Security Advisory Retainer

Your security. Covered.
Without hiring a CISO.

Ongoing Microsoft 365 security advisory for Austin law firms, CPA practices, and title companies. Plain-English guidance, cyber insurance readiness, and a named person to call, starting at $500/month.

Microsoft 365 Focused
No Long-Term Contract
Austin-Based
300+ M365 Accounts Advised
The Problem

Small firms have real security pressure.
And no one on staff to handle it.

Cyber insurance carriers, clients, and regulators are all raising the bar at the same time. Most firms under 40 people don't have an internal security resource. They don't need a full-time CISO either. They need something in between.

Cyber insurance renewals are harder

Carriers now require documented evidence of MFA, access controls, and security policies. Most small firms can't answer the questionnaire confidently because nobody is watching those controls.

You don't know what you don't know

Microsoft 365 is powerful, but most small firm environments were set up for convenience, not security. Misconfigured settings and stale access are the rule, not the exception.

Compliance pressure is real

Law firms, CPAs, and title companies face bar requirements, state data protection laws, and increasingly security-conscious clients asking questions you need to be able to answer.

No one to call when something feels off

Your IT vendor fixes tickets. But when a suspicious email lands or a staff member clicks something they shouldn't have, you need an advisor, not a help desk.

What's Included

Security advisory built for firms your size

Not enterprise complexity. Not a generic checklist. A consistent advisory relationship focused on the things that actually matter for a professional services firm running Microsoft 365.

01

M365 Security Posture Reviews

Regular review of your Conditional Access policies, MFA enforcement, admin accounts, Defender configuration, and sharing settings. In plain English.

02

Written Posture Summaries

A simple document showing where you stand, what changed, and what to prioritize next. Built to show your cyber insurance carrier, a client, or a partner.

03

Cyber Insurance Support

Help answering renewal questionnaires, documenting your controls, and understanding what carriers are actually asking for before your renewal comes up.

04

Vendor and Client Questionnaires

When a client or partner sends a security questionnaire, you'll have someone to help you answer it accurately and confidently instead of guessing.

05

Incident Advisory

A named person to call when something feels off — phishing attempts, suspicious logins, staff security concerns. Triage and guidance, not a ticket queue.

06

Security Awareness Guidance

Practical recommendations for staff — what to watch for, how to use M365's built-in training tools, and how to reduce your human risk layer without a dedicated program.

How It Works

Simple. Consistent. Ongoing.

A clear path from finding your gaps to staying ahead of them, with regular visibility built in by default.

1

Security Assessment

A 45–60 minute conversation. No system access required. We walk through your security posture, AI usage, backup, and access controls. Plain-English written findings within 48 hours. No commitment required.

2

Baseline and Roadmap

Month one: we document where you stand and build a prioritized list of what to address first, in order of actual risk.

3

Quarterly Reviews

Every quarter: a review call, updated posture summary, and your next quarter priorities. You always know where you stand.

4

Ongoing Access

Between reviews: email and phone access for questions, incidents, insurance renewals, and anything that comes up between cycles.

Your Advisor

A named person. Not a platform.

You work directly with Jeremy Lowery, not a shared team or an automated reporting tool. Jeremy has 20 years across MSP, Microsoft, and security environments — including time as a Microsoft Customer Success Manager overseeing hundreds of M365 accounts across professional services firms.

He holds Microsoft certifications in cloud fundamentals, security, and Azure. His focus is exclusively on the firms and environments that match this service: professional services, Microsoft 365, under 40 people, Austin area.

Microsoft Certifications
MS-900 · M365 Fundamentals SC-900 · Security Fundamentals AZ-900 · Azure Fundamentals
Experience
20 Years in IT 300+ M365 Accounts Microsoft Background
Focus
Austin-Based Professional Services Microsoft 365 Only Firms Under 40 People
Pricing

Straightforward retainer pricing

No long-term contracts to start. Cancel with 30 days notice. Most clients start with a Security Assessment before choosing a tier.

