Founder-led · Framework-aligned · Transparently priced
Assessments, Microsoft 365 & Google Workspace hardening, and 24/7 managed protection for the small businesses and school districts the big firms overlook — real expertise, published pricing, clear terms.
Free 30-minute consult
Instant, transparent pricing
A senior expert answers
150+
Security controls checked
every assessment
5
Compliance frameworks
CIS · NIST · HIPAA · FTC Safeguards · PCI
10-day
Report turnaround
fixed timeline
24/7
Managed monitoring
SOC-backed
ALIGNED TO
CIS Controls
NIST CSF
Microsoft 365 & Google Workspace
HIPAA
FTC Safeguards
PCI DSS
Why now
The organizations attackers hit hardest are the ones with the least security help.
Ransomware against small businesses and school districts keeps climbing, and cyber-insurers now deny claims when basic controls like MFA aren't in place. You don't need more alerts or a bigger IT budget — you need the right handful of controls, done right.
Most incidents exploit misconfigurations a proper assessment finds in week one.
Insurers are raising the bar
No MFA, no EDR, no policy? Applications get denied and premiums spike.
K-12 is a top target
Districts hold rich data with lean IT teams and tight budgets.
Attacks are automated
Small size is no longer camouflage — bots scan everyone, equally.
Our approach
Four stages, on your timeline — start anywhere, and only take the next step when it's right for you.
01
Assess
Find the gaps — a clear, ranked picture of your real risk.
02
Harden
Close them — MFA, Microsoft 365 & Google Workspace, and identity, done right.
03
Advise
Stay ahead — fractional CISO leadership and insurance readiness.
04
Protect
Keep watch — 24/7 managed detection and response.
Assessments & projects
One-time projects that solve a specific problem — and give you a clear picture of what to do next. Every price is a starting point; final scope depends on your size and environment.
Security Baseline Assessment
Know exactly where you stand — the perfect first step.
Starting at
$3,000
External vulnerability scan + Microsoft 365 or Google Workspace identity posture review
Risk register aligned to the CIS Controls (IG1) + cyber-insurance readiness check
Prioritized 12-month remediation roadmap you can act on
Vulnerability Assessment
Find the holes before someone else does.
Starting at
$1,900
External assessment $1,900 flat — internal + external with hands-on validation of key findings starting at $4,500
Full technical report plus a plain-English executive summary
Clear, prioritized remediation plan
Microsoft 365 & Google Workspace Hardening
Lock down the tools your team lives in every day.
Starting at
$2,200
Conditional Access / context-aware access + MFA enforcement, endpoint & email threat-protection configured
Email authentication (SPF / DKIM / DMARC) + anti-phishing policy
OAuth-app cleanup, backup verification, before/after posture score
IAM / MFA Rollout
The #1 control your cyber-insurer asks for.
Starting at
$1,800
Microsoft Entra ID, Google Workspace, or Duo — designed and rolled out
Phased deployment with clear user communications
Keep your policy: MFA is the most common insurance requirement
Password & Identity Audit
Fast, affordable, and eye-opening.
Starting at
$1,200
Active Directory / Entra / Google Workspace password audit + breach-exposure sweep
Stale-account and privileged-access review
One-week turnaround
K-12 Cybersecurity Assessment
Written for superintendents, boards, and insurers.
Starting at
$3,500
District-wide review: identity, endpoints, backups, and vendor risk
Cyber-insurance application readiness
Board-ready summary + grant-fundable roadmap
Small-district tier starting at $3,500; full-district engagement $8,000–12,000
See a real assessment report before you buy
Board-ready, plain-English, with a prioritized 90-day roadmap. Here's a full sample deliverable (fictional district) so you know exactly what you'll get.
Managed protection
Ongoing protection that keeps working after the project ends — the difference between a point-in-time report and a security program your insurer actually trusts. Priced per month on a 12-month term. Build your exact price below.
Instant pricing — no email required
Build your price
Pick a package and slide to your size. Your price depends on how big you are — not on how well you negotiate.
Full managed protection — EDR, email, MFA / identity, scanning, quarterly reviews.
Users
20
Workstations & laptops
20
Servers
1
ADD-ONS
More than 150 users? Book a call — volume pricing kicks in.
YOUR ESTIMATE
20 users × $35
$700
1 server × $20
$20
$720
/ mo
≈ $36 / user effective
Each user includes one protected workstation, MFA, email security, and awareness training.
Instant estimate, not a binding quote — we confirm it on a short scoping call. No setup fees. Managed plans are billed monthly on a 12-month term that renews to keep coverage continuous — cancel before renewal with 60 days’ notice.
24/7 SOC-BACKED · CYBER-INSURANCE READY · 12-MONTH TERM
Crusader Shield
Our flagship — complete managed protection layered over your existing IT.
Managed EDR with a 24/7 SOC backstop
Managed email security + phishing simulation & training
MFA / identity management + monthly external scanning
Quarterly security review with a real person
Optional compliance tier (HIPAA / FTC Safeguards) — toggle it in the calculator
Managed EDR / MDR
Endpoint detection & response, watched around the clock.
