Baseline · For businesses under 100 employees
Your MSP runs your IT. Nobody runs your security program.
A defensible security program — built, documented, and maintained — without displacing the IT provider you already pay.
$4,950 to build it $500/month to keep it 45 days
Bundled price with a 12‑month commitment. $6,500 for the build alone. Level‑pay available.
Anchored to CIS Controls v8.1 IG1 — the 56 safeguards SB 2610 names for your headcount. We hold no credentials to your systems, and your IT provider keeps every dollar of their contract.
The law
Texas SB 2610
20–99 employees must implement all 56 CIS Controls IG1 safeguards, maintained on an ongoing basis.
The renewal
Your cyber insurer
The application is now a multi‑page attestation. Every answer is a representation you are signing.
The deal
Your biggest customer
A 200‑row security questionnaire, and nothing moves until somebody can answer it.
Nine Deliverables. Forty-Five Days. One Fixed Price.
Baseline is fixed scope. Not “up to” nine deliverables, not “as needed” — these nine, in forty‑five days, for the price on this page. Every one of them is scored against CIS Controls v8.1 IG1, the standard Texas SB 2610 names for a business your size.
Current-State Assessment
All 56 IG1 safeguards scored against your actual environment, by owner interview, technical interview with your IT provider, and evidence review. Produces a scored gap register — not a checklist someone filled in from memory.
SB 2610 · Insurer · QuestionnaireShared Responsibility Matrix
Every safeguard mapped to your IT provider, your business, or us — built jointly with your provider in a working session. Most businesses have never seen their coverage written down. Neither has their provider.
Your IT provider · Audit trailRisk Register
Your top 12–15 risks, rated by likelihood and impact, each with a named human owner and a target date. Reviewed and re‑rated quarterly for as long as you stay on Care.
SB 2610 · Owner & boardCore Policy Set
Ten ratified policies — acceptable use, access control, authentication, data classification and retention, vendor risk, remote work, incident response, awareness, backup, and the program policy above them. Tailored to your environment and signed, not downloaded.
SB 2610 · Insurer · QuestionnaireIncident Response Plan & Tabletop
A written plan naming who is in charge, who gets called, and what happens in the first hour — then a 60‑minute tabletop walkthrough with you and your IT provider in the room. Insurers have started asking for the exercise record specifically.
SB 2610 · InsurerAttestation Pack
Pre‑answered responses to the standard insurance application and the common customer questionnaire, each tied to a numbered piece of evidence. This is usually the deliverable that started the conversation.
The actual triggerAwareness Training Rollout
Training coordinated across all eight IG1 awareness safeguards, with a completion records baseline established. Training records are named in SB 2610 by statute and requested on nearly every insurance application.
SB 2610 — all headcount tiersRemediation Roadmap
Prioritized, costed where possible, and issued to your IT provider as a scope of work they can quote — never as a report card. Most providers have been asking for some of this budget for two years.
Your IT providerOwner Readout
A written program summary and a 45‑minute presentation to you and, if you want it, your board or your bank. Plain language, no acronym theatre, and an honest answer to “are we covered?”
Close · Board-readyWhat Baseline is not. We do not implement, configure, monitor, patch, or administer anything — that is your IT provider’s contract, and we are not trying to take it. We specify; they implement. And we never hold a credential to any of your systems, which is written into the agreement rather than promised in a meeting.
Why that matters to you. Independence is most of what you are buying. Your insurer and your customer’s procurement team both know the difference between a security review and a provider grading their own homework.
Forty-Five Days, Not Ninety
Insurance renewals and customer questionnaires land on a 30–60 day clock, not a 90‑day one. Baseline is built to the clock you are actually on.
Days 1–7
Discovery
- Owner kickoff — 60 minutes
- Technical interview with your IT provider — 90 minutes
- Document and evidence request issued
- Letter to your IT provider sent before the first call
Days 8–21
Assessment
- All 56 IG1 safeguards scored against evidence
- Shared Responsibility Matrix built with your provider
- Risk register drafted and rated
- Interim findings call — no surprises at the readout
Days 22–35
Documentation
- Policy set drafted and circulated for comment
- Incident response plan written
- Awareness training launched
- Remediation roadmap costed with your provider
Days 36–45
Ratification
- Policies ratified and signed
- Incident response tabletop run
- Attestation pack finalized
- Owner readout delivered
If your renewal is sooner than that — the assessment, risk register, and attestation pack can be complete in three weeks, which is what your insurer actually needs. Policies and the tabletop follow in the normal window.
Day 46: Baseline Care begins. Quarterly program review with your risk register re‑rated in writing. Annual full re‑assessment, policy refresh, and tabletop. Two questionnaires or insurance applications reviewed a year. $500 a month.
One Price. Published. No Discovery Call Required to Get It.
The cheapest published vCISO retainer in the 2026 benchmark data is $1,500/month — $18,000 a year, with no program build at all. Baseline builds the program and maintains it for $10,950 in year one and $6,000 every year after.
Baseline Build
$4,950 one time $6,500
Bundled price with a 12‑month Care commitment. $6,500 for the build on its own.
