve never met. The senior practitioner who scopes your security plan is the one who delivers it.

Resolute Security

Scope

What we take on, and what we don’t.

We work with businesses between roughly 10 and 250 employees. Engagements include assessments, remediation plans, vendor reviews, incident response coordination, and compliance prep for CMMC, PCI, and SOC 2 readiness.

We don’t take on penetration testing engagements, 24/7 SOC monitoring, or fractional CISO retainers above 10 hours per month. If you need those, we’ll point you to firms that do them well.

What we do

Four ways we work, each a fixed scope.

Named engagements, quoted before they start. Every one ends with a written report you own.

NIST CSF Readiness Assessment

A four-week, senior-led review of your security against the NIST Cybersecurity Framework, ending with ranked findings and a budgeted plan.

You keep the written report

Compliance Prep: CMMC, PCI, or SOC 2

We map your environment to the framework a customer or auditor is asking for, and turn copy-pasted questionnaire answers into ones you can defend. AI accelerates the evidence work, drafting control answers and mapping them to the framework, while a senior practitioner reviews every call and attests.

See how we use AI You keep the written report

Vendor and Third-Party Review

We find every outside company that can reach your systems, judge the risk each one carries, and tell you which doors to close first.

You keep the written report

Incident Response Coordination

If something has happened, we help you steady the response, work the problem in the right order, and document it as you go.

You keep the written report

How we price. Every engagement is fixed-scope and quoted before it begins. No hourly surprises, no retainer that renews itself. If you do not get value from the assessment, you do not pay for the next phase.

Frequently asked questions

What do you actually do?

Four named engagements: a NIST CSF readiness assessment, compliance prep for CMMC, PCI, or SOC 2, a vendor and third-party review, and incident response coordination. We work with businesses between roughly 10 and 250 people. Each engagement is fixed-scope and ends with a written report you keep.

What do you not take on?

We do not run penetration tests, staff a 24/7 monitoring center, or sell large fractional-CISO retainers. If you need those, we will point you to firms that do them well. We would rather send you to the right help than stretch past our scope.

Which compliance frameworks do you handle?

CMMC, PCI, and SOC 2 readiness. We map your environment to the controls the framework requires and get you ready for the audit or the customer questionnaire. If your obligation is a different standard, tell us on the call and we will be straight about whether we are the right fit.

Who does the work?

A senior practitioner, from the first call through the final report. You are not handed off to a junior consultant you have never met, and you are not passed between rotating analysts. The person who scopes your engagement is the person who delivers it.

Do I keep the deliverable?

Yes. The report, the inventory, and the plan are yours to keep and act on, with or without us. There is no proprietary tool you cannot take with you and no managed contract that quietly renews.

How does pricing work?

Every engagement is fixed-scope and quoted before it starts, so you know the cost up front. No surprise hours, no scope that drifts wider every month. If you do not get value from the assessment, you do not pay for the next phase.

Two minutes

How ready are you, really?

Answer three quick questions and see roughly where you stand, then take the full 10-minute readiness assessment.

Take the readiness assessment