24/7 SOC-backed detection and response
Deployment, tuning, and alert triage handled for you
Monthly rollup report
Managed Email Security + Awareness
Stop phishing at the door and train your team.
Enterprise-grade email filtering with managed policies
Awareness training + monthly phishing simulations
Reporting you can put in front of leadership
Managed Vulnerability Scanning
Always know what needs fixing.
Monthly external + internal scans, human-validated
Quarterly trend review
Feeds directly into your cyber-insurance renewal
vCISO Retainer
Senior security leadership, without a full-time hire.
Foundational — policies, quarterly reviews, insurance questionnaires
Standard — monthly reviews, compliance program, board reporting
Compliance — audit-ready leadership for financial-services & healthcare
Add any tier to your estimate in the calculator
K-12 Defense Subscription
District-wide protection, priced per endpoint.
Managed EDR on staff endpoints + identity monitoring
Staff awareness training + phishing simulations (student edition included)
Monthly scans and a quarterly review with your tech coordinator
Builds on — never resells — the free state and CISA services your district already gets
OUTSIDE A FIXED SCOPE
Standard consulting $175 / hr
Emergency incident response (no retainer) $300 / hr
How we work
No 40-page proposals or enterprise runaround. A clear process with named deliverables, ending in something you can act on.
01
Kickoff & scope
A short call to confirm scope, access, and what success looks like — fixed price agreed before we start.
02
Assess & collect evidence
External scans, Microsoft 365 or Google Workspace identity review, and configuration analysis mapped to the CIS Controls.
03
Ranked findings report
A plain-English report with technical detail — every finding ranked by real-world risk and effort to fix.
04
Remediation roadmap
A prioritized 12-month plan you own: do it yourself, hand it to your IT team, or have us close the gaps.

Security Assessment
SAMPLE · your logo & findings
B+
68 / 100
POSTURE SCORE
3 critical · 5 high · 11 medium findings, each with a fix.
CRITICAL
MFA not enforced for admins
HIGH
Legacy/basic auth still enabled
MEDIUM
No DMARC enforcement on domain
+ prioritized 12-month remediation roadmap
Founding-client offer
15% off your first engagement in exchange for a short testimonial. A few early spots only.
Why Crusader
Serious security, priced for real budgets — and a person who answers the phone.
Transparent, instant pricing
Project prices are published up front, and managed protection prices itself in our calculator — no opaque quotes, no "call us for pricing."
Senior expertise, direct
You work with a seasoned practitioner — not a junior handed your account after the sale.
Cyber-insurance ready
Built to pass the questionnaires and renewals your insurer and clients now demand.
Powered by our own platform
We run findings and reporting through the Crusader platform — consistent, evidence-backed results.
What we don't do
We don't take vendor commissions or kickbacks — our advice is vendor-neutral.
We don't lock you into multi-year contracts — managed plans run on a clear 12-month term you can cancel before any renewal.
We work alongside your existing IT team — we don't try to replace them.
We don't hand your account to a junior — you work with a senior practitioner.
See where you stand — free
Run a passive check on your own domain and get a plain-English read on the email authentication, encryption, and header gaps attackers look for first. No agent to install, no call required.
Takes about 30 seconds. We only check what's already public.
Common questions
Do you replace our IT provider?
No. We work alongside your existing IT team or MSP as your dedicated security specialist — the role most small organizations are missing.
What's included in an assessment?
An external vulnerability scan, a Microsoft 365 or Google Workspace identity posture review, a risk register mapped to the CIS Controls, a cyber-insurance readiness check, and a prioritized, plain-English remediation roadmap.
How long does it take?
Most assessments are delivered within 10 business days. Hardening and managed-onboarding timelines are agreed up front, in writing.
Remote or onsite?
We start in person. For Wisconsin clients, the kickoff and initial walkthrough happen onsite. From there, most assessment and monitoring work runs remotely and securely, with onsite visits whenever the work calls for it. Outside Wisconsin, engagements are fully remote.
What happens after the assessment?
You get a report you own — no lock-in. Every finding is a clear next step you can act on yourself, hand to your IT team, or have us remediate. Your call.
Do you work with K-12 budgets and grants?
Yes. K-12 engagements are structured for board approval and mapped to grant-fundable remediation wherever state or federal cybersecurity grant programs apply, with reporting written for superintendents and insurers.
How does pricing work?
Projects are fixed scope, fixed price — published right here. Managed protection is priced by the calculator above: pick a package, set your user and device counts, and see your monthly price instantly. Managed plans are billed monthly on a 12-month term and renew to keep your coverage continuous — cancel before renewal with 60 days’ notice. No setup fees, no surprise invoices.
Let's talk
Book a free 30-minute consult. We'll talk through where you stand, what your insurer needs, and the smallest next step that moves you forward — no pressure, no obligation.
Calendar not loading? Open our booking page
Prefer email? Reach us directly at info@crusadersec.com
Madison, Wisconsin — serving Wisconsin and remote clients nationwide