Skip to main content

For one small business

A confidential Cyber Health Check and a practical 90-day plan.

Get a clear view of what matters most without committing to a long assessment or burying the owner in a compliance report. The result is a short list of priorities the business can actually sequence and operate.

When this is useful

Use the health check when the business needs direction before a larger project.

It works for regulated and unregulated businesses alike. Customer expectations, insurance questions, growth, contracts, or a general sense that security has become too ad hoc can all be valid reasons to establish a baseline.

Starting well

Startups

Founders establishing business-controlled email, accounts, devices, sharing, backups, and employee procedures.

Finding the baseline

Existing small businesses

Owners who know security matters but do not know which weaknesses are most important or how to sequence improvements.

Supporting growth

Growing teams

Businesses adding staff, vendors, cloud services, customer expectations, or more complicated access and data-sharing workflows.

Preparing for pressure

Customer and contract scrutiny

Businesses facing questionnaires, insurance questions, supplier onboarding, contract expectations, or a new need to explain current practices.

Three tracks, one practical system

Choose the track that matches the business pressure.

The assessment and reporting backbone stays consistent. The questions and recommendations change with the business stage and the reason security work matters now.

Existing small businesses that need a practical starting point.

Cyber Health Check

Find the weaknesses that matter most and turn them into a manageable 90-day sequence.

  • Identity and email
  • Devices and backups
  • Vendors and incident readiness
  • Insurance and customer pressure

New businesses establishing their first real technology environment.

Secure Startup Launch

Build minimum viable security early, while accounts, devices, sharing, and operating habits are still taking shape.

  • Business-controlled email
  • Multi-factor authentication and password management
  • Administrative separation
  • Backups, sharing, and starter procedures

Suppliers and contractors facing customer, insurer, public-sector, or prime-contractor questions.

Contract-Ready Security

Understand the requirement, avoid unsupported claims, and organize the next practical readiness steps.

  • Questionnaires and clauses
  • Evidence and answer support
  • Supplier onboarding
  • FCI and CUI applicability screening when relevant

What the business receives

A short engagement with a decision-quality result.

The point is not to create a large technical report. The point is to help an owner see what matters, what can wait, who should own the next action, and what outside support may be useful.

  1. 01

    Short owner-friendly intake

  2. 02

    60 to 75-minute guided assessment

  3. 03

    Category-based red, yellow, and green scorecard

  4. 04

    Five prioritized recommendations

  5. 05

    30-day, 60-day, and 90-day action plan

  6. 06

    30-minute confidential results discussion

What to expect

Six steps from application to a usable plan.

  1. 01

    Apply

    Share basic business context, choose a track, and confirm the limited scope.

  2. 02

    Confirm eligibility

    Trawvid Sec checks program fit, sponsor criteria, capacity, and any routing concerns.

  3. 03

    Prepare

    Gather high-level provider details and ordinary business records without sending secrets.

  4. 04

    Assess

    Work through a guided 60 to 75-minute review grounded in how the business actually operates.

  5. 05

    Receive the report

    Get the scorecard, five priorities, and a sequenced 90-day action plan.

  6. 06

    Discuss results

    Use a private 30-minute conversation to clarify ownership, effort, and the next decision.

Confidentiality by design

Funding the program does not create access to a business's security details.

Trawvid Sec keeps participant advisory records separate from sponsor program reporting. A participant controls its individual report and action plan.

The participant receives

  • Interview notes when retained in the participant record
  • Individual scorecard
  • Five priorities and 90-day action plan
  • Confidential results discussion

The sponsor receives

  • Enrollment and completion counts
  • Non-identifying industry and employee ranges
  • Aggregate risk categories and outcome indicators
  • Program satisfaction and future-program recommendations

Direct engagement

A defined first step for one business.

$950 to $1,250

The final price depends on business size, complexity, and the track selected. The standard scope is interview-based and does not require system access, scanning, file uploads, or custody of sensitive evidence.

Discuss fit and scope

Included

Guided assessment

A 60 to 75-minute discussion focused on the selected track and the way the business actually operates.

Included

Prioritized result

A category scorecard, five practical priorities, and a 30-day, 60-day, and 90-day action sequence.

Included

Private results call

A 30-minute discussion to answer questions, clarify ownership, and decide what should happen next.

Scoped separately

Implementation support

Hands-on changes, deeper evidence review, technical testing, expanded documentation, and ongoing advisory are separate engagements.

Program questions

Clear boundaries before anyone enrolls.

Will a sponsor see an individual business result?

Ordinarily, no. Individual interview notes, scorecards, findings, evidence, recommendations, and action plans stay between Trawvid Sec and the participating business. Sponsors receive approved aggregate, non-identifying program outcomes unless a participant separately authorizes a specific disclosure.

Is this a penetration test or technical audit?

No. The program is an interview-based health check with limited review of appropriate, non-sensitive evidence examples. It does not include exploitation, scanning, social engineering, forensic acquisition, continuous monitoring, or formal audit work.

Does the program certify compliance?

No. It provides practical readiness guidance and next steps. It is not a certification, formal CMMC assessment, audit opinion, legal conclusion, insurance determination, contract-award guarantee, or promise that an incident cannot occur.

What businesses are a good fit?

The program can support startups, existing small businesses, manufacturers, suppliers, professional services firms, and businesses facing customer, contract, insurance, or public-sector expectations. A sponsor can set additional service-area or membership eligibility.

What information does a participant need to provide?

Basic business and technology context, major providers, the IT support model, current business pressure, and ordinary records that help explain current practices. The intake does not accept passwords, multi-factor authentication codes, recovery codes, restricted data samples, detailed network diagrams, contracts, insurance records, or file uploads.

Can a business get help after the health check?

Yes. Follow-on advisory or implementation support can be scoped separately when the participant wants it. A sponsor is not told whether a participant buys additional work unless the participant separately authorizes that disclosure.

Supporting more than one business?

Chambers, municipalities, associations, incubators, and supplier programs have a separate partner path.

Explore endorsed resources, co-branded programs, and sponsored cohorts without sorting through the individual-business engagement.

Sponsor or partner options

Choose your next step

Start with a private conversation or the self-guided checklist.

If a Cyber Health Check is not the right fit, the introductory call should make that clear before you commit to anything.