TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one partner Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Who We Serve  /  Small & Medium Business

We become your security executive. Not another vendor you have to manage.

You're not ready for a full-time CISO and you might never be. What you need is someone senior who owns the outcome, shows up every month, and handles the things that keep landing on whoever happens to be closest. That's a retainer, and we publish what it costs.

88%
of breaches at small and mid-size businesses involved ransomware, against 39% at large organizations.
Verizon, 2025 Data Breach Investigations Report
43%
of security incidents involved shadow AI, more than double the year before.
IBM, Cost of a Data Breach Report 2026
35%
of small organizations say their cyber resilience is inadequate, a share that has grown sevenfold since 2022 while large organizations' has nearly halved.
World Economic Forum, Global Cybersecurity Outlook 2025
The thing nobody is watching

Your employees are already using AI. The question is whether your company knows how.

Nobody ran a procurement process for this. Somebody signed up for a chatbot on a Tuesday, it worked, they told two colleagues, and now customer lists and contracts and half your pricing model have been pasted into tools nobody has reviewed. That's not a hypothetical risk profile. It's most companies we walk into.

FIND IT

Shadow AI discovery

We find which AI tools are actually in use across browsers, extensions, endpoints and your SaaS estate, and which accounts they were signed up with. The first honest inventory is usually uncomfortable reading, and it's also the fastest thing we can give you.

GOVERN IT

Policy and training people follow

An acceptable use policy written in English, an approval path for new tools, and training that covers what your staff will actually face. Cloned voices on a phone call. Video that looks like you. Messages written well enough that the old advice about spelling mistakes is useless.

DEFEND IT

Controls where the data moves

Data loss prevention around AI tools, least-privilege access to anything AI can reach, and vendor review of the AI features your existing suppliers quietly switched on last year without asking you.

The one almost everyone misses

Turning on Microsoft 365 Copilot or Google Gemini doesn't create new permissions. It surfaces the ones you already had, including every sharing mistake anyone has made since you set the tenant up. Microsoft publishes guidance on this because it's the most common way a rollout goes wrong. Fixing the permissions first is cheap. Explaining afterwards why the assistant summarised the payroll file is not.

Your customers have started asking

AI questions are showing up in enterprise security questionnaires, and auditors are now asking for evidence of data-flow controls around AI integrations. A policy saying "don't paste customer data into ChatGPT" gets no credit as a control. If you sell to anyone larger than you, this is about to become a sales problem rather than a security one.

Pricing

Published rates, because you shouldn't need three calls to learn a number.

Most firms in our industry make you sit through a discovery process before they'll say what anything costs. We think that's a poor way to treat someone's time, so here it is.

Cyber Risk Assessment
Where nearly everyone starts. One engagement, no commitment afterwards.
$2,500one timeDelivered in 10 business days
  • External attack surface review
  • Security controls, identity and MFA assessment
  • Endpoint, backup and recovery assessment
  • Vendor risk and compliance gap analysis
  • Cyber insurance gap review
  • Executive risk report and 90-day roadmap
AI Security Bundle
For companies where AI arrived before the policy did, which is most of them.
$2,500–$5,000/ monthPriced on company size and scope
  • AI risk assessment and shadow AI discovery
  • AI usage and governance policy
  • AI data protection and vendor risk review
  • Staff training on deepfakes, phishing and data leakage
  • AI incident response procedures
  • Quarterly AI risk review
  • Executive AI risk dashboard
Our main offer
Security Leadership Program
Enterprise cybersecurity leadership for companies that aren't ready for a full-time CISO.
$5,000/ monthAgainst $250,000+ for the equivalent hire
  • Monthly executive security review
  • Security roadmap, risk register, board reporting
  • SOC 2, HIPAA, NIST and CMMC readiness
  • Policy management, security questionnaires, vendor risk
  • Architecture review, vulnerability management, SOC oversight
  • Incident response plan and tabletop exercise
  • Cyber insurance renewal prep and control validation
  • AI governance included

The path most companies take is assessment, then roadmap, then retainer, and there's no obligation to move along it. Retainers run month to month after an initial term. Monitoring, endpoint and identity detection, and email security are quoted on top depending on your environment, because pretending one number covers every company would be a lie you'd find out about later.

What you're actually buying

The security executive, rather than the security vendor.

CISA makes this point about smaller organizations: you may not have a formal CIO or CISO, but those functions still have to be owned at an executive level by somebody. Usually they get spread across whoever is nearest, which is how things end up half done.

01

Someone owns it

A named person, in your monthly leadership meeting, accountable for the answer when a client, an insurer or your board asks a hard question.

02

The questionnaires stop being your problem

Enterprise security reviews get answered by us, on your behalf, with evidence attached. This alone tends to pay for the retainer in unstuck deals.

03

Your insurer gets real answers

We prepare the renewal and validate the controls you're attesting to, so the policy you're paying for actually responds when you need it.

04

Your MSP keeps doing its job

We work alongside whoever runs your systems rather than replacing them. They keep things running. We're accountable for whether they're defensible.

Who this is for

Organizations where one bad week would be felt for years.

We work best with businesses between roughly ten and five hundred people, where somebody owns technology as part of a broader job and nobody owns security outright.

Professional services

Law firms, accounting practices, consultancies. You hold your clients' most sensitive material, and increasingly they're the ones asking you to prove you can protect it.

Client questionnairesSOC 2Privilege & confidentiality

Media & publishing

Local television, radio, digital news and production houses. A compromised broadcast chain does reputational damage in minutes that takes years to undo.

Production systemsSource protectionContinuity

Nonprofits & mission-driven

Foundations, associations, community organizations. Donor data and grant records, defended on an overhead budget everybody scrutinises.

Donor dataGrant complianceVolunteer access

Healthcare-adjacent

Dental groups, therapy practices, billing companies, medical suppliers. HIPAA applies whether or not anyone has walked you through what it requires.

HIPAABusiness associate agreementsPHI handling

Financial & insurance services

Independent advisors, agencies, mortgage brokers, lenders. The FTC Safeguards Rule reaches further than most owners expect and regulators have stopped being patient.

FTC SafeguardsGLBAPCI-DSS

Multi-site operators

Franchises, clinics, dealerships, regional service companies. Every location is a network, and the one you visit least is running the oldest firewall.

Site-to-siteWireless auditsStandard policy
What we find

Five things that break, over and over.

We've seen the same failures across enough companies to know where to look first, and almost none of them are exotic.

01

No one is accountable

Security lives with an office manager, a founder, or an outsourced help desk whose contract covers uptime and nothing else.

02

Everything runs on cloud defaults

Microsoft 365 and Google Workspace arrive configured so everything works for everyone on day one. Most tenants we open still have legacy sign-in enabled and sharing wide open.

03

AI showed up without a decision

Nobody approved it, nobody inventoried it, and the accounts it runs on aren't company accounts, which means there's no logging and no way to get the data back.

04

Compliance arrives as a surprise

A client sends a questionnaire, or an insurer asks for evidence, and suddenly a framework you'd never heard of is a condition of doing business.

05

Backups exist but were never tested

Plenty of companies have backups. Far fewer have restored from one recently, and an incident is an expensive time to find out which group you're in.

Start with the assessment.

Two and a half thousand dollars, ten business days, and a ranked list of what to do about it. If you want us to execute the roadmap afterwards we'll talk about a retainer, and if you'd rather take it to someone else the document is still yours.