For small & mid-size businesses

Cyber risk simplified for
small business.

Know your risk. Secure your business.

A clear, prioritized picture of your security posture and exactly what to fix first. No enterprise budget or in-house security team required.

Scoped to your business size, not a template built for enterprise
Questionnaire-based — no network scans or intrusive access required
Prioritized brief delivered in about a week

Services

One clear starting point, with room to grow into more.

Cyber risk assessment is the flagship engagement. IT architecture guidance is there when a risk finding points to a bigger infrastructure question.

Flagship service

Cyber risk assessment

Find out where you're exposed, in plain English — scoped to a business your size, not a Fortune 500.

  • Questionnaire scoped to your company's size and setup
  • Mapped against trusted cybersecurity and control frameworks
  • A prioritized list of what to fix first, and why

Add-on service

Additional services

Once your risk picture is clear, add the specific support that fits where you are — from remediation help to IT architecture guidance for growing systems.

  • Remediation planning based on your budget and technical capabilities
  • Ready-to-use policy templates that meet industry standards
  • Practical roadmap for staying secure

Process

From first conversation to a plan you can act on.

Most engagements move from meeting to brief-out in about a week.

01

Discovery call

A 30 minute conversation to understand your business, your systems, and what's keeping you up at night.

02

Scoped questionnaire

You get a questionnaire sized to your business because a 5-person shop and a 150-person company don't answer the same one.

03

Analysis

Your answers are scored and mapped against industry controls and frameworks.

04

Brief-out

You get a tailored report with your risk picture and prioritized list of what to do next.

05

Deeper deliverablesOptional

For teams ready to act, you'll receive a roadmap, a project plan, and a recommended risk register to track progress.

Deliverables

Start with a brief. Add more if you need it.

Every engagement includes the discovery call and scoped questionnaire. The difference is what you walk away with.

Fastest turnaround

Essentials

For a quick, affordable gut-check.

  • Discovery call
  • Scoped questionnaire
  • Report with prioritized recommendations
Get a quote

Most complete

Program ready

For businesses building a real program.

  • Everything in Roadmap
  • Risk register and tracking template
Get a quote

"Most small businesses don't need more security tools. They need someone to tell them, plainly, what actually matters first."

— Founder, Sectrus

Run by someone who's built the program, not just sold it.

Sectrus is run by a practitioner with direct, hands-on experience building and running cybersecurity risk programs — not a generic checklist vendor. That background is built into every questionnaire, every score, and every recommendation you receive.

FAQ

Common questions before booking a call.

Most engagements move from the discovery call to a delivered brief in about a week, depending on how quickly the questionnaire is completed.

No. The assessment is questionnaire-based, so there's no need to grant network or system access to get your risk picture and brief.

The questionnaire and scoring adapt to your business size and setup, so it applies across retail, professional services, healthcare offices, contractors, and similar small and mid-size businesses.

You keep the PowerPoint brief and, if you chose a higher tier, the roadmap and risk register. You can implement fixes yourself, hand them to your existing IT provider, or ask about a follow-up engagement.

Have a different question? Ask it on the discovery call — there's no cost to talk it through first.

Get your risk picture in one meeting.

Book a discovery call and find out what a scoped assessment looks like for a business your size.