Skip to content

Quick fit check

Know when this service is the right next step.

The fit depends on the problem, the systems involved, and whether the work is diagnostic, focused implementation, or a broader handoff.

Choose this service when

  • One Microsoft 365 or Google Workspace tenant, one primary domain, and up to 25 active users
  • The owner can authorize an authenticated configuration review
  • Users, administrators, MFA, recovery, stale accounts, senders, vendors, backups, and response documentation need one evidence index
  • The business needs a prioritized plan before approving implementation

Choose another path when

  • The business only needs one known public Email Trust or Website Trust module - use Focused Security Cleanup
  • Several findings already need hands-on changes - use the Business Security Remediation Sprint
  • The requested work is penetration testing, SOC monitoring, compliance certification, or a comprehensive enterprise risk assessment

Work performed

Authorized configuration and ownership evidence

The review uses explicit authorization and a safe access plan agreed after scope is approved.

Users, administrators, MFA, recovery, shared accounts, stale accounts, and offboarding evidence

One primary domain and approved email-sender inventory

SPF, DKIM, DMARC, and other available email-authentication evidence

Public website, email, and domain findings

Work performed

Practice operations and handoff evidence

Endpoint, update, and backup evidence supplied by the client or provider

Vendor and sensitive-data inventory

Incident contacts and basic response documentation

Owner/provider responsibilities and evidence-source notes

What you receive

Concrete outputs you can keep and use.

The deliverable separates completed work, remaining decisions, and any action that belongs with a provider or administrator.

Current-state and target-state scorecard

Prioritized 30/60/90-day plan

Provider-ready evidence index

Users, administrators, MFA, recovery, offboarding, sender, vendor, backup, and response-documentation notes

Public website, email, and domain findings

Owner/provider readout call

Scope and responsibilities

What CyberBit needs, and where the engagement stops.

Authorization, provider access, and customer-controlled decisions stay explicit before implementation begins.

What to provide

  • Microsoft 365 or Google Workspace tenant, one primary domain, and active-user count
  • Authorized administrators, approved sender tools, vendors, and known offboarding concerns
  • Endpoint, update, and backup evidence from the client or provider where available
  • Incident contacts and current response documentation
  • Authorized read-only or guided access after scope approval - never credentials through the public form

Boundaries

Not implementation; hands-on changes move into a Business Security Remediation Sprint

Not penetration testing, SOC monitoring, a compliance certification, or a comprehensive enterprise risk assessment

No legal advice, insurance approval, vendor approval, or guaranteed security outcome

No passwords, recovery codes, private keys, or sensitive credentials through forms or email

Pricing

From $1,250: how scope is confirmed.

The From $1,250 starting scope covers one Microsoft 365 or Google Workspace tenant, one primary domain, and up to 25 active users. CyberBit confirms authorization, evidence sources, administrators, senders, vendors, and readout scope before payment.

What can change the scope

  • More than 25 active users
  • Multiple tenants, domains, brands, or environments
  • Missing or fragmented evidence that requires additional provider coordination
  • Hands-on implementation, migration, account recovery, network, endpoint, or device work

Compare nearby options

Choose the service that matches the actual problem.

These are the adjacent paths buyers most often need to distinguish from this engagement.

Website, Email & Domain Security Snapshot

Use the $199 Snapshot for a human-verified external assessment without authenticated workspace review.

Compare the Snapshot

Focused Security Cleanup

Use one $750 module when a known public Email Trust or Website Trust issue already fits the hard scope.

Compare Focused Cleanup

Business Security Remediation Sprint

Use the Sprint when the baseline findings need broader authenticated, multi-system, network, ownership, or provider implementation.

Compare the Sprint

Service FAQ

Questions to resolve before you request scope.

Is this a setup service or a review?

It is an evidence-based configuration review with a scorecard, evidence index, 30/60/90-day plan, and readout. Implementation is separate.

Can you review both Microsoft 365 and Google Workspace?

The initial scope covers one tenant on one platform. A business using both platforms requires a separately confirmed scope.

Does this include remote-access engineering?

No generic remote-access package is implied. Any specific network, VPN, device, or remote-access work must be documented and scoped separately.

Is this a compliance or HIPAA assessment?

No. CyberBit may provide HIPAA-aware website, email, domain, workspace, and vendor-handoff support, but this is not a HIPAA Security Risk Analysis, legal advice, compliance certification, or review of all systems containing ePHI.