Your network isn’t the only way in.
Most security assessments stop there. This one also examines your facility, your hiring and termination practices, your emergency procedures, and who can walk through your front door — with a specialist alongside me when the work calls for one.
You get a scored baseline, a prioritized list of what to fix, and what each fix costs. The report is yours — hire Associated Konsultants to carry it out, or take it to anyone.
No cost, no obligation. A short conversation, not a sales presentation.
Nothing costs you anything until we both understand what’s needed
A 20-minute call. We work out whether there’s a fit — what you’re dealing with, and whether it’s the kind of work I do. If it isn’t, I’ll tell you, and I can usually point you somewhere better.
An hour at your place. Questions in both directions, and I look at what you actually have. Not a presentation — your environment, with its history and its workarounds.
Neither costs anything. I don’t quote before I’ve seen your environment.
Then a proposal. Not a surprise.
After the visit you get a rough estimate of hours. If that’s in a sensible range, a written proposal follows: fixed hours, fixed cost, and a timeline, signed by both parties before any work starts.
You know the number before work begins. No meter running, no invoice you didn’t expect.
What actually gets examined
Two halves. Most firms only do the first.
The cyber half — scored against a published standard
Your environment is assessed against the 18 CIS Critical Security Controls, the framework most regulators and cyber-insurers now treat as the baseline for due diligence. Each control is scored on a six-point maturity scale, from non-existent to best in class.
That includes asset and software inventory, data protection, secure configuration, account and access management, vulnerability management, audit logging, email and browser protections, malware defenses, data recovery, network infrastructure and monitoring, awareness training, service provider management, application security, and incident response.
The scoring matters as much as the findings. It’s a published standard, so the result isn’t my opinion — it’s a measurement anyone can check, and one you can be re-measured against later to show what improved.
The corporate half — the part nobody else does
I don’t claim to be the country’s leading authority on physical security, so when an engagement needs one I bring one. On a recent assessment that meant Matt Tank, a retired FBI agent with more than twenty years in physical security, working alongside me on site.
I’ve used the same small group of specialists for between ten and twenty years. If your engagement needs one, they’ll join our first video call — so nobody unfamiliar turns up at your door on the day.
This is a structural advantage, not an apology for being small. A firm with staff assesses what its staff can assess. I bring in whoever the job actually requires.
Administrative
Background screening. Whether training is tracked and evidenced. Separation of duties on payments and transfers. Whether you’d know if a trusted contractor had a relevant criminal record. Whether anyone knows which recently terminated employees left unhappy. Travel and traveler safety for staff going abroad.
Health and safety
Defibrillators on site. Current CPR training. Actual first-responder times to your address. A crime survey of the surrounding blocks. Whether anyone knows the route to the nearest hospital.
Operational security
Visitor check-in and escort. Contractor identification. Emergency and incident response plans that exist on paper rather than in someone’s head. Bomb threat procedure. Signage.
Physical security
Entrance cameras. Badge-controlled doors. Fencing and gates. Parking lot lighting and coverage. Barriers and bollards — which prevent accidental vehicle incidents as often as deliberate ones.
None of that shows up in a network scan. All of it is how people actually get in.
How the work is done
Three methods, top down, breadth before depth:
Reviewing
Documentation, architecture, rule-sets, configurations, policies and interviews.
Examination
Hands-on technical and analytical work across systems, network, facility, people and process, including network-awareness scanning and direct observation of how the place actually runs day to day.
Testing
Penetration testing. Scoped separately — and the two methods above are what make it worth doing properly.
What you get, and when
Security Baseline Report
The detailed document: your current security posture, the evidence behind every finding, and where to focus. This is the paid deliverable and it’s treated as sensitive. It isn’t only the map of where you’re weakest — it also shows where you’re meeting or exceeding the baseline standards.
Executive out-brief
The summary a board or a partner group can read: scorecards for both halves, and recommendations sorted into short, mid and long term. Each finding shows where you are now and where you should be.
