The questions owners actually ask.
Including the awkward ones - answered the way we’d want them answered if we were buying.
How long have you been in business?
The practice is built so you never have to take our word for anything: fixed published prices, scope and exclusions in writing on every engagement, senior certified partners for the deep technical work, and a scored before-and-after so results are measured, not claimed. You verify instead of trust.
Are you certified?
Penetration testing is delivered by our partners’ certified senior testers, named in every contract - credentials you can look up, not logos on a slide. For training, the measure that matters is behaviour: we score your team before and after, and show you the difference.
Why should we trust you with our office?
Don’t take anyone’s word for it - including ours. Every price is fixed and published, the full checklist we score against is public on this site, a complete sample report is open before you pay, scope and exclusions go in writing on every engagement, and nothing is simulated without your signed authorization. Verification before trust - it’s the same standard we teach.
Can you do penetration testing?
Yes - through certified senior partners, scoped and translated by us. You get one accountable local contact and the right expert for the job. We’ll never point a scanner at your network and call it a pen test - you’d be surprised how often that’s what’s being sold.
What if we get hacked?
In the first hour, your cyber insurer’s breach line leads - calling anyone else first can jeopardize coverage. We prepare you before (so hour one is a laminated checklist, not a panic), advocate for you during, and harden after. Anyone our size who claims they’ll firefight it solo is telling you a story.
Do we really need this?
Maybe not. Take the free self-check - if you score Ready, we’ll say so in writing and point you at the free resources. Two things are true either way: your insurance renewal will ask these questions, and the offices that get hit are almost always the ones nobody ever checked.
Will our IT company be upset?
They usually thank us. We don’t touch their lane - we train your people, check the things that fall between the cracks, and send them a copy of everything we find. Different jobs, same team.
Will anyone be embarrassed in training?
No - it’s our founding rule. Props get named, people don’t. Scores are team scores. Simulations are authorized in writing and report in aggregate only. The fastest way to make an office insecure is to make people afraid to report, so we do the opposite.
Why does it cost this much?
The flagship works out to roughly $195 a person, once, for the training your team will still be talking about at renewal time - versus $30 a seat every year for videos nobody remembers, or five figures a day for the enterprise version of the same drill. And you keep artifacts - scorecard, certificates, insurer answers - the cheap options never produce. Prices are fixed and published; nobody gets a different number.
Can you make it cheaper?
The price is fixed - that’s a promise to every client, not a negotiating position. What flexes is scope: we can start with the two highest-risk items and stage the rest, or spread payments 50/25/25 on anything over $3,000.
What do you need from us for a training day?
A room, a TV or blank wall, your team for the booked block, and fifteen minutes of prep with whoever runs the office. We bring everything else, including backup dongles. Nothing gets installed.
Is our information safe with you?
We collect the minimum, never take custody of patient or client records, delete simulation data within 30 days, and put data handling, confidentiality and liability in plain language in the engagement letter.