Home / Services

Capabilities  //  Scope  //  Deliverables

Security services that actually close gaps.

We don't advise and disappear. Every engagement ends with a clear picture of your exposure, evidence for every finding, and a concrete path forward that someone is accountable for.

Scoped for organizations that can't afford theater.

Each engagement is fixed in scope and delivered by the same operator who assessed your environment. No handoffs to junior analysts, no findings you can't reproduce.

[ 01 ]

Network Security Assessment

What is a network security assessment?

A network security assessment is a hands-on evaluation of your network's exposure — external footprint, internal segmentation, firewall rules, and wireless — combined with penetration testing to verify which weaknesses are actually exploitable. Sparrowhawk delivers findings ranked by real business impact, with reproduction steps and a remediation plan, typically within two to four weeks depending on environment size.

Your perimeter has gaps. Most organizations don't find out until someone else does. We map your attack surface the way an attacker would, then test whether your defenses actually hold. What you get back is a prioritized remediation plan ranked by real exploitability, not a 200-page PDF that collects dust on a shared drive.

Penetration Testing Vulnerability Scanning Firewall Audit Segmentation Review
What's Included
  • External and internal penetration testing
  • Authenticated and unauthenticated vulnerability scanning
  • Firewall and ACL rule-set audit
  • Network segmentation and VLAN boundary review
  • Wireless security assessment
  • Egress filtering and data-exfiltration path analysis
What You Walk Away With
  • Ranked findings tied to actual business impact
  • Evidence and reproduction steps for every finding
  • Remediation plan sequenced by risk and effort
  • Executive summary your board can read
  • Re-test of critical findings after remediation
[ 02 ]

Infrastructure Security Hardening

What does infrastructure security hardening include?

Infrastructure security hardening is the process of closing configuration-level weaknesses across servers, endpoints, and directory services. Sparrowhawk's hardening engagements cover Active Directory privilege tiering, server and endpoint baselines, patch governance, service account hygiene, and validation that your logging and detection actually fire during an attack — verified by testing, not assumed.

Antivirus is not a security program. Your servers, endpoints, and directory services are where an intrusion becomes a breach — and where most environments are quietly misconfigured. We harden at the configuration level, with detection coverage that actually fires when something goes wrong instead of logging quietly into a void.

Active Directory Endpoint Hardening Patch Governance Privilege Management
What's Included
  • Active Directory tiering and privilege boundary design
  • Domain controller and server baseline hardening
  • Endpoint configuration and EDR coverage validation
  • Patch governance and enforcement workflow
  • Service account and credential hygiene audit
  • Logging, alerting, and detection gap analysis
What You Walk Away With
  • Hardened baselines documented and repeatable
  • Privilege model that survives staff turnover
  • Verified detection coverage — tested, not assumed
  • Patch process with accountability built in
  • Configuration drift monitoring recommendations
[ 03 ]

Cyber Insurance Compliance

How do I prove compliance with my cyber insurance policy?

Proving cyber insurance compliance requires documented evidence that each control named in your policy — MFA, immutable backups, endpoint protection, and a tested incident response plan — is actually deployed and working. Sparrowhawk audits your environment line by line against your specific policy language and produces an underwriter-ready evidence package, which is what determines whether a claim is paid or denied.

Answering “yes” on the application is easy. Proving it at claim time is where policies get denied. We audit your environment against the specific control language in your policy and hand you the evidence your underwriter will accept — before you need it.

MFA Enforcement Gap Assessment Evidence Documentation Policy Alignment
What's Included
  • Line-by-line policy control mapping
  • MFA coverage verification across all access paths
  • Backup immutability and restore testing
  • Endpoint protection deployment validation
  • Incident response plan review and tabletop exercise
  • Documented evidence collection for each control
What You Walk Away With
  • Gap report against your actual policy language
  • Underwriter-ready evidence package
  • Remediation roadmap for any failed controls
  • Renewal support and attestation documentation
  • Reduced risk of claim denial on a technicality
[ 04 ]

Virtual CISO & Security Retainer

What does a virtual CISO do, and when do you need one?

