Enterprise customer asked about your security
A prospect or existing customer sent over a security questionnaire, asked about SOC 2, or wants to see evidence of monitoring. Deal is gated on the answer.
Katalor Security
Small business
Most small businesses get serious about security because of a specific trigger: an enterprise customer asks about it, a cyber insurance renewal lands, or a near-miss makes the owner realize how exposed they are. The Security Pulse Check is one four-week engagement that addresses all three — for a fixed price, with a one-page executive summary you can hand to a customer, an auditor, or an underwriter.
Why now
A prospect or existing customer sent over a security questionnaire, asked about SOC 2, or wants to see evidence of monitoring. Deal is gated on the answer.
Your underwriter wants evidence of MFA, EDR, an IR plan, and basic monitoring. Premiums are climbing; coverage caps are dropping. You need answers and a paper trail.
Phishing landed, an ex-employee account got hit, a vendor told you they were breached. You want grown-up security in place before next time isn't a near-miss.
Pricing
Every step is buyable. Start where it makes sense; ramp only if it earns its keep. Pricing is fixed before any work begins — no scope creep, no surprises.
Getting Started
A 30-minute intro call
A quick conversation to understand where you are, what your security pressure looks like (customer questionnaire, insurance, recent scare), and whether there's an obvious next step. No pitch deck.
Quick Audit
One-time posture review
External attack-surface scan, MFA and email-hygiene check, and a one-page summary you can hand to a customer or underwriter. Two-week turnaround, no engineering team disruption.
Security Pulse Check — Most popular
Four-week deep dive
Everything in the Quick Audit, plus a full web application penetration test and thirty days of monitored remediation. Two deliverables: technical pack for engineering, executive one-pager for the board.
Monthly Retainer
Ongoing managed security
For businesses that want their security team on retainer. 24×7 monitoring, quarterly retests, incident response on call, and rolling compliance evidence — managed by the same Katalor lead that ran your Pulse Check.
What's in the Pulse Check
Four-week engagement. Fixed scope, fixed price. One named Katalor lead, one report you can hand to anyone who asks.
We catalog everything an attacker can see from the internet — marketing site, customer portal, exposed admin panels, forgotten subdomains. Manual verification, not just an automated scan.
Authenticated and unauthenticated testing of your primary web app against the OWASP Top 10. Business-logic abuse where applicable. Findings ranked by exploitability, not just CVSS scores.
MFA coverage across your team, SPF/DKIM/DMARC posture on your domain, password-manager and SSO state. The boring stuff that closes the most common breach paths.
As your team (or contractor) fixes the findings, we monitor that the fixes hold and don't introduce new exposures. You get unblocking help, not a report-and-walk-away.
A technical pack for your engineering team or contractor (full findings, severity, fix steps). A one-page executive summary you can hand to a customer, an auditor, or an underwriter.
Works for
Timeline
30-minute call, asset inventory, kickoff. Fixed-scope SOW signed.
External recon, web pen test, identity hygiene assessment. Daily progress notes.
Technical pack + executive one-pager delivered. Remediation plan walked through.
Monitored remediation window. We watch the fixes hold and answer questions as they come up.
After the Pulse Check
If the Pulse Check surfaces enough to warrant ongoing coverage — 24×7 monitoring, retained incident response, quarterly retests, compliance evidence — the same team rolls into a monthly Katalor Security program. No second sales cycle, no new vendor.
Schedule a 30-minute scope call with Katalor Security.