Small OfficeSecurity. Free email check

SMALL OFFICES. UTAH COUNTY.

A little office.
A lot worth
protecting.

Email and account security for small offices in Provo, Orem, and Utah County.

A real person in Provo. Plain English. Clear prices.

FIRST 10 CLIENTS 50% off. Your rate held for a year.
YOUR FIRST LINE OF DEFENSE
FREE CHECK

Could someone send
email as your office?

Find out what your public email settings say. No login needed.

Just looking?

SPF DMARC Mail provider

Public records only. No account access.
Nothing changed. Nothing stored by this site.

A small check. A smarter starting point.

Practical protection.
For the tools you already use.

Microsoft 365 Google Workspace2–25 people.
Your size of office.

THE SMALL OFFICE BLIND SPOT

You’re busy running a business.
That’s what they count on.

You don’t need an IT department to get the basics right. You need someone who knows where to look.

01 / EMAIL

The invoice that isn’t yours.

A fake payment request with your name on it. Proper email settings help receiving inboxes spot the impersonation.

Check your email settings
02 / ACCOUNTS

The login that still works.

A former employee’s account. A shared password. No two-step login. Small gaps can open the door to your whole office.

Close the account gaps
03 / RECOVERY

The backup nobody’s tested.

A backup is only useful if you can restore it. Find out whether yours works before the day you need it.

Make a plan for the what-ifs

PRACTICAL HELP. PUBLISHED PRICES.

Start with what you need.
Build from there.

Standard starting prices are crossed out below. Launch prices are for my first 10 clients, with scope and final price agreed in writing.

Linux compliance checks: CIS Level 1, Level 2, or your own policies
01THE FOUNDATION

Email lockdown

Make it harder for someone else to send email in your office’s name.

Standard from $350

Launch from $175 / project

  • SPF, DKIM, and DMARC setup
  • Careful rollout over 4–6 weeks
  • Lookalike domain check
  • One-page findings report
Scope
Quoted by email domain and sending setup.
Timing
Staged rollout over 4–6 weeks.
Extra work
Additional domains or sending tools are scoped separately.
Let’s secure your email
03KEEP IT THAT WAY

Monthly care

Someone to watch the alerts and answer “does this email look real?”

Standard from $250

Launch from $125 / month

  • Email and sign-in alert review
  • Staff account changes
  • Quarterly backup restore tests
  • Help with suspicious emails
  • A short monthly summary
Scope
Agreed users, domains, alert reviews, and routine account changes.
Cadence
Monthly summary and a backup restore test every quarter.
Extra work
New setup projects are quoted separately. Review and response times are agreed in writing.
Talk about ongoing care

Your written quote lists the users, domains, systems, and deliverables included. Any additional work or third-party costs are agreed before work begins.

A little more specific?

Focused help for your office and your team.

LINUX COMPLIANCE SCANNING · POWERED BY BASELINEX

CIS Level 1. Level 2.
Or your own rules.

Check your Linux servers against CIS Level 1, CIS Level 2, or a custom security policy. I run the assessment, review the findings, and give you a clear list of what meets the standard and what needs attention.

Your policy, made testable. Bring your internal requirements. I can tailor a supported CIS baseline or build custom checks for passwords, SSH, logging, services, and file permissions. Custom checks can stand alone or run alongside a CIS assessment.

CIS Level 1CIS Level 2Custom policy checksFindings & Excel reportsRepeat scans & history
KNOW WHERE YOU STAND

CIS Level 1 or 2 assessment

Two scans included: an initial assessment, then a recheck after your IT team works through the findings.

Standard from $500

Launch from $250 / project

  • Up to 5 Linux servers on one supported OS version
  • Your choice of one CIS Level 1 or Level 2 Server profile
  • Scanner setup and your first scan
  • Prioritized findings and an Excel report for your IT team
  • A second scan within 30 days of the report to check their fixes

Your IT team applies the fixes; I recheck the same servers and profile. Hands-on remediation is quoted separately. After this package, you can add monthly scans.

Choose my CIS assessment
BUILT AROUND YOUR RULES

Custom policy assessment

Checks built around your requirements, on their own or alongside CIS Level 1 or 2.

Standard from $1,000

Launch from $500 / project

  • Up to 5 Linux servers on one supported OS version
  • Up to 5 custom automated checks, developed and validated against your policy
  • Option to include one CIS Level 1 or Level 2 Server profile
  • Scanner setup and 2 scans: an initial assessment and one recheck
  • Prioritized findings, policy differences, exceptions, and an Excel report for your IT team
  • Recheck your IT team’s fixes within 30 days of the report

The recheck uses the same servers and policy. Tailored CIS profiles currently cover RHEL 8/9. More checks and hands-on remediation are quoted separately. Monthly scans are optional after this package.

Build checks for my policy
ADD ON AFTER YOUR ASSESSMENT

Monthly compliance checks

Purchase a CIS Level 1, Level 2, or custom assessment first. Then I rerun your agreed configuration each month.

Standard from $200

Launch from $100 / month

  • Up to 5 servers from your initial assessment
  • One scheduled scan per month
  • The same agreed CIS Level 1, Level 2, or custom checks
  • Reviewed findings and changes for your IT team
  • Scan history and an updated Excel report

Optional monthly service after a separately purchased assessment. The assessment’s 2 scans are included in its project fee. Monthly billing starts on the date we agree; new policies, extra servers, and remediation cost extra.

Add monthly scans

Supported Linux systems: RHEL 8/9, Rocky Linux 8/9, and CentOS Stream 9. Available CIS profiles depend on your OS and benchmark version. I confirm the selected level, checks, access, and scan window before work starts. Larger environments are quoted individually.

