Security posture review
A plain-English view of the risks most likely to disrupt your business, plus an affordable, sequenced plan for what to fix first. This is the usual starting point when nobody has a current picture.
Cybersecurity for small businesses that need clarity
When a customer, insurer, or new contract starts asking security questions, I help you answer them - then fix the few things that would hurt most if they failed.
Where I can help
Focused support for owners and lean teams who need a trusted security partner - without hiring a full-time security department or buying tools they will not use.
A plain-English view of the risks most likely to disrupt your business, plus an affordable, sequenced plan for what to fix first. This is the usual starting point when nobody has a current picture.
Help answering the questions your insurer, customers, and partners actually ask - MFA, backups, incident contacts, who owns security - with honest answers and a short list of gaps to close before you submit.
Practical improvements to MFA, Microsoft 365 or Google Workspace, employee access, and company devices. These are the controls that stop the account takeovers and email fraud most small businesses actually face.
Clear, right-sized security policies plus an incident response plan with key contacts, escalation steps, and recovery decisions your team can use under pressure.
Review how your current practices align to NIST CSF and, where relevant, HIPAA Security Rule or SOC 2 expectations - then receive a practical gap plan. I prepare you for an audit; I do not issue the certificate. That comes from an independent auditor.
Focused, agreed-upon testing of the systems that matter most, with clear findings and a prioritized report that explains what to address and why. Every engagement runs under written authorization and an agreed scope - see the testing terms.
Ongoing guidance for owners and operations leaders: prioritize investments, make sense of vendor advice, report on progress, and choose the next right security step. The right buy once someone needs a named owner, not a one-off report.
Who this is for
Size is not the trigger. Accountability is. If a customer, insurer, or new contract is waiting on a security answer - or nobody owns those decisions - this work is for you.
Carriers now ask for proof of MFA, tested backups, and a named incident contact - not a yes on a form.
A buyer or partner sent a security packet and the deal stalls until someone can answer it honestly.
Someone clicked, a mailbox was taken over, or you can see how easily that could happen.
Security decisions keep landing on whoever is least busy, and vendor pitches are impossible to judge.
A two-minute needs check
Five short questions. You get a plain-English picture of the gaps, what you can do yourself this week, and whether I am the right person to help - or not. Nothing is sent unless you choose to send it.
Who you would be working with
I’m David. I work from the Bay Area. I started CISO Peak because most small businesses do not need a security department. They need one person who will say what matters, what can wait, and what the customer or insurer is actually asking.
You work with me. I sit on your side of the table: I read the questionnaire, I talk to whoever runs your IT, and I leave you with owners and a plan your team can use without me in the room. I do not sell products, I do not take referral fees, and I will not pretend a certificate comes from me.
Week to week that looks like a focused conversation, a written scope, and artifacts with names on them. If the honest next step is to spend nothing yet, I will say so.
David Founder, CISO Peak ยท Bay Area
The engagement model
"Good security makes the path forward clearer."
Define what matters, where the exposure sits, and who needs to act.
Review the facts, test assumptions, and separate urgent risks from background noise.
Deliver actions, owners, and working artifacts your team can carry forward.
How this is different
Your IT provider keeps the lights on. Tool vendors sell licenses. A full-time CISO costs more than most small businesses spend on all of IT. I set priorities, translate the outside questions, and leave you with owners and a plan.
Keeps systems running and sells hours or tools. Essential - and a poor fit as the person who independently decides what security work is worth buying.
I work with them, not instead of them.
Licenses do not answer a customer questionnaire or tell you what to fix first. Most small businesses already own more software than they use.
I sell no products and take no vendor commissions.
The right hire once security is a daily executive job. Loaded cost in the US typically runs $250,000 to $400,000 a year, plus a long search.
Most small businesses need hours a month, not a seat.
One accountable person for the security answer: a written scope, a sequenced plan, and artifacts your team can use. Project work or a monthly retainer.
Starting points from $4,500, or $3,500 a month.
How engagements run
Three shapes the work usually takes, and what you are left holding at the end of each. These describe the process rather than any particular client - engagement details stay confidential unless a client asks to be named.
