SERVICES
AMM Cyber Solutions offers practical, a la carte cybersecurity support for small businesses. Start with an assessment, then add the right mix of policies, training, and technical hardening based on your goals, your systems, and your budget.
-
The absolute best way to find out where your business is vulnerable—without the tech jargon, long-term commitment, or high upfront costs.
____________________________________________
📋 What You Get in 1 Hour:
We run a comprehensive baseline evaluation of your physical, network, email, cloud, and employee defenses. Within days of our 1-hour consultation, you will receive a crystal-clear, 1-Page Cybersecurity Scorecard (based on industry-standard frameworks like ISO 27001, SAFETAG, and the Essential Eight) featuring:
An Overall Security Grade (A to F): A realistic, honest assessment of your current risk level so you know exactly where you stand.
Detailed Section Scoring: Clear, color-coded grades across 9 critical defense areas (Physical Security, Backups, Network Infrastructure, Email Spoofing Protections, Identity/MFA, and more).
The Top 3 "Quick Wins": A prioritized list of the absolute highest-ROI fixes we can implement immediately to shut down automated attacks.
____________________________________________
🎁 The Risk-Free Guarantee (Fee Waived):
We believe in building trusted, practical partnerships.
We charge a simple, flat fee for this high-value 1-Hour Health Check and the resulting customized scorecard report.
If you decide to contract AMM Cyber Solutions for any subsequent services (whether it's a quick, one-time hardening project or a monthly retainer) within 30 days of receiving your report, the entire fee of the Health Check is 100% waived/credited back to you.
____________________________________________
🛠️ Flexible Engagement: Project-Based or Monthly Retainer:
Once we have completed your Health Check and identified your gaps, we don't force you into a rigid, one-size-fits-all package. Any defense tier within our service menu below can be delivered in two distinct ways:
🛠️ As a Targeted Project: Need a quick win or immediate remediation? We can execute any specific tier (such as building your secure backup architecture, conducting a live employee threat workshop, or hardening your cloud infrastructure consoles) as a fixed-scope, standalone project.
🛡️ As a Continuous Retainer: Want hands-off, long-term peace of mind? Select the exact protection levels your business needs to build a customized monthly retainer. This ensures ongoing monitoring to actively prevent "Posture Drift" and locks in priority access to a certified expert when you need it most.
-
Minimizing the digital "doors and windows" that attackers use to breach an organization by keeping all your business software up to date.
____________________________________________
Level 1 — Passive Domain Audits:
What’s Included: Fully automated dark web monitoring for your corporate domains and continuous monthly scanning alerts for newly leaked credentials.
Why You Want This: Employees often use work emails to sign up for external websites. If those sites are hacked, their passwords leak onto the dark web. This acts as an early warning system to change passwords before a hacker uses them to access your network.
🛠️ One-Time Project Delivery: A comprehensive, single deep-dive audit of your corporate domain history to uncover, flag, and force resets on all historically leaked credentials floating on the dark web.
🛡️ Monthly Retainer Management: Continuous monitoring. Hackers dump newly stolen databases onto the dark web daily; a password leaked today might not have existed last month. Monthly oversight ensures we catch and reset newly exposed logins before they are exploited.
____________________________________________
Level 2 — Active Patch Oversight:
What’s Included: Continuous monthly auditing, monitoring, and verification of security updates and hotfixes on all business machines.
Why You Want This: Outdated software is like a cracked shop window; hackers scan the internet for these exact cracks. We continuously audit every office machine to prove your software is updated and the "window" is locked tight.
🛠️ One-Time Project Delivery: A complete baseline audit and manual patching cycle for all current office machines, bringing your entire device inventory up to date simultaneously.
🛡️ Monthly Retainer Management: Ongoing maintenance. Software updates are released constantly, and devices frequently skip updates when users click "Remind Me Later" or close their laptops. Monthly auditing ensures no machine falls behind, keeping your entire office unified under a single defense.
____________________________________________
Level 3 — Dynamic Attack Surface Mapping:
What’s Included: Continuous monthly external network and communication port scanning.
Why You Want This: As your business grows, IT changes can accidentally leave network doorways (ports) open. We continuously scan your public internet connection to ensure no unauthorized doors are left propped open to the public.
