Blue North Cyber

Engagements

One environment, or all of them.

Every engagement is fixed scope and fixed fee, agreed in writing before anything starts.

  • Cloud tenant assessment

    One environment, checked against its CIS benchmark. Most people start here.

    1–2 weeks
  • Full cybersecurity audit

    Every environment you run, plus policy, access, backup, and incident readiness.

    3–5 weeks
  • Website & perimeter assessment

    Everything exposed to the internet without credentials.

    About a week
  • Security posture assessment

    A fast, honest baseline when a client questionnaire or a board is asking.

    1–2 weeks
  • Quarterly validation

    Configuration drifts. A quarterly re-check keeps the baseline true.

    Ongoing
  • Remediation support

    Help closing the gaps, or coordination with your existing IT provider.

    Scoped to findings
  • Incident response plan & tabletop

    A written plan with named owners, then an exercise that tests it.

    2–3 weeks
  • Security awareness program

    Training set up once, on a cadence, with the completion records to prove it.

    2–4 weeks

Quoted after a short call · Scope is agreed in writing before anything starts. No hourly billing.

In scope

  • Read-only access to the tenants in scope
  • Configuration measured against published CIS benchmarks
  • External checks of anything internet-facing

Not in scope

  • Penetration testing or exploitation of any kind
  • Changes to any system — assessment is passive
  • Certification, attestation, or an audit opinion

Questions

Is this a penetration test?

No. Nothing is exploited or changed — configuration is inspected and measured against a published benchmark. If you need a penetration test, you'll be told that on the first call.

Why CIS benchmarks?

Because every finding then cites a published recommendation instead of resting on one consultant's opinion. That is what makes a report hold up in front of a client, an insurer, or a board.

Will you tell us we're secure?

No, and be wary of anyone who does. The work records what was verified and where your configuration diverges from the benchmark. It stops short of certification.

What does it cost?

It depends on how many environments are in scope and how big they are. Fixed fee, quoted against a written scope before anything starts — usually one call to get to a number.

We already have an IT provider.

Good — remediation usually goes back to them. There's no managed service being sold here and no product margin behind any recommendation.

Something else? Just ask.

Find out where you actually stand.

One short call covers which tenants you run and what you need. If it isn't a fit, you'll be told.

Fixed scope, fixed fee · Quoted after a short call