First 10 clients: the half-price rates above are held for 12 months from signing. Scans assess technical configuration; they do not certify regulatory compliance. Infrastructure or hosting costs, if needed, are agreed separately.

How does this compare with buying Nessus?

Tenable lists Nessus Professional at $4,790/year for a software license, checked 24 September 2026. It includes broad vulnerability scanning, configuration audits, and unlimited IP assessments. Prices can change.

These packages cover a smaller, defined Linux environment and include my setup, review, and reporting. You pay for a scoped service, with optional monthly follow-up. baselineX focuses on configuration compliance; it does not replace Nessus’s broader vulnerability coverage.

BEFORE WE GET STARTED

Good questions.
Straight answers.

Know what the work involves before you give anyone access to your office.

How does the first 10 clients offer work?

The first 10 clients who sign a service agreement receive the launch rates shown on this page. Those rates are held for 12 months from each client’s signing date, including monthly care, compliance scanning, custom policy work, and projects agreed during that period. Your quote confirms the work included, your fee, and the start and end dates of your offer.

The discount is available whether or not you leave a testimonial. There is no long-term contract required to keep the rate during your offer period.

What does the starting price cover?

The service cards list the work included in each type of engagement. The final quote depends on your staff, email domains, providers, and existing setup. Before work starts, you receive an exact scope, price, and schedule in writing.

Will my email keep working during the changes?

The rollout is designed to keep legitimate mail flowing. I identify your sending services, test changes, and tighten the email policy in stages. We agree on a rollback plan before changes are made.

What access will you need?

The free check only uses public records and needs no login. Paid work may require access to domain settings, Microsoft 365 or Google Workspace, and backup tools. Compliance scans need approved access to the Linux servers and scanner setup, agreed with you or your IT provider. The scope names the access needed. Your office keeps ownership of its accounts.

Should we choose CIS Level 1, Level 2, or custom checks?

CIS Level 1 provides a practical security baseline. Level 2 adds stricter requirements for systems that need greater protection and may involve operational tradeoffs. Custom checks test the specific rules your organization has chosen. I help you select an appropriate profile for your systems and the evidence you need.

You can choose a CIS Level 1 or Level 2 assessment, custom checks on their own, or a combination. Your report identifies the benchmark, level, and any policy changes so you know exactly what was assessed.

What are the two scans included in an assessment?

Every CIS Level 1, Level 2, or custom assessment includes an initial scan and one recheck. After the first scan, you receive prioritized findings and an Excel report to share with your IT team. They make the fixes, then I scan the same servers against the same agreed profile or custom checks within 30 days of the report and show what changed.

Both scans are covered by the project fee. Hands-on remediation is separate, and you do not need a monthly subscription to use the included recheck.

Do we need an assessment before monthly scans?

Yes. First purchase a CIS Level 1, Level 2, or custom assessment so we can set up and agree on your scan configuration. After that, you can add the optional monthly service. I rerun that configuration once a month on the same covered servers and send your IT team an updated report.

Monthly scanning is billed separately from the initial package, starting on an agreed date. New policies, additional servers, and hands-on remediation receive a separate quote.

Can you scan against our own security policy?

Yes. Bring your technical requirements and I can turn them into repeatable checks for settings such as SSH access, required services, password rules, logging, and file permissions. These can run independently or alongside CIS Level 1 or Level 2. The custom package includes up to 5 agreed automated checks; larger policies are quoted separately.

I can also tailor supported CIS settings to your policy. Tailored profiles currently cover RHEL 8/9. We agree on which requirements can be automated and which need a person to review evidence, and your report documents differences from the original benchmark.

What happens if you find more work?

I explain the finding and quote the additional work before making changes outside the agreed scope. Software subscriptions, new hardware, and migrations are separate from the listed service fees.

How does monthly care work?

We agree on the users and systems covered, when alerts are reviewed, and response expectations. You receive a monthly summary, with a backup restore test every quarter. New projects receive a separate quote.

LOCAL OFFICES. IMPORTANT WORK.

Small doesn’t mean
low stakes.

Client records. Closing funds. A reputation you’ve spent years building. Your office has plenty worth protecting.

Provo · Orem · Lehi · American Fork · Springville

NO GUESSWORK. NO RUNAROUND.

A clear plan.
From first check to final report.

You know what’s happening, what it costs, and what comes next. Every step of the way.

  1. Start with a free check.

    I look at your public email settings and give you a one-page finding. No login, access, or cost.

  2. Agree on the work.

    You get a written scope: exactly what I’ll change, what I’ll leave alone, and the price.

  3. Make careful changes.

    Emergency admin access and a rollback plan come first. Then I work through the agreed fixes.

  4. Understand the result.

    A short report covers what was wrong, what’s fixed, and what’s left. Written for you.

YOUR LOCAL SECURITY PERSON

Marc Provo, Utah

One office at a time.
One person you can reach.

HI, I’M MARC.

Less tech talk.
More peace of mind.

I’m a cybersecurity student in Provo. I help small offices secure the email and accounts they rely on every day. When you get in touch, you talk to me.

I fix the settings, document the work, and explain what it means for your business. For policies and compliance, I prepare the paperwork for your attorney or accountant to review.

No software to sell you No long-term contract Your accounts stay yours
Let’s talk about your office

CLIENT TESTIMONIALS

A few words from you
can go a long way.

After we’ve worked together, I’d love an honest testimonial about your experience. With your permission, I’ll share your words here so other small offices can learn about my work.

Sharing a testimonial is completely optional and does not affect your launch discount.

Email Marc a testimonial

ONE SMALL STEP TO A SAFER OFFICE

Let’s take a look.
Start with your email.

Send me your office’s domain. I’ll reply with a one-page finding within two business days.