🛠️ One-Time Project Delivery: An intensive, one-time external penetration scan of your public IP addresses and network endpoints to discover open ports or unpatched external vulnerabilities.
🛡️ Monthly Retainer Management: Continuous scanning. Your internet provider may reset equipment, or local software may automatically open communication ports to sync data. Monthly scans verify that no accidental, unauthorized pathways to your internal systems have been silently created.
-
Targeting the single most common vulnerability: compromised logins, which account for approximately 80% of modern data breaches.
____________________________________________
Level 1 — Security Posture Verification:
What’s Included: Self-reported account security and login posture review during regular check-ins.
Why You Want This: A single guessed password can bankrupt a business. This regular check holds your team accountable, ensuring critical double-locks are active on your bank accounts and business emails.
🛠️ One-Time Project Delivery: A comprehensive initial discovery workshop and audit evaluating your team's current login protocols, MFA usage, and credential safety habits.
🛡️ Monthly Retainer Management: Routine verification. Human habits naturally drift. Employees frequently disable secure features (like screen locks or security keys) on their personal devices for temporary convenience and forget to turn them back on. Monthly verification keeps security policies active and top-of-mind.
____________________________________________
Level 2 — Setup & Deployment Support:
What’s Included: Ongoing monthly administrative support for onboarding new hires to password managers, modifying user access, and maintaining app-based MFA configurations.
Why You Want This: Setting up security apps can be frustrating for staff. We walk your team through the process, ensuring authenticators and shared password vaults (like Bitwarden Teams) are configured correctly and productively.
🛠️ One-Time Project Delivery: Strategic architecture and deployment of a business-wide password manager platform alongside a structured rollout of corporate MFA configurations across your current team.
🛡️ Monthly Retainer Management: Ongoing user administration. Your workforce is dynamic—employees join, leave, change devices, and alter their business roles. If a departing employee’s vault access isn't verified as revoked, or a new hire is onboarded without MFA, you have an open backdoor. Monthly check-ins keep your directory clean and secure.
____________________________________________
Level 3 — Identity Console Hardening:
What’s Included: Continuous monthly administration reviews of your primary cloud environments (Microsoft 365 or Google Workspace) to disable unauthorized legacy login protocols.
Why You Want This: Foreign hackers run automated bots that try millions of password combinations against your logins. We log into your administrator consoles to block logins from foreign countries entirely and shut down old, insecure backdoors.
🛠️ One-Time Project Delivery: A complete backend teardown and hardening project for your Microsoft 365 or Google Workspace admin console—disabling legacy protocols, setting conditional access rules, and configuring geo-blocking filters.
🛡️ Monthly Retainer Management: Continuous configuration audits. Cloud platform defaults are constantly updated by Microsoft and Google, often introducing new legacy protocols or altering conditional access rules. Monthly configuration audits ensure your administrator settings never "drift" into less secure states.
-
The ultimate business insurance policy. If a ransomware outbreak occurs, this is how we ensure you keep the doors open and never pay a ransom.
____________________________________________
Level 1 — Backup Structure Review:
What’s Included: Continuous monthly mapping and review of your backup directories to ensure new operational folders align with the "3-2-1" backup rule.
Why You Want This: If your backup drive is plugged directly into an infected computer, ransomware encrypts that backup too. We inspect your layout to guarantee your "digital life raft" is physically separated from your network so it cannot be destroyed in an attack.
🛠️ One-Time Project Delivery: Architecture and deployment of a localized and cloud-based "3-2-1" backup framework, mapping your company's critical files to ensuring absolute network isolation.
🛡️ Monthly Retainer Management: Continuous mapping reviews. Businesses experience "Scope Drift." If your employees create a new, highly critical client folder, local folder, or database this month, but it wasn't explicitly added to your backup configuration list, it remains completely unprotected. Monthly reviews ensure your backups grow alongside your data.
____________________________________________
Level 2 — Active Log Verification:
What’s Included: Detailed monthly manual verification of backup success logs and encryption states.
Why You Want This: Backups fail silently due to minor software glitches or disconnected cables. We manually audit your backup records every month to guarantee your data is actually copying successfully and is fully encrypted.
🛠️ One-Time Project Delivery: A forensic health check of your current backup logs to diagnose past silent failures, resolve configuration conflicts, and verify proper end-to-end encryption.
