Four other options are open to you. Here is honestly where each one wins, where it fails, and when we are the right answer.
The alternatives
Most comparison pages pretend the alternatives are bad. They are not. Each of these is the right answer for somebody, and being clear about which is which is the fastest way for you to decide.
| Option | Where it wins | Where it fails |
|---|---|---|
| Ask your IT provider | They know your environment, they are already engaged, and it costs nothing extra. | They are marking their own work. A customer, insurer or board asking for independent assurance will not accept it, and the provider has no incentive to report what they did not do. |
| A large accounting or consulting firm | Brand recognition that satisfies procurement, deep bench, international footprint. | Fees an order of magnitude higher, a team you did not meet at the pitch, and a scope shaped to their methodology rather than your business. Rarely interested in engagements of this size. |
| Buy templates and do it yourself | Cheapest by a wide margin, fast, and you keep full control. | Documentation proves intent, not operation. Nobody independent has checked, so you still cannot answer the question that prompted the purchase. We sell these too, and say the same thing on the product page. |
| Hire a security manager | Permanent capability, institutional knowledge, available every day. | A salary, a long recruitment, and the same independence problem: the person building the program is the person reporting on it. Most organizations of this size cannot justify the role yet. |
| RootGuard | Independent of whoever implements. Fixed fee, fixed scope, fixed end date. You keep every document, and we verify that agreed fixes actually closed. | We are a young practice with no local reference list yet. We do not implement, monitor or answer at 2am. If you need those, you need somebody else as well as us. |
What you are actually buying
Any firm can claim quality. These are the commitments that have a price attached, which is the only reason to believe them.
We do not configure systems, resell products or take vendor commission. There is no finding we profit from making and none we profit from softening. The cost to us is every implementation engagement we turn down.
The person who assesses your controls is the person in the room at the briefing and the person you call a year later. The cost to us is that we cannot scale by adding juniors.
We ask for the export, the report, the record, and inspect complete populations where the scale allows. The cost to us is that this takes materially longer than a questionnaire exercise.
Each action is checked against the criterion agreed at assessment. A message saying the work is done is not sufficient. The cost to us is a stage most competitors simply omit.
Editable files, updates included, no platform and no subscription to keep your own policies. The cost to us is the recurring revenue a locked platform would produce.
If our honest view after the free review is that you do not need a paid engagement this quarter, we say so. The cost to us is obvious, and it is the reason the free review is worth taking.
The honest limits
Stated plainly, because you will find them out anyway and it is better that you hear them from us.
Who does the work
Held between the principals, and relevant to what we actually sell rather than listed for volume.
Also SSCP and Microsoft SC-200. Full curricula vitae available on request. Credentials establish that we are qualified; they do not establish that we have delivered for you, which is why the first step is free.
The low-risk way to decide
Take the free readiness assessment, send us the result, and we will spend forty-five minutes going through it at no charge. You will know within the hour whether our reasoning is worth paying for, and it costs you nothing to find out.