“We have IT support, but no security plan.”
Define priorities, assign responsibilities, and give your internal IT team or managed service provider a shared roadmap.
Security advisory & managed exposure
Practical policies, clear responsibilities, and a plan your business can follow. Praeven helps small and midsize businesses establish their security foundations, manage external exposure, and keep improving with ongoing guidance.
From priorities to practice
A familiar starting point
Start with the decisions that are already showing up in your work.
Define priorities, assign responsibilities, and give your internal IT team or managed service provider a shared roadmap.
Set practical rules for access, information handling, and approved tools, with examples employees can apply.
Document your current practices, identify gaps, and build a realistic improvement plan you can explain.
A defined project
Establish the policies, responsibilities, and priorities your business needs to get started.
We review how your organization works, agree on the most useful changes, and develop a focused set of policies and supporting procedures. Each project includes a plan for approval, rollout, and follow-through.
Scope, deliverables, revision rounds, timing, and fees are agreed before work begins. The policy set is selected around your needs and existing practices.
Recognized guidance, including NIST CSF 2.0, helps structure the work. Your business context determines the priorities.
Policies people can use
Each policy connects an expectation to the people, decisions, and practices needed to support it.
How employees use business systems, handle information, and request exceptions.
Which personal devices can access business resources, required protections, support responsibilities, and departure procedures.
Approved tools, permitted data, uses that need approval, human review, and a way to raise questions.
How access is requested, approved, reviewed, and removed when someone changes roles or leaves.
What employees should report, who receives it, and how the business reaches the right technical support.
AI use governance
AI tools can help people move quickly. Your business still needs to decide which tools are approved, what information may be used, and who owns those decisions.
Praeven helps turn those decisions into practical expectations your team can follow. The work fits naturally into a foundations project or an ongoing advisory engagement; it does not require a separate AI program to get started.
For ongoing clients, we can revisit the tool register, vendor changes, and policy fit as your use of AI evolves.
Managed exposure review
Praeven reviews your authorized internet-facing systems, turns scan results into practical priorities, and works with your team or MSP to track the fixes.
Recommended starting point
$750per month
$500 one-time setup
$1,500per month
$3,000per month
Additional advisory time is $225/hour. Additional public assets are $50 per asset per month. Specialized technical work is quoted separately. Plans include business-hours intake, initial severity assessment, recommended next steps, and coordination with your IT provider. They do not provide 24/7 monitoring, active containment, malware removal, forensics, legal advice, or breach notification. View all pricing and packages.
Ongoing security advisory / vCISO
Keep your security program moving as your business, people, and technology change.
A virtual chief information security officer (vCISO) provides security leadership on an agreed schedule. Praeven helps leadership review risk, choose priorities, and coordinate progress with the people doing the work.
We agree on the meeting cadence, advisory capacity, response expectations, and responsibilities before starting. Managed exposure review can be included when a recurring view of your public-facing systems is useful. This is also where we help teams set practical AI use, vendor, and data-handling expectations. Hands-on implementation and incident response are scoped separately.
Start after a foundations project or build on an existing program. We review your current position before recommending the scope.
How we work
Understand your goals, current practices, systems, and the requirements driving the work.
Draft the agreed policies, procedures, and roadmap with input from the people who will use them.
Business leadership approves the decisions. Praeven guides the rollout, and your IT team or provider implements agreed technical changes.
Review progress, address questions, and hand over the plan or continue with a defined advisory engagement.
Connect the plan to your people
Give employees the context and skills to follow your policies. Choose a dedicated training program or a focused session as part of an agreed advisory rollout.
The Tradecraft Series helps employees recognize threats, verify unusual requests, and report concerns. Connect those habits to your organization’s policies.
Explore the trainingUse a focused session to introduce a policy, explore AI use, or help leaders work through a specific security decision.
Explore briefings and workshopsCommunity Cybersecurity Readiness Review
No cost for eligible local organizations.
Praeven offers a limited number of guided readiness reviews for small local utilities and essential community organizations. We’ll discuss your current practices and provide a short, prioritized action plan with resources your team can use. No purchase required.
We are starting with two review appointments per month. Tell us about your organization, location, and needs so we can confirm eligibility and availability.
Questions draw on selected CISA Cybersecurity Performance Goals. Findings reflect reported practices; this review does not verify controls or certify compliance. It involves no scanning, system access, or operational changes.
This is an independent Praeven service, not a CISA assessment or a government-endorsed program. Drinking-water and wastewater utilities can also request a free assessment through EPA.
Tell us about your team, your current IT support, and what you want to improve. We’ll discuss whether a foundations project or ongoing guidance fits.
Prepare. Anticipate. Protect.