Typical trigger A customer, insurer, or new contract starts asking security questions nobody in the business can answer.
How it runs Two to three weeks. Conversations with whoever runs your IT, a look at the systems the business genuinely cannot operate without, and an honest assessment of what would hurt most if it failed.
What you end up with A short risk picture in plain English, and a sequenced plan that says what to fix first, what it will take, and what can safely wait.
Typical trigger A deal is held up pending a security review, HIPAA obligations arrive with a new client, or someone upstream wants a framework answer.
How it runs Six to ten weeks. A gap assessment against the framework that actually applies to you, then policies and an incident response plan written to match how your team really works.
What you end up with A gap register with named owners and dates, right-sized policies, an incident response plan your team has walked through, and a brief you can hand to whoever asked.
Typical trigger Security decisions keep landing on someone whose actual job is something else, and vendor pitches are impossible to judge from the inside.
How it runs Standing monthly time. Owning the roadmap, reviewing tools and vendor claims before you buy, and being the number to call when something goes wrong.
What you end up with A roadmap that gets revisited each quarter, progress reporting an owner or board can actually read, and one accountable person for the security answer.
Engagement shapes
Most work falls into one of three shapes. The figures below are starting points for a typical small business; every engagement is quoted in writing after the intro call, so you know the cost and the deliverables before any work begins. If you are a very small team and nobody is asking for a review yet, start with a posture review rather than a monthly retainer.
From $4,500
From $12,000
From $3,500/mo
A better consulting experience
Clear expectations before the work starts, plain language while it is underway, and useful artifacts when it is done.
Ask something elseOwners, operations leaders, and lean technology teams at small and growing businesses - typically from about ten people up to a couple of hundred - that need a named security owner without building a full in-house security function. You work with me, David, not a bench of juniors.
We start with a focused conversation to understand the decision, the systems involved, and the outcome you need. You receive a clear scope before any work begins.
No. I work alongside your existing IT provider or internal team, bringing independent security judgment, helping set priorities, and translating recommendations into practical next steps.
Depending on the engagement, that may include a prioritized roadmap, named owners, working playbooks, technical findings, or a leadership-ready brief. Deliverables are built to be used, not filed away.
Yes. I can assess readiness against frameworks such as NIST CSF and, where relevant, HIPAA Security Rule or SOC 2 expectations, then turn the gaps into a realistic improvement plan. I do not issue SOC 2 reports or HIPAA attestations - those come from independent auditors. If you are not ready to sit an audit, I will say so.
Focused reviews may take a few weeks; broader readiness or leadership work may run longer. Timing is agreed up front and shaped around your team’s capacity to participate and act.
Under a mutual NDA, with the least access needed for the work, and with any testing performed only under written authorization and an agreed scope. Details are in the engagement and testing terms and the privacy notice.
If a customer, insurer, or partner is already asking security questions, yes - start with a posture review. If nobody is asking yet and you mainly need the basics (MFA on email, tested backups, a short incident contact list), your IT provider can often do that work, and CISA’s small-business guidance is a good free starting point. A monthly retainer is usually the right buy once someone needs a named owner over time.
Yes. I help you answer the application honestly, gather the proof carriers now expect - MFA on email and admin access, backup restore tests, an incident contact - and fix the gaps that would get a quote declined or a claim denied. I cannot promise a cheaper premium or that a carrier will bind coverage.
Tools do not decide what matters, answer a customer, or tell your insurer who owns security. I sell no products and take no commissions. If a tool is the right next step, I will say so and help you judge the pitch. If it is not, I will say that too.
Me. CISO Peak is a one-person practice based in the Bay Area. The person you speak to on the intro call is the person who scopes the work, does the work, and signs the deliverables. If you need a 24/7 bench or a named backup while I am away, say so early - that is a reason to choose a larger firm instead.
A two-minute set of questions about what is in front of you, who owns security, and which basics are already true. You get a picture of the gaps, what you can do yourself, and whether I am the right person to help. It is not a scan or an audit. Answers stay in your browser unless you choose to send the picture.
Start with a focused conversation
Share a little context and I will get back to you with the right next step. If you would rather start with the gaps, take the two-minute needs check first.
Prefer email? Write to [email protected].