The invoice that isn’t yours.
A fake payment request with your name on it. Proper email settings help receiving inboxes spot the impersonation.
Check your email settingsSMALL OFFICES. UTAH COUNTY.
Email and account security for small offices in Provo, Orem, and Utah County.
A real person in Provo. Plain English. Clear prices.
FIRST 10 CLIENTS 50% off. Your rate held for a year. ↗Find out what your public email settings say. No login needed.
A small check. A smarter starting point.
Practical protection.
For the tools you already use.
THE SMALL OFFICE BLIND SPOT
You don’t need an IT department to get the basics right. You need someone who knows where to look.
A fake payment request with your name on it. Proper email settings help receiving inboxes spot the impersonation.
Check your email settingsA former employee’s account. A shared password. No two-step login. Small gaps can open the door to your whole office.
Close the account gapsA backup is only useful if you can restore it. Find out whether yours works before the day you need it.
Make a plan for the what-ifsPRACTICAL HELP. PUBLISHED PRICES.
Standard starting prices are crossed out below. Launch prices are for my first 10 clients, with scope and final price agreed in writing.
Make it harder for someone else to send email in your office’s name.
Standard from $350
Launch from $175 / project
Give your email, accounts, and backups the attention they deserve.
Standard from $900
Launch from $450 / project
Someone to watch the alerts and answer “does this email look real?”
Standard from $250
Launch from $125 / month
Your written quote lists the users, domains, systems, and deliverables included. Any additional work or third-party costs are agreed before work begins.
Focused help for your office and your team.
LINUX COMPLIANCE SCANNING · POWERED BY BASELINEX
Check your Linux servers against CIS Level 1, CIS Level 2, or a custom security policy. I run the assessment, review the findings, and give you a clear list of what meets the standard and what needs attention.
Your policy, made testable. Bring your internal requirements. I can tailor a supported CIS baseline or build custom checks for passwords, SSH, logging, services, and file permissions. Custom checks can stand alone or run alongside a CIS assessment.
Two scans included: an initial assessment, then a recheck after your IT team works through the findings.
Standard from $500
Launch from $250 / project
Your IT team applies the fixes; I recheck the same servers and profile. Hands-on remediation is quoted separately. After this package, you can add monthly scans.
Choose my CIS assessmentChecks built around your requirements, on their own or alongside CIS Level 1 or 2.
Standard from $1,000
Launch from $500 / project
The recheck uses the same servers and policy. Tailored CIS profiles currently cover RHEL 8/9. More checks and hands-on remediation are quoted separately. Monthly scans are optional after this package.
Build checks for my policyPurchase a CIS Level 1, Level 2, or custom assessment first. Then I rerun your agreed configuration each month.
Standard from $200
Launch from $100 / month
Optional monthly service after a separately purchased assessment. The assessment’s 2 scans are included in its project fee. Monthly billing starts on the date we agree; new policies, extra servers, and remediation cost extra.
Add monthly scansSupported Linux systems: RHEL 8/9, Rocky Linux 8/9, and CentOS Stream 9. Available CIS profiles depend on your OS and benchmark version. I confirm the selected level, checks, access, and scan window before work starts. Larger environments are quoted individually.
First 10 clients: the half-price rates above are held for 12 months from signing. Scans assess technical configuration; they do not certify regulatory compliance. Infrastructure or hosting costs, if needed, are agreed separately.
Tenable lists Nessus Professional at $4,790/year for a software license, checked 24 September 2026. It includes broad vulnerability scanning, configuration audits, and unlimited IP assessments. Prices can change.
These packages cover a smaller, defined Linux environment and include my setup, review, and reporting. You pay for a scoped service, with optional monthly follow-up. baselineX focuses on configuration compliance; it does not replace Nessus’s broader vulnerability coverage.
BEFORE WE GET STARTED
Know what the work involves before you give anyone access to your office.
The first 10 clients who sign a service agreement receive the launch rates shown on this page. Those rates are held for 12 months from each client’s signing date, including monthly care, compliance scanning, custom policy work, and projects agreed during that period. Your quote confirms the work included, your fee, and the start and end dates of your offer.
