No canned checklist, and no 200-page scanner dump. You choose what gets tested: endpoints, network, cloud, identity, email, and detection coverage. I assess it hands-on and hand you a prioritized plan your team or IT provider can act on right away.
Start with a single module or combine them into a full posture review. Add modules to your scope below and they'll carry into the request form, so we start the scoping call already knowing what you need.
Authenticated scans across workstations and servers to find missing patches, vulnerable software, and risky configurations, then validated by hand so you're not chasing false positives.
See your business the way an attacker does from the internet: exposed services, forgotten hosts, and remote-access entry points.
A review of your firewall rules, segmentation, and wireless setup to find the paths an intruder would use to move from one machine to everything.
Read-only review of your cloud tenants against security baselines, focused on the misconfigurations that actually lead to breaches.
Most breaches start with a compromised account. This module checks who has access to what, and how well those accounts are protected.
Business email compromise is one of the costliest attacks on SMBs. This module looks at how easily your domain can be spoofed and how well phishing gets filtered.
Having EDR isn't the same as being protected by it. I check deployment coverage, policy strength, and whether it would actually catch a modern attack.
If something happened last month, could you prove it? This module maps what you log, how long you keep it, and the blind spots that would stall an investigation.
A focused threat-hunt sweep that answers a simple question: is anyone already in here? It's well suited to post-acquisition, post-incident, or "something feels off" situations.
A clear, low-friction process designed to work around your operations. You'll know exactly what's being tested, when, and why.
A 30-minute call to understand your business, environment, and concerns. You get a fixed-fee proposal and written rules of engagement.
Scans and configuration reviews run on a schedule you approve, using read-only access wherever possible and without disrupting production.
Every finding is validated by hand and ranked by real-world risk to your business, not just a raw CVSS score.
A walkthrough of the results with leadership and IT, plus a prioritized remediation plan, with quick wins first.
Written for two audiences: the people who sign off on the budget and the people who make the fixes.
Plain-English risk picture for owners and leadership: what's exposed, what it could cost, and what to fix first.
Each finding with evidence, affected assets, severity, and step-by-step remediation guidance for IT or your MSP.
A 30 / 60 / 90-day plan that sequences fixes by risk reduction and effort, so the highest-impact work happens first.
A live review session to answer questions, plus support during remediation if you want it.
analyst@sentinelforge:~$ ./report --summary --client acme-co [*] scope: VULN, EXT, CLOUD, IAM, MAIL [*] assets reviewed: 47 endpoints · 1 M365 tenant [*] status: validated & ranked [CRITICAL] RDP exposed to internet on 1 host [CRITICAL] 6 accounts without MFA (2 admins) [HIGH] Legacy authentication still enabled [HIGH] 11 endpoints missing critical patches [MEDIUM] DMARC policy set to p=none [MEDIUM] Guest Wi-Fi not segmented [+] quick wins identified: 4 [+] roadmap generated: 30/60/90 // illustrative example — not real client data
If you rely on a small IT staff or an outside MSP and need an independent, expert look at your security, this is designed for you.
Still unsure? Call or send a note. You'll get a direct answer, not a sales sequence.
No. Scans are scheduled with you, throttled for production networks, and nothing in your environment is changed without your approval. Cloud and configuration reviews use read-only access wherever possible.
Every assessment is custom-scoped. After a short scoping call, you'll receive a fixed-fee proposal based on the modules you choose and the size of your environment, with no hourly surprises.
It depends on scope. A focused single-module review moves quickly, while a multi-module assessment takes longer. You'll get a timeline in the proposal before any work begins.
Not exactly. A penetration test tries to exploit weaknesses to prove impact. This assessment is broader: it finds and validates weaknesses across endpoints, network, cloud, identity, and detection coverage, then prioritizes fixes. If you need a targeted pen test afterward, the findings make it far more efficient.
Yes. Findings can be mapped to the controls insurers and auditors commonly ask about, such as MFA, EDR, backups, patching, and logging, so you can answer questionnaires with evidence instead of guesses.
Absolutely. I work alongside your internal IT or MSP and share findings and remediation guidance directly with them, so fixes get done and nobody is left guessing.
Tell me a little about your business and what you'd like assessed. I'll follow up to schedule a short scoping call, and you'll have a fixed-fee proposal shortly after.
SentinelForge LLC is a solo-operated cybersecurity firm based in Trumbull, CT. Your assessment is performed and reviewed by the same senior analyst from scoping call to final walkthrough.