Watch
- ✓ Named responder on 24/7 recall
- ✓ Priority triage within four hours
- ✓ Annual security posture review
- ✓ Cyber-insurance documentation support
The engagement catalogue · Milton, NH
Every Kryptomend engagement is fixed in scope and stated in price before it begins. What follows is the whole catalogue — from a single penetration test to a firm kept on standing recall.
How every service is delivered
Whichever line you engage, the method is the same: a written scope, real-world testing, a report your own team can act on, and a retest to prove the fix. No line item is a black box.
Rules of engagement, systems in scope, and test windows are signed off — so you always know what is happening and when.
Manual exploitation, not just an automated scan — credential attacks, misconfigurations, and known ransomware footholds.
Each finding is ranked by exploitability and business impact, with reproduction steps and a remediation path.
Critical and high items are retested at no extra charge to confirm the door is actually shut.
The catalogue in full
Prices below are typical starting points for a small or mid-sized business. Final figures are set once the scope is agreed — never before, never after.
Everything an outsider can reach: internet-facing services, remote access, VPNs, and the perimeter your business exposes without meaning to.
What an attacker does once inside — a phished laptop, a compromised vendor. Lateral movement, privilege escalation, and access to what matters.
A hands-on assessment of a customer-facing or internal application — authentication, business logic, injection, and access-control flaws.
A controlled campaign against your staff, reported without naming names — a measure of the human surface and the training it needs.
Policy, access, and backup posture assessed against a written remediation roadmap — and mapped to the control language cyber insurers ask for.
Microsoft 365, Google Workspace, or AWS reviewed against hardening baselines — identity, sharing, logging, and the defaults most teams never change.
Backup validation, network segmentation checks, and a tabletop exercise of your response plan — before the day you need it.
Kept on standing recall
Most clients begin with a fixed-scope engagement and move to a retainer once they see the surface they were carrying. Choose the depth that fits your risk.
Containment, forensics, and recovery for an active breach. Retainer clients reach a named responder first; the line below is answered around the clock.
Before you engage
Straight answers on scope, price, and what a test does to a business that has never had one.
No. Every engagement runs inside agreed test windows with rules of engagement signed in advance. We flag any high-risk action before it runs, and destructive testing is never performed without explicit, written consent for that specific step.
A breach checks whether the door was locked, not the size of the payroll. The bulk of ransomware losses land on businesses under a hundred staff. Our fixed-scope assessments are built for exactly that size — a clear starting price and a report your existing IT support can act on.
The figures on this page are typical starting points. We hold a short scoping call, count the systems genuinely in play, and quote a fixed price before any work begins. You are never billed for hours spent scanning systems that were never in scope.
A findings report led by a plain-language executive summary, then every issue ranked by exploitability and business impact with reproduction steps and a remediation path. It maps to the questions on common cyber-liability questionnaires, and includes one retest of critical and high items.
Scoping is typically a one-week intake. A fixed-scope assessment is delivered in three to four weeks, with the findings report inside ten business days of testing. An active incident is different — for that, call the line, don't wait on a form.
A mutual NDA precedes every engagement. Test data, credentials, and findings are held under a documented retention and destruction policy and removed on the agreed schedule once the work closes.
Not sure which line you need?
Tell us what you run and who you answer to. We'll point you at the right first step and quote it in writing — no obligation to go further.