Core service

Security Assessment

A thorough, plain-language review of your business's security posture — what you have, what's missing, and exactly what to do next. Designed for businesses with up to 20 staff. No technical background required to understand the results.

A full picture of your risk — clearly explained.

Most small businesses don't know what they don't know when it comes to security. The First Canary Security Assessment gives you a structured, expert review of your digital environment and translates what we find into language you can actually act on.

We look at the areas that matter most for businesses your size: how your team handles email, where your data lives, how your network is set up, and whether your basic security practices are in place. The entire assessment is conducted remotely — no on-site visit required.

We diagnose — you decide what to fix. Our job is to give you a clear, honest picture of your risks and the options available to you. We don't provide ongoing services or fix issues on your behalf. That keeps us objective and keeps you in control.

Sample Report — Risk SummaryAcme Dental · 2025
High
Staff email accounts not using two-factor authentication
Next step: Enable 2FA enforcement in your email admin settings (15 min)
High
Patient data backup stored on same network as workstations
Next step: Move backups off-site or to an isolated cloud storage account
Medium
Website contact form transmitting data without encryption
Next step: Ask your web host to install an SSL certificate (free)
Medium
No formal offboarding process when staff leave
Next step: Create a checklist — revoke accounts on the last day of employment
Low
No written password policy for staff
Next step: We can draft one for you as an add-on

Everything we review.

Email securityAuthentication records (SPF, DKIM, DMARC), 2FA enrollment, admin access controls, breach exposure check on your domain.
Network & devicesExternal exposure scan, Wi-Fi configuration, remote access setup, device OS and patch status via lightweight pre-session script.
Data handlingWhere sensitive data lives, backup practices and whether they have been tested, access controls on sensitive files.
Access managementUser accounts, shared credentials, former employee access, and offboarding practices.
Software & updatesOperating system and application patch status, end-of-life software in use.
Web presenceSSL certificate validity, security headers, CMS platform identification, exposed admin panel check, domain security.
Staff practicesPassword hygiene, phishing awareness, shadow IT, incident reporting culture.
Risk reportEvery finding rated High / Medium / Low with a plain-English explanation and a concrete, actionable next step.
Report walkthroughA video call to review findings, answer your questions, and discuss what to prioritize first.

Where we stop.

Being clear about scope keeps us objective and your costs predictable.

Re-assessment options: Quarterly re-assessments at 25% off ($375). Annual re-assessments at 15% off ($425). Re-assessments focus on changes since the prior report — no long-term commitment required.

What to expect.

Most assessments are complete start to finish in under two weeks. Everything is handled remotely.

01

Sign the engagement agreement

We send a plain-language contract via DocuSign covering scope, deliverables, pricing, and data handling. Takes about 2 minutes to review and sign.

02

Payment and intake questionnaire

Once signed, we send the payment link and a short intake questionnaire. Covers your business setup, tools, and main concerns. No technical knowledge needed — "I don't know" is a valid answer. Payment is due before work begins.

03

Schedule your working session

Once payment clears, we send a scheduling link for a 90–120 minute video call where we go through your questionnaire together and make sure we have a complete picture before the assessment begins.

04

Assessment

We conduct the review remotely — combining independent external scanning, information from the working session, and a simple one-command system check you can run on each work computer ahead of time.

05

Report and walkthrough

Written report delivered within 7 business days of the working session, followed by a video call to walk through every finding and discuss priorities.

Add-on services.

Simple, transparent pricing.

One flat rate. No tiers, no hidden fees, no ongoing commitment unless you choose one.

Ready to see where you stand?

One-time, no ongoing commitment required.

Get your assessment →