WarrenBarr
SEC-01
Advisories
Published findings
OPS-02
Methodology
How an engagement runs
ENG-03
IT & Dev
Build and administer
ARM-04
Software
Tooling I wrote
MSP-05
MSSP
Flat-rate managed
REC-06
Case Studies
Work, in full
WEB-07
Websites
Sites that convert
SUP-08
Gear
Coming soon
DOC-09
Doctrine
What I will not do
WHO-10
About
Who you'd be hiring
Work with me

What do you actually need?

Pick the one that fits. Each one tells you how it works, what it costs, and what you get — before you fill in anything.

You don't want a security vendor. You want one person who handles it.

Most businesses I talk to are not shopping for cybersecurity. They're tired of having four numbers for four problems, of nobody owning it when something breaks, and of an invoice arriving every time they ask a question. That's the actual job. I run your IT, I watch it, and most of the time I fix things before you know they broke.

Being direct about it: most of my clients could not tell you what an EDR is, and they don't need to. They can tell you their laptop works, new hires get set up on day one, the backups have actually been tested, and when something goes wrong one person picks up the phone.

The security is real and it's why nothing has gone badly wrong yet. But it's a property of the work, not the reason to hire me.

Most of what I fix, you never hear about.

This is the part that's hard to sell because it's invisible when it's working. I'm monitoring your machines, so when something goes wrong I usually know before you do — and most of the time I've already dealt with it by the time you'd have noticed. You find out in the monthly summary, if you read it.

How it goes with everyone else

01Something breaks quietly. Nobody notices.
02It gets worse for a few days, or weeks.
03Eventually it's bad enough that you notice.
04You stop what you were doing and call someone.
05You wait. Maybe until Monday.
06You get an invoice for the privilege.

How it goes here

01Something breaks quietly. I get the alert.
02I look at it, usually the same hour.
03Eventually you notice
04You stop what you were doing and call
05You wait until Monday
06You read about it in the monthly summary. Or you don't.

A backup that silently stopped running six weeks ago is the thing that ends businesses — and it is exactly the kind of problem nobody notices until the day they need it. That's what you're actually paying for: not the fixing, the knowing.

Two ways that works

Priced per device, per month. No setup fee, no contract term, 30 days' notice to cancel. Move the slider and you'll see roughly what it costs — no form required to find out.

Monitored
$100 /device /mo
Security eyes only, for teams with their own IT. I watch, detect, and tell you what I'd fix first — your people do the fixing.
Fully Managed — most picked
$300 /device /mo
Not more security — the whole IT function. Accounts, machines, patching, backups, the printer that won't print. All mine to run, with incident response included. No emergency rate.
12
$3,600 per month, all in IT administration and incident response, included. That number doesn't change in the month something goes wrong — which is the whole point.

What "a project" usually means here

One person scopes it, builds it, secures it and hands it over — instead of a vendor for the network, a vendor for the servers and a third party nobody can reach when it breaks.

Network & infrastructureDesign and build from the rack up. Segmentation, VLANs, firewalls, wireless, remote access — laid out so it can be defended, not just so it works on day one.
Servers & systemsOn-prem, cloud or both. Domain services, file and application servers, virtualisation, backup that gets restored rather than assumed.
Databases & dataSchema design, migration off whatever it is currently living in, access control that reflects who should actually see what.
Physical security systemsAccess control, cameras, alarms — specified and installed by someone who spends the rest of his time defeating them.
AI deploymentLocal or hosted models, agent tooling, retrieval over your own documents. Deployed with the credential handling and network position thought through first — which, as my advisories keep showing, is where these go wrong.
Software & webCustom applications, booking systems, internal tools, sites. Written from an empty folder, owned by you, hosted in your name.

Fixed scope, fixed number, agreed before anything starts. No hourly meter and no discovery phase that bills while nothing ships. If the honest answer is that you need less than you asked for, I will tell you that instead.

A real engagement, run the way an adversary would

Most "penetration tests" sold to businesses this size are an automated scan with a PDF wrapped around it. That is not what this is. Engagements follow my published methodology — the T-ALC, twelve phases sequenced by dependency rather than convention, available to read in full before you hire me.

Physical infiltrationMy specialisation. Badge cloning, lock bypass, tailgating, drop devices, and simply walking in wearing the right thing and carrying the right object. Most organisations have spent everything on the network perimeter and nothing on the door — and the door is usually faster.
Ghost employee internal assessmentI operate inside your environment as though I were a hire nobody vetted — the contractor, the temp, the person who was given a badge and a laptop and never questioned. It answers the question that actually matters: what can somebody already inside do before anyone notices?

Those are where I go deepest. The rest of the lifecycle is available and gets run when the scope calls for it:

External & networkWireless / RFSocial engineering Web applicationActive DirectoryPrivilege escalation Lateral movementExfiltration simulationDetection validation Remediation & retest

Engagements run announced or unannounced. Announced lets us compare what I did against what your defenders actually saw, which is usually the more useful output. Unannounced tells you the harder truth. Either way you get the record of what worked, in the order it worked, and what to fix first.

If you're mid-incident, don't fill in a form.

Call. Every hour matters during an active compromise. If I can't pick up, leave a voicemail saying it's an incident and I'll call straight back.

(713) 882-0902

Don't power anything off — that destroys memory evidence. Disconnect from the network instead.

These are the reasons people actually call. Pick whatever's true.
I reply personally, usually same day
No pitch deck, no discovery call with a salesperson
If you don't need me, I'll say so
You'll hear from me before you have to call

Rather just talk? (713) 882-0902  ·  warren@barr-cyber.com  ·  Kalispell, Montana — and remote.