🛡️ Monthly Retainer Management: Manual monthly auditing. Automated backup notifications are notoriously unreliable; they can stop working entirely or report a "Success" even when specific critical files are skipped. Monthly manual verification is the only way to prove you have a real "life raft" before a crisis hits.
____________________________________________
Level 3 — Isolated Disaster Recovery Testing:
What’s Included: Continuous monthly restore script validation paired with semi-annual (twice-a-year) live, hands-on file recovery tests in an isolated test environment.
Why You Want This: A backup is completely useless if you cannot open the files when a crisis hits. Twice a year, we perform a real-world fire drill: pulling down backup data, restoring it, and proving you can recover in hours rather than weeks.
🛠️ One-Time Project Delivery: A live, standalone disaster recovery simulation—downloading your existing data backups into an isolated sandbox to test readability, speed, and recovery configurations.
🛡️ Monthly Retainer Management: Continuous verification and scheduled testing. Over time, stored files can become corrupted, or new software configurations can make recovered files unreadable. Regular testing ensures that your recovery scripts and processes remain fully functional under your current software setup.
-
Equipping your employees to spot, dodge, and report incoming social engineering threats, while embedding actionable, frontline emergency protocols.
____________________________________________
Level 1 — Safe Habits Workbook & "First 5 Minutes" Flowchart:
What’s Included: Delivery of a customized "Top-5 Cyber Habits" workbook tailored to your business operations, paired with an emergency "First 5 Minutes" triage cheat sheet for employees.
Why You Want This: Employees want to keep your business safe but need simple, realistic rules. This workbook gives your team a clear, jargon-free reference sheet for safe passwords, Wi-Fi usage, and suspicious activity, alongside a definitive protocol of what to do if they suspect an active breach (e.g., immediate network disconnection rules).
🛠️ One-Time Project Delivery: Drafting and delivering a bespoke corporate cybersecurity safety manual and a custom emergency triage poster tailored to your physical office layout.
🛡️ Monthly Retainer Management: Continuous content updates. Cybercriminals change their tactics constantly. A workbook detailing threats from last year won't protect your staff from modern scams, such as AI-generated voice cloning. Monthly updates ensure your training and reporting flowcharts match the real-world threats your team is facing today.
____________________________________________
Level 2 — Live Threat Playbook Training & Reporting Drills:
What’s Included: Bi-annual interactive, live threat scenario workshops with your staff (remote or in-person) designed to test employee reporting times.
Why You Want This: Boring compliance videos don't stop hackers. In this live, engaging workshop, we show your staff exactly what real-world, localized invoice scams look like and actively drill them on our rapid, "1-minute" incident notification protocol so security issues are flagged instantly.
🛠️ One-Time Project Delivery: Hosting a single, highly engaging live or virtual cybersecurity training workshop for your current staff, paired with an immediate post-training reporting drill.
🛡️ Monthly Retainer Management: Ongoing training and lightweight monthly bulletins. Human memory naturally fades over time. Employees trained six months ago are statistically far more likely to click a malicious link today. Continuous monthly check-ins ensure that safe security habits and rapid reporting paths remain top-of-mind.
____________________________________________
Level 3 — Live Playbooks & Tabletop Capstone Simulation:
What’s Included: An annual interactive Incident Response tabletop simulation exercise customized for your leadership team.
Why You Want This: When a cyber crisis happens, panic leads to expensive mistakes. In this simulated, facilitated "fire drill," we walk your leadership through a mock ransomware attack in real time to stress-test your communication paths, legal liabilities, and operations before a real hacker is on your network.
🛠️ One-Time Project Delivery: Coordination and facilitation of a standalone crisis simulation exercise for your executive team, concluding with an extensive executive summary of gaps in your response structure.
🛡️ Monthly Retainer Management: Continuous playbook alignment and optimization. Your internal operations, vendors, banking procedures, and staff roles change. If your emergency communication list or leadership escalation paths are out of date when an incident occurs, response times stall. Monthly backend coordination keeps your crisis playbook aligned with your actual operational structure.
-
Systematically auditing your local office networks and website for technical flaws before automated hacker bots find them.
____________________________________________
Level 1 — External Web Presence Check:
What’s Included: Monthly automated external checks of your primary company website security certificate, backed by an annual high-level, deep-dive external check of your domain configuration.
