ESRM Program · Assets Cluster

Cybersecurity

A security leader on your side of the table, working with your IT provider.

$2,500 fixed-fee assessment 3–4 weeks Credited toward the vCISO program

Measured against CIS Controls v8.1 and NIST CSF 2.0. Led by Don Oxman, CPP, CISSP, CISM. Licensed by Texas DPS. In business since 2013.

Most small businesses assume IT has security covered.

Cybersecurity is one of thirteen domains in our Enterprise Security Risk Management (ESRM) program, and part of the Assets cluster with Physical Security, Information Security, and Brand Protection. It covers the systems, accounts, and networks your business runs on: a title company wiring closing funds, a dental group in Keller, a Grand Prairie plant with machines online.

In most small and mid-sized companies, cybersecurity is left to the IT provider, and the owner assumes it is handled. The provider keeps things running, but nobody independent sets the standard, checks the work, or answers the cyber-insurance application with real evidence. When a wire gets redirected or ransomware hits, the gaps all show up at once. We write the security standard, your IT provider implements it, and we verify the work.

What can go wrong with your systems

Email & wire fraud

A compromised mailbox or a convincing fake invoice redirects a payment. Anyone who wires money is a target.

Ransomware

Attackers steal data and then lock your systems. Recovery depends on backups that were actually tested.

Account takeover

Reused passwords and accounts without multi-factor authentication let attackers log in as an employee.

Third-party access

Your IT provider, software vendors, and billing services all have some access. Their breach can become yours.

Insurance & contracts

Insurers and larger customers ask detailed questions about your controls. A wrong answer can cost a claim or a contract.

Legal exposure

Texas SB 2610 can shield smaller businesses from punitive damages after a breach if they follow a recognized framework.

Five questions for leadership

  • Is multi-factor authentication turned on for email, remote access, and every admin account?
  • When were your backups last restored in a test, and how long did the restore take?
  • Who outside your company can log in to your systems today, and who reviews that list?
  • Could you back up every answer on your cyber-insurance application with evidence?
  • Does a written incident response plan say who calls the insurer and outside counsel?

If you answered “no” or “not sure” to any of these, that is where we would start. Most of these gaps cost little to fix before an incident and a great deal to fix after one.

How an Engagement Works

Every ESRM domain starts with the same fixed-fee assessment. If you decide to continue, we credit the fee toward the program, and cybersecurity becomes part of your vCISO engagement alongside whichever other domains you need.

Step 1 · Start here

Cybersecurity Assessment

Fixed fee · typically 3–4 weeks
$2,500
  • Interviews with the owner or CFO, your IT provider, the controller or office manager, and anyone with admin access.
  • Structured review: a 15-question risk profile, a 25-point practices checklist, and a maturity score from 1 (Initial) to 5 (Optimized).
  • Environment profile: systems, cloud services, remote access, vendors with access, and where sensitive data sits.
  • Gap analysis against CIS Controls v8.1 and NIST CSF 2.0, with an eye to the Texas SB 2610 safe harbor.
  • Written report and prioritized roadmap, walked through with your leadership team. The report is yours whether or not you continue.

The fee is credited in full toward the program if you start within 90 days.

Step 2

The vCISO / ESRM Program

Run as a vCISO engagement or inside your full ESRM program
$2,500–$7,500 /month
  • Assess (Q1): we start from your assessment findings. If cyber is your main risk, the program runs as a vCISO engagement.
  • Build (Q2): written security policies, a control standard for your IT provider to implement, an incident response plan, and a vendor access review.
  • Verification: we check your IT provider’s work against the standard using evidence. We never hold admin credentials ourselves.
  • Tabletop exercise on a ransomware or wire fraud scenario, so leadership knows who calls the insurer, counsel, and the bank.
  • Operate (Q3+): we stay on as your named security lead, with quarterly reviews, insurance renewal support, and reporting to leadership or your board.

Month to month. Cancel with 30 days’ notice. About the vCISO program →

Add-on · Any client

Security Requests & Exercises

Billed per request, quoted in advance.

  • Customer questionnaires answered accurately, with evidence.
  • Cyber-insurance applications checked against what is in place.
  • Tabletop exercise built around one scenario you worry about.
  • Board briefing on cyber risk, written for owners and directors.

Why Total 360

Independent review

We never hold admin credentials, and we don’t resell security products or take commissions. That keeps our review of your IT provider’s work honest.

Cyber inside the bigger picture

Wire fraud, stolen laptops, and fake executive emails cross into fraud, physical, and brand risk. We handle cyber as one part of your security program.

Experienced leadership

Led by Don Oxman: M.S. in Security Management, CPP, CISSP, CISM. U.S. Army and AT&T background. In business since 2013 and licensed by Texas DPS.

Common questions

What does a cybersecurity assessment cost?

$2,500, as a fixed fee. It usually takes three to four weeks from kickoff to the readout. If you start the vCISO program within 90 days, the full fee is credited toward it.

What do we get at the end of the assessment?

A written report with your maturity score from 1 (Initial) to 5 (Optimized), the gaps we found against CIS Controls v8.1 and NIST CSF 2.0, with an eye to the Texas SB 2610 safe harbor, and a prioritized roadmap. We walk your leadership team through it, and the report is yours whether or not you continue.

Do we have to sign up for the full program?

No. The assessment stands on its own. If you continue, cybersecurity runs inside the vCISO program at $2,500 to $7,500 a month depending on scope. It is month to month, and you can cancel with 30 days’ notice.

Can we buy security requests & exercises without the program?

Yes. They are available to any client. Billed per request, quoted in advance.

Will you replace the people and providers we already use?

No. We work alongside your IT provider, attorney, insurer, and other advisors. We set the standard, help them meet it, and check that the work gets done.

Start with a 30-minute Risk Discussion

No deck and no sales pitch. Tell us who runs your IT and what concerns you. We’ll give you an honest read on the gaps and send a scoped proposal within five business days.

Schedule a Risk Discussion Or call 817-677-0515 · info@total360security.com