- All nine deliverables, complete in 45 days
- All 56 CIS IG1 safeguards assessed against evidence
- Ten policies tailored, ratified, and signed
- Incident response plan plus a live tabletop
- Attestation pack with an indexed evidence trail
- Roadmap issued to your IT provider as fundable scope
- 50% at signature, 50% at readout — or level‑pay, below
Baseline Care
$500 /month
Begins day 46. Month‑to‑month after the first year, 30 days’ notice.
- Quarterly program review, risk register re‑rated, two‑page written status
- Annually full IG1 re‑assessment, policies refreshed and re‑ratified, tabletop re‑run, attestation pack rebuilt
- Named‑contact email access, 2‑business‑day response on governance questions
- Two questionnaires or insurance applications reviewed per year
- Notification when a governing framework changes
Year one: $10,950 · Every year after: $6,000
Against $18,000 a year for the cheapest published retainer on the market — which does not include the build.
Level-pay
No build fee at signature. $1,325/month for six months, then $500/month, on a 24‑month term. Same year‑one total. Requires ACH autopay.
Beyond the calendar
$275/hour for ad‑hoc advisory, billed in 30‑minute increments. Rarely charged — it exists so the boundary is real.
Extra questionnaires
$450 each beyond the two included per year. If you are consistently past that, Foundation is the cheaper answer.
We will not sell you Care without the Build. There would be nothing to maintain — we would be charging you $6,000 a year to review documents that do not exist. That is not a sales position; it is an indefensible one if you are ever breached.
Your IT Provider Keeps Every Dollar
The fastest way to kill a security engagement is to walk in and audit the IT provider. Baseline is built so that does not happen — not as a courtesy to them, but because a provider who is on your side is worth more to your security than a report that makes them look bad.
01
We never hold a credential
No administrative access to any of your systems, ever — written into the agreement, not promised in a meeting. Assessment is by interview, document review, and evidence your provider supplies. Governance work does not require access.
02
The coverage matrix is theirs too
Built jointly in a working session, it documents what your provider already covers across all 56 safeguards — which for a competent provider is most of the technical ones. Most have never had it written down and cannot easily produce it themselves.
03
Gaps become their scope of work
Everything requiring implementation is written as work your provider can quote and sell. In practice we end up making the case for security spend they have been asking you to approve for two years.
04
They hear it from you first
A one‑page letter you forward to your provider the day you sign, stating what we do, what we explicitly do not do, and what they get out of it. It goes out before the first technical call.
“You run the controls. We own the paperwork, the risk decisions, and the questions the owner can’t answer at renewal. If we find a gap, it becomes your scope of work — not our project.”
What we say to your IT provider, in the first conversation, verbatim.
If your provider wants to see it before you commit, send them the letter. It is one page and it answers the question they are actually asking.
Read the Letter to Your IT ProviderIs Baseline the Right Program for You?
Baseline fits
All five have to be true.
- Fewer than 100 employees
- An IT provider already under contract
- No audit or certification underway, or committed inside 12 months
- No contract naming a framework beyond CIS Controls
- No prior incident with legal or regulatory exposure still open
Typically triggered by an insurance renewal, a customer questionnaire, or Texas SB 2610. See where SB 2610 puts you →
Baseline does not fit
Any one of these and we will tell you so on the call.
- An auditor is already scheduled, or SOC 2 is on the roadmap
- A customer contract names ISO 27001, HIPAA depth, PCI‑DSS, or CMMC
- You need someone accountable between the scheduled touchpoints
- You have no IT provider and need the controls run, not just governed
- You are dealing with the aftermath of a live incident
Every one of these routes to the vCSO program, which starts at $2,500/month. Compare the tiers →
The five questions everyone asks
My IT provider already handles security. Why do I need this?
They probably handle the controls well. Ask them for your written risk assessment, your ratified policy set, and your training records — the three things SB 2610 and your insurer ask for by name.
If they have them, you do not need us. Almost nobody has them, because it is not what an IT contract buys.
Is $500 a month too cheap to be real?
It is cheap because it is narrow. You get a fixed calendar of deliverables, not an executive on call. The build is where the work is; the $500 keeps it from going stale.
If you need someone in the room every month, that is a different program and it costs five times as much. We will say so rather than stretch this one.
Can we just do a template pack off the internet?
You can, and the policies will be fine. What a template cannot do is score your actual environment against 56 safeguards, tell your insurer which ones you meet, or put a name on a signed risk assessment.
The document is not the deliverable. The defensibility is.
What happens if we get breached anyway?
Nothing prevents a breach, and anyone who tells you otherwise is selling something.
Texas SB 2610 gives you an affirmative defense against punitive damages if you had a qualifying program in place — not against compensatory damages, regulatory fines, the Attorney General, or a class action. What you are buying is a documented, defensible position and a plan you have actually rehearsed.
Our renewal is in three weeks. Is that too late?
No. The assessment, risk register, and attestation pack can be complete in three weeks — that is the part your insurer actually reads. The policy set and the tabletop follow in the normal window and are ready well before you need them for anything else.
Thirty minutes, and you will know which program you need
A Risk Discussion is not a sales call with a discovery script. We ask five questions, tell you which tier fits, and if the answer is that your IT provider already has this covered, we will say that instead.
Schedule a Risk Discussion Don Oxman · Total 360 Security · No credential to your systems, ever.