Why You Want This: If your website has security flaws, hackers can deface it, redirect your customers, or steal data. We scan your website annually to ensure there are no obvious, invitation-like warnings exposed to the public.
🛠️ One-Time Project Delivery: A rigorous external vulnerability audit of your customer-facing website code, SSL configuration, and domain naming registry settings.
🛡️ Monthly Retainer Management: Continuous plugin and theme monitoring. Websites are built on plugins, themes, and code libraries that are updated continuously. A secure website plugin today can become a massive security vulnerability tomorrow when a new exploit is published. Monthly auditing identifies these risks before search engines flag your site as unsafe.
____________________________________________
Level 2 — Bi-Annual Automated External Scanning:
What’s Included: Continuous monthly firewall configuration verification, paired with scheduled bi-annual (twice-a-year) automated vulnerability scans against your office firewall and public network infrastructure.
Why You Want This: Hacker bots scan small businesses daily. We run scheduled scans twice a year against your firewalls to locate and patch weaknesses before malicious scanners exploit them.
🛠️ One-Time Project Delivery: A comprehensive configuration audit of your perimeter router and firewall appliances, followed by a targeted network penetration scan.
🛡️ Monthly Retainer Management: Continuous configuration verification. Firewalls and routers occasionally receive background updates from your internet provider that can accidentally reset security rules to factory defaults. Monthly oversight ensures your boundary defenses remain tightly locked in between major scheduled scans.
____________________________________________
Level 3 — Onsite Network Scanning & Verification:
What’s Included: Monthly internal network device inventory tracking, anchored by quarterly onsite internal network vulnerability scans with manual cleanup of technical false alarms.
Why You Want This: If a hacker gets inside your network via an accidental employee click, they will hunt for weak, unpatched machines. Every quarter, we scan your office network and give you a simple, prioritized "Quick-Win Fix List" to hand straight to your IT company.
🛠️ One-Time Project Delivery: An intensive onsite network hardware audit—mapping every connected device, locating hidden endpoints, and scanning internal systems for unpatched technical flaws.
🛡️ Monthly Retainer Management: Device tracking. Employees connect personal devices, smart TVs, local printers, or guest hardware to your office Wi-Fi every single month. These unmanaged devices introduce fresh technical vulnerabilities. Monthly internal monitoring ensures no new, insecure devices have been set up on your secure network.
-
Translating complex technical metrics into clear compliance alignment and executive-level business context, helping leadership direct resources with certainty.
____________________________________________
Level 1 — Annual Health Check & Posture Scorecard:
What’s Included: Continuous monthly tracking of key risk indicators against industry-standard frameworks (ISO 27001, SAFETAG, and the Essential Eight), culminating in an annual comprehensive audit of your operations to generate your official, updated "Cyber Health Score."
Why You Want This: You cannot manage what you do not measure. Once a year, we run a baseline check of your operations against leading frameworks and award a clear "Cyber Health Score," showing you where you stand and proving your security investments are working.
🛠️ One-Time Project Delivery: A formal, standalone cybersecurity compliance assessment mapped directly to ISO 27001 or Essential Eight controls, delivering a one-time baseline Cyber Health Score card.
🛡️ Monthly Retainer Management: Incremental tracking. Waiting an entire year for a scorecard update leaves you completely blind to deteriorating security habits or posture drift. Monthly risk-tracking builds your report incrementally, giving you real-time visibility and eliminating the stress of annual "audit surprises."
____________________________________________
Level 2 — Semi-Annual Health Check & Posture Roadmap:
What’s Included: Continuous monthly progress tracking of your action items, paired with semi-annual (twice-a-year) comprehensive posture audits and scorecard updates.
Why You Want This: Security isn't a one-time project. Your business grows, you buy new software, and habits drift. Every six months, we update your score and adjust your plan, keeping you safe without wasting money on unneeded technology.
🛠️ One-Time Project Delivery: Building a 12-month strategic security remediation roadmap based on an immediate, mid-level procedural audit.
🛡️ Monthly Retainer Management: Active roadmap pacing. If your security roadmap is static, it cannot pivot when your business adopts new tools or launches new services. Monthly tracking updates your progress continuously, ensuring your active roadmap always matches your real-world technology footprint.