A virtual CISO provides senior security leadership on a fractional basis — owning security posture, policy governance, vendor risk decisions, and incident response readiness without a full-time executive salary. Organizations typically engage one when they have compliance or contractual obligations but no internal security owner. Sparrowhawk delivers this on a monthly retainer, reviewed quarterly as needs change.

Most small and mid-size organizations need security judgment more often than they need a full-time executive — someone who owns the posture, sets priorities, and is accountable when a decision has to be made.

Security Governance Vendor Risk IR Readiness Monthly Retainer
What's Included
  • Ongoing threat posture management and review
  • Security policy authorship and governance
  • Third-party and vendor risk assessment
  • Incident response readiness and tabletop facilitation
  • Security roadmap and budget planning
  • Board and leadership reporting
What You Walk Away With
  • A named security owner, not a ticket queue
  • Quarterly posture review with measurable progress
  • Policy set that holds up under audit
  • Vendor risk decisions made before contracts are signed
  • Priority access during an active incident
[ 05 ]

Cloud Security — Microsoft 365 & Entra ID

How do I secure a Microsoft 365 and Entra ID tenant?

Securing Microsoft 365 and Entra ID means enforcing Conditional Access and MFA across every access path, shutting down legacy authentication, auditing role assignments and app consents, governing external sharing, and verifying that departed employees retain no access. Sparrowhawk performs this as a security engagement rather than a managed service, and most tenants are found to have licensed protections that were never switched on.

You're paying for Microsoft 365. A significant portion of what you're paying for is misconfigured or switched off. We verify that former employees aren't still reaching your data from an unmanaged device three states away.

M365 Hardening Conditional Access Entra ID Audit Identity Governance MFA Enforcement Offboarding Verification
What's Included
  • M365 tenant-wide security configuration review
  • Conditional Access policy design and enforcement
  • Entra ID role, permission, and app-consent audit
  • Legacy authentication identification and shutdown
  • Guest and external sharing governance
  • Offboarding verification and orphaned access cleanup
What You Walk Away With
  • Tenant hardened against the attacks actually used
  • Conditional Access that blocks without breaking work
  • Full inventory of who can reach what, and why
  • Confirmed removal of stale and orphaned access
  • Licensing you're already paying for, actually enabled

Fixed price. Written scope.

How much does a security assessment cost?

Sparrowhawk prices every assessment as a fixed fee against a written scope, agreed before any work begins. Cost is driven by environment size — user count, number of sites, and whether operational technology is in scope — not by hourly billing. Virtual CISO and security retainer work is billed monthly and reviewed quarterly. Request a briefing for a scoped quote.

[ Fixed Fee ]

Assessments & Audits

One price, agreed in writing before work starts. It does not change unless you change the scope in writing. Covers testing, reporting, the findings walkthrough, and re-testing of critical items.

[ Monthly Retainer ]

Virtual CISO

A recurring monthly fee scaled to your organization's size and obligations, reviewed quarterly. Includes priority access during an active incident.

[ No Cost ]

Initial Briefing

The first conversation is free and carries no obligation. If an engagement doesn't make sense for you, we say so — including pointing you elsewhere when that's the right call.

Four phases. No surprises.

What happens during a Sparrowhawk security engagement?

A Sparrowhawk engagement runs in four phases: a no-cost technical briefing, a written scope and fixed-price agreement with defined rules of engagement, hands-on assessment with critical findings escalated immediately by phone, and a final report with ranked findings, evidence, an executive summary, and re-testing of critical items.

[ 01 ]

Briefing

A technical conversation about your environment, your obligations, and what's actually keeping you up at night. No cost, no pitch.

[ 02 ]

Scope & Agreement

Written scope, fixed price, defined timeline, and rules of engagement signed before anyone touches a system.

[ 03 ]

Assessment

Hands-on testing and review. Critical findings are escalated immediately — you don't wait for the report.

[ 04 ]

Report & Remediation

Ranked findings with evidence, an executive summary, and a walkthrough. Re-testing of critical items included.

If your network is worth protecting,
it's worth an honest assessment.

We provide technical security briefings for business owners, operations leaders, and IT teams who want a straight answer about where they stand. No sales pitch.

Request a Security Briefing

info@sparrowhawktech.com  ·  sparrowhawktech.com