The discount is available whether or not you leave a testimonial. There is no long-term contract required to keep the rate during your offer period.
The service cards list the work included in each type of engagement. The final quote depends on your staff, email domains, providers, and existing setup. Before work starts, you receive an exact scope, price, and schedule in writing.
The rollout is designed to keep legitimate mail flowing. I identify your sending services, test changes, and tighten the email policy in stages. We agree on a rollback plan before changes are made.
The free check only uses public records and needs no login. Paid work may require access to domain settings, Microsoft 365 or Google Workspace, and backup tools. Compliance scans need approved access to the Linux servers and scanner setup, agreed with you or your IT provider. The scope names the access needed. Your office keeps ownership of its accounts.
CIS Level 1 provides a practical security baseline. Level 2 adds stricter requirements for systems that need greater protection and may involve operational tradeoffs. Custom checks test the specific rules your organization has chosen. I help you select an appropriate profile for your systems and the evidence you need.
You can choose a CIS Level 1 or Level 2 assessment, custom checks on their own, or a combination. Your report identifies the benchmark, level, and any policy changes so you know exactly what was assessed.
Every CIS Level 1, Level 2, or custom assessment includes an initial scan and one recheck. After the first scan, you receive prioritized findings and an Excel report to share with your IT team. They make the fixes, then I scan the same servers against the same agreed profile or custom checks within 30 days of the report and show what changed.
Both scans are covered by the project fee. Hands-on remediation is separate, and you do not need a monthly subscription to use the included recheck.
Yes. First purchase a CIS Level 1, Level 2, or custom assessment so we can set up and agree on your scan configuration. After that, you can add the optional monthly service. I rerun that configuration once a month on the same covered servers and send your IT team an updated report.
Monthly scanning is billed separately from the initial package, starting on an agreed date. New policies, additional servers, and hands-on remediation receive a separate quote.
Yes. Bring your technical requirements and I can turn them into repeatable checks for settings such as SSH access, required services, password rules, logging, and file permissions. These can run independently or alongside CIS Level 1 or Level 2. The custom package includes up to 5 agreed automated checks; larger policies are quoted separately.
I can also tailor supported CIS settings to your policy. Tailored profiles currently cover RHEL 8/9. We agree on which requirements can be automated and which need a person to review evidence, and your report documents differences from the original benchmark.
I explain the finding and quote the additional work before making changes outside the agreed scope. Software subscriptions, new hardware, and migrations are separate from the listed service fees.
We agree on the users and systems covered, when alerts are reviewed, and response expectations. You receive a monthly summary, with a backup restore test every quarter. New projects receive a separate quote.
LOCAL OFFICES. IMPORTANT WORK.
Client records. Closing funds. A reputation you’ve spent years building. Your office has plenty worth protecting.
Provo · Orem · Lehi · American Fork · Springville
NO GUESSWORK. NO RUNAROUND.
You know what’s happening, what it costs, and what comes next. Every step of the way.
I look at your public email settings and give you a one-page finding. No login, access, or cost.
You get a written scope: exactly what I’ll change, what I’ll leave alone, and the price.
Emergency admin access and a rollback plan come first. Then I work through the agreed fixes.
A short report covers what was wrong, what’s fixed, and what’s left. Written for you.
YOUR LOCAL SECURITY PERSON
Marc Provo, Utah
One office at a time.
One person you can reach.
HI, I’M MARC.
I’m a cybersecurity student in Provo. I help small offices secure the email and accounts they rely on every day. When you get in touch, you talk to me.
I fix the settings, document the work, and explain what it means for your business. For policies and compliance, I prepare the paperwork for your attorney or accountant to review.
CLIENT TESTIMONIALS
After we’ve worked together, I’d love an honest testimonial about your experience. With your permission, I’ll share your words here so other small offices can learn about my work.
Sharing a testimonial is completely optional and does not affect your launch discount.
Email Marc a testimonialONE SMALL STEP TO A SAFER OFFICE
Send me your office’s domain. I’ll reply with a one-page finding within two business days.