____________________________________________
Level 3 — Quarterly Health Checks & Risk Register Governance:
What’s Included: Continuous monthly updates to your backend business threat profiles, anchored by quarterly deep-dive executive briefings and active maintenance of your formal Business Risk Register.
Why You Want This: This is your security steering wheel. Every quarter, we hold an executive briefing to review your actual business threats, legal compliance pressures (such as state-level PII laws or vendor requirements), and update your official Risk Register so leadership can make risk-optimized, calculated decisions.
🛠️ One-Time Project Delivery: Establishing a formal, legally viable corporate Business Risk Register built from scratch to pass vendor compliance audits.
🛡️ Monthly Retainer Management: Dynamic threat profiling. Business risks develop constantly due to external events—such as a local supplier suffering a major breach or a shift in state regulatory demands. Monthly backend oversight keeps your official Risk Register razor-sharp so your quarterly executive updates are accurate, timely, and actionable.
-
Direct, prioritized access to a certified cybersecurity expert for strategic business decisions and rapid, coordinated execution of your Incident Response Plan (IRP).
____________________________________________
Level 1 — Priority Email Support:
What’s Included: Prioritized email response (within business hours) for active monthly reviews of suspicious emails, files, or login notices.
Why You Want This: When an employee receives a highly realistic email asking for a wire transfer or login, they shouldn't guess if it's safe. They can forward it directly to us for rapid, expert evaluation.
🛠️ One-Time Project Delivery:(Not applicable as a standalone project—requires a continuous retainer relationship).
🛡️ Monthly Retainer Management: Active availability. Suspicious threats are highly unpredictable. Paying a monthly support fee ensures that our expert response team is actively available and on-call to evaluate and contain threats within minutes of them reaching your inbox, rather than waiting for standard booking queues.
____________________________________________
Level 2 — Strategic Advisory & Virtual Consultations:
What’s Included: Dedicated monthly 1-on-1 virtual consulting sessions to assist with vendor security questionnaires, hardware evaluation, or regulatory compliance reviews.
Why You Want This: Never make expensive technology or software decisions in the dark. We sync monthly to answer questions, check vendor security demands, and ensure you have a trusted security advisor in your corner.
🛠️ One-Time Project Delivery: A single, focused consulting block (e.g., helping your team navigate and complete a critical, high-stakes vendor security questionnaire to land a major contract).
🛡️ Monthly Retainer Management: Proactive strategic alignment. Operational business decisions happen continuously. Whether you are signing a contract with a new customer software provider or upgrading office hardware this month, regular advisory sessions ensure these adjustments do not expose your data.
____________________________________________
Level 3 — Priority Retainer, Active Playbook Maintenance & Remote Incident Triage:
What’s Included: Continuous monthly Incident Response Plan (IRP) playbook maintenance, paired with priority 24/7 remote emergency triage support dedicated exclusively to containing active, network-wide security breaches.
Why You Want This: If the worst happens, you have an expert ready to step in immediately to anchor your defense and execute your customized IRP. For businesses without a dedicated IT staff, we act as your emergency responder—initiating remote containment protocols, isolating compromised systems to stop the spread of infection, and preserving vital digital logs to secure your cyber insurance claims.
🛠️ One-Time Project Delivery:(Not available standalone. Emergency response and containment are reserved strictly for retainer clients to maintain system familiarity and immediate queue bypassing).
🛡️ Monthly Retainer Management: Immediate operational response. Emergency response is only possible when we intimately know your digital layout. Our team actively updates your emergency contact chains, vendor phone lists, and system architecture plans every month. Your monthly retainer guarantees our immediate availability to step into the trenches during a crisis, completely bypassing standard client queues.
📝 Note: While initial breach containment and triage are fully covered under this Level 3 retainer, extensive post-incident network rebuilding or extensive physical hardware replacement is scoped and billed separately to ensure dedicated resource allocation.
We’re Here to Help
Have a question, want a second opinion, or not sure where to start? Reach out anytime. We’ll help you understand your options and the best next steps for your business. 507.450.3124 | andrew.m@ammcybersolutions.com
Schedule Your Free Discovery Call
Book a quick 15-minute call to talk through your current setup, your biggest concerns, and what protection makes the most sense for your business. No pressure. Just clear answers and practical next steps.