Essential
Annual coverage for smaller firms
$500 / month
No minimum commitment
  • Annual M365 security review
  • Annual written posture summary
  • Cyber insurance questionnaire support
  • Email access for questions
Get Started
Partner
Deeper engagement and planning
$1,750 / month
No minimum commitment
  • Everything in Advisory
  • Monthly check-in call
  • Annual security roadmap document
  • Staff security awareness guidance
  • On-call incident support (2 hrs/month)
  • Cyber insurance renewal prep session
Get Started

All tiers include a one-hour M365 Security Assessment to start. Already a managed IT client? Ask about bundled pricing.

Scope

What this covers and what it doesn't

Honest about what fits and what doesn't. If you need something outside this scope, we'll tell you and point you in the right direction.

In Scope
What's covered
  • Microsoft 365, Entra ID, and Defender configuration
  • Conditional Access and MFA review
  • Cyber insurance readiness and questionnaire support
  • Risk communication to firm leadership
  • Vendor and client security questionnaire guidance
  • Incident triage and advisory
  • Security awareness recommendations
  • M365 change monitoring and alerts
Out of Scope
What this isn't
  • Formal HIPAA or SOC 2 certification audits
  • Penetration testing
  • Legal or compliance certification work
  • 24/7 SOC monitoring
  • Non-Microsoft environments such as Google Workspace
  • Network infrastructure engineering
  • Incident response execution
Who This Is For

Professional services firms under 40 people

Firms that handle confidential client data, run Microsoft 365, and don't have a dedicated security resource on staff.

Law Firms

Bar association requirements, client confidentiality, and increasingly security-conscious opposing counsel and partners. We know what Austin law firms actually face.

  • Attorney-client privilege protection
  • State bar compliance guidance
  • Matter-based access controls

CPA Practices

Tax data, financial records, and client trust are all on the line. Cyber insurance carriers are asking harder questions at renewal. We help you answer them.

  • Client financial data protection
  • Secure file sharing for tax season
  • Cyber insurance renewal support

Title Companies

Wire fraud and social engineering are the primary threat vectors. Real estate transactions are high-value targets. We help you build the controls that actually matter.

  • Transaction data protection
  • Wire fraud risk reduction
  • Access control cleanup

Other Professional Services

Any Austin firm under 40 people that handles confidential client data on Microsoft 365 and wants consistent security without hiring a full-time resource.

  • M365 security and administration
  • Proactive posture monitoring
  • Quarterly reviews built in
Common Questions

Frequently asked questions

Are you a CISO?

No, and I'm upfront about that. I'm an IT security consultant with 20 years across MSP, Microsoft, and security environments — including direct advisory work at Microsoft across hundreds of M365 accounts. The advisory services I provide are appropriate for firms your size. If you need a formal CISO engagement, I'll tell you and point you toward someone who offers that.

We already have an IT company. Why do we need this?

Most IT companies fix things when they break. Security advisory is a different function — proactively reviewing your posture, preparing for insurance renewals, and having someone watching the strategic picture. Many clients use both. If your current provider already covers this, you probably don't need me.

What does the Security Assessment involve?

45–60 minutes. No system access required. We walk through a structured set of questions covering M365 security, AI usage, backups, and access controls. You answer based on what you know about your environment. I identify the gaps, document the findings, and send you a plain-English written report within 48 hours. No obligation after that.

Is there a long-term contract?

No long-term contract required to start. Monthly retainer, cancel with 30 days notice. Most clients start with the Security Assessment and a month-to-month Advisory retainer, then decide from there.

We're already a managed IT client. Does this overlap?

Partially. Managed IT clients already get security attention as part of their service. The advisory retainer is a separate, elevated layer for firms that want documented quarterly posture reviews, insurance support, and a formal advisory relationship on top of day-to-day IT. Ask about bundled pricing if you're an existing client.

What if we have a security incident?

Advisory and Partner tier clients have direct phone access to reach Jeremy when something happens. I'll help you triage the situation, understand what you're dealing with, and figure out your next steps. If the incident requires a formal incident response firm, I'll help you find one and brief them on your environment. You won't be navigating it alone.

Start with a Security Assessment

One hour. No software install. A plain-English picture of where your Microsoft 365 environment actually stands and where your real risks are.

No commitment. No pitch. Just findings you can use.