Small business

Your security team. For small business.

Most small businesses get serious about security because of a specific trigger: an enterprise customer asks about it, a cyber insurance renewal lands, or a near-miss makes the owner realize how exposed they are. The Security Pulse Check is one four-week engagement that addresses all three. Fixed price, one-page executive summary you can hand to a customer, an auditor, or an underwriter.

Schedule a scope call See what's included
Why now

Three reasons small businesses finally call us

Enterprise customer asked about your security

A prospect or existing customer sent over a security questionnaire, asked about SOC 2, or wants to see evidence of monitoring. Deal is gated on the answer.

Cyber insurance renewal is coming up

Your underwriter wants evidence of MFA, EDR, an IR plan, and basic monitoring. Premiums are climbing; coverage caps are dropping. You need answers and a paper trail.

A near-miss made it real

Phishing landed, an ex-employee account got hit, a vendor told you they were breached. You want grown-up security in place before next time isn't a near-miss.

Pricing

Pick your starting point

Every step is buyable. Start where it makes sense; ramp only if it earns its keep. Pricing is fixed before any work begins. No scope creep, no surprises.

Intro call
Free

A 30-minute intro call

A 30-minute conversation about where you are and what is worth doing first. No pitch.

  • Understand your security posture
  • Spot quick wins
  • Get a clear next step
  • No commitment required
Book a call
Quick AuditStarts at
$1,500

One-time posture review

External attack-surface scan, MFA and email-hygiene check, and a one-page summary you can hand to a customer or an underwriter. Two-week turnaround.

  • External attack-surface scan
  • MFA and email hygiene check
  • One-page executive summary
  • 60-minute walkthrough call
Schedule audit
Most popularSecurity Pulse CheckStarts at
$4,500

Four-week deep dive

Everything in the Quick Audit, plus a full web-application pen test and 30 days of monitored remediation. A technical pack for your engineers and a one-pager for the board.

  • Everything in Quick Audit
  • Web application penetration test
  • 30 days monitored remediation
  • Technical pack + executive one-pager
  • Named Katalor Security lead
Schedule Pulse Check
Monthly managedStarts at
$2,500/mo

Ongoing managed security

Your security team on retainer: 24×7 monitoring, quarterly retests, incident response on call, and rolling compliance evidence, run by the same lead who ran your Pulse Check.

  • 24×7 SOC monitoring
  • Quarterly retests
  • Incident response retainer
  • Rolling compliance evidence
  • Named Katalor Security lead
Start a conversation
What's in the Pulse Check

Inside the Security Pulse Check

Four-week engagement. Fixed scope, fixed price. One named Katalor Group lead, one report you can hand to anyone who asks.

01

External attack-surface review

We catalog everything an attacker can see from the internet: marketing site, customer portal, exposed admin panels, forgotten subdomains. Manual verification, not just an automated scan.

02

Web application penetration test

Authenticated and unauthenticated testing of your primary web app against the OWASP Top 10. Business-logic abuse where applicable. Findings ranked by exploitability, not just CVSS scores.

03

Email and identity hygiene check

MFA coverage across your team, SPF/DKIM/DMARC posture on your domain, password-manager and SSO state. The boring stuff that closes the most common breach paths.

04

Thirty days of monitored remediation

As your team (or contractor) fixes the findings, we monitor that the fixes hold and don't introduce new exposures. You get unblocking help, not a report-and-walk-away.

05

Two deliverables

A technical pack for your engineering team or contractor (full findings, severity, fix steps). A one-page executive summary you can hand to a customer, an auditor, or an underwriter.

Works for
  • SOC 2 vendor-review responses
  • Cyber insurance renewal evidence
  • Customer security questionnaires
  • Post-incident hardening
Timeline

Four weeks, then a month of monitored follow-through

No multi-month sales cycle, no open-ended retainer. The work happens, the report lands, the fixes ship. We stay watching.

Week 1

Scope

30-minute call, asset inventory, kickoff. Fixed-scope SOW signed.

Weeks 2-3

Test

External recon, web pen test, identity hygiene assessment. Daily progress notes.

Week 4

Report

Technical pack + executive one-pager delivered. Remediation plan walked through.

+30 days

Verify

Monitored remediation window. We watch the fixes hold and answer questions as they come up.

After the Pulse Check

Ramp to ongoing security only if it's worth it

If the Pulse Check surfaces enough to warrant ongoing coverage, the same team rolls into a monthly Katalor Security program: 24×7 monitoring, retained incident response, quarterly retests, compliance evidence. No second sales cycle. No new vendor.

See the full Katalor Security program

Ready to adopt AI without the exposure?

Book a 30-minute scope call. We will walk your stack, point out the exposure that matters most, and propose the right program. No cost, no obligation.

Schedule a scope call Email the security team
No-cost scoping call
Senior security lead on every engagement
Monthly or annual terms