A meeting to go through it
The report isn’t emailed and abandoned. We sit down, walk it, and I answer questions until there aren’t any.
Timeline. Six to eight hours on site collecting information, then seven to ten days to produce the report, then the out-brief meeting. Roughly two weeks from signature.
You’re paying for the report and the judgment in it. The site visit isn’t billed separately.
Priorities, not a list of thirty problems
Every finding gets a horizon: short term, mid term, or long term. A list of thirty equal problems is useless to someone with a business to run — you need to know the three things that matter this quarter and what can reasonably wait.
Where a finding is driven by a regulation — PII, HIPAA, PCI DSS — it says so, so you can tell the difference between what’s advisable and what’s required.
The report belongs to you
You can take it to any firm you want. Hire us to carry out the recommendations, hire someone else, or do it in-house. The advice doesn’t change either way, because it was never written to sell you the next thing.
That’s not generosity. It’s the only arrangement under which the advice is worth anything.
A managed services provider who assesses your environment is producing a document that leads to a contract with them. That isn’t dishonesty — it’s how their business works, and all of them do it. It just means you’re reading a sales proposal in the clothes of an assessment.
Most clients do hire us for the work. Not from obligation, but because anyone else has to rediscover everything we’ve already found, and that costs money. We give away an option we usually win anyway.
What can follow
Nothing here is a decision you need to make now.
Implementation
Carrying out the recommendations. Same agreement, fixed hours agreed first.
Penetration testing
The third methodology, scoped separately.
Ongoing managed IT services
For retained clients: the full suite, shaped around your business rather than sold by the seat, and less expensive per hour the longer it runs. Read more →
Security awareness training and executive digital footprint work
Personal exposure removal for owners, physicians, attorneys and their families.
How we get paid
Associated Konsultants is paid for time and judgment. That’s all.
We make no money on hardware and none on software. Several of the products your environment needs aren’t sold to end users at all — only through resellers — so we procure them on your behalf, at the price you’d pay if you could buy them yourself.
One exception, and you should know about it. Microsoft 365 and Azure licensing: we buy through a distributor and our clients pay less than Microsoft’s own direct price. We keep the small difference. If you’d rather buy direct from Microsoft, that’s fine — you’re still a client.
Questions people ask
- How long does it take?
- Six to eight hours on site, seven to ten days to produce the report, then the out-brief meeting. About two weeks from signature.
- How disruptive is it to my staff?
- Very little. The time we need from any individual member of your staff is 15 to 20 minutes. That’s possible because the process is documented and built on industry standards — we already know what to ask, so nobody spends a morning being interviewed.
- How much does it cost?
- It depends on size and complexity, which is why we don’t quote before seeing the place. You’ll have a fixed number before any work begins, and I’ll bring the rate sheet to our meeting.
- Do you do penetration testing?
- Yes, but it’s scoped separately and it isn’t where I’d start. Testing tells you whether a specific door can be forced. Reviewing and examination tell you how many doors you have. Most firms who’ve never had an assessment don’t yet need a pen test — they need to know what they own.
- We already have an IT provider. Is this a problem?
- No, and it’s often why people call. An assessment isn’t a replacement — it’s an independent read on whether what you’re paying for does what you need. Your provider may well end up carrying out the recommendations.
- Why does a security assessment cover parking lot lighting?
- Because that’s a way in. Information security and physical security were split apart by convenience, not by how attackers behave. I learned to assess them together in defense work, and I’ve never seen a good reason to stop.
- What if we don’t act on the report?
- Then you own a written, prioritized, costed picture of your risk, and you can act when it suits. It doesn’t expire and we don’t chase.
- Do you only work with companies in Tucson?
- No. Associated Konsultants is based in Tucson, with clients across the country. The site visit is arranged around where you are.
Start with twenty minutes.
No cost, no presentation, no obligation. We find out whether there’s a fit — and if there isn’t, I’ll say so.
(520) 585-4746 · ClientServices@akonsultants.com · Tucson-based — clients nationwide