WarrenBarr
SEC-01
Advisories
Published findings
OPS-02
Methodology
How an engagement runs
ENG-03
IT & Dev
Build and administer
ARM-04
Software
Tooling I wrote
MSP-05
MSSP
Flat-rate managed
REC-06
Case Studies
Work, in full
WEB-07
Websites
Sites that convert
SUP-08
Gear
Coming soon
DOC-09
Doctrine
What I will not do
WHO-10
About
Who you'd be hiring
[ MANAGED SECURITY // FLATHEAD VALLEY & REMOTE ]

You Have A Business To Run.
Not A Security Program.

Most small businesses don't get breached because they made a bad decision. They get breached because nobody was watching, and the person who was supposed to be watching bills by the hour and answers on Monday.

I do this differently. You pay a flat rate per device. I run your security, I administer your IT, and when something goes wrong, I handle it — not "I'll send a quote." Handle it.

[ THE PROBLEM // HOW IT ACTUALLY GOES ]

The Break-Fix Trap

The standard arrangement punishes you exactly when you're most vulnerable.
01

Nobody is actually watching

You have antivirus, so you think you're covered. Antivirus catches known malware. It does not catch a valid login from a stolen password at 3am, an admin account quietly created last Tuesday, or your backups silently failing for six weeks.

02

The meter starts when the fire does

Something breaks. Now you're negotiating an hourly rate during the worst week of your year, with someone who benefits from it taking longer. Incident response billed by the hour is a conflict of interest, and everybody knows it.

03

You end up doing IT yourself

Because calling costs money, you don't call. You defer the patch, you reuse the password, you leave the old employee's account active. Not out of ignorance — out of a completely rational desire to not get invoiced again.

Every one of those is a pricing problem wearing a security costume. So I fixed the pricing.

[ THE PLANS // FLAT RATE, PER DEVICE, PER MONTH ]

Two Ways To Work With Me

Priced per device, billed monthly, no setup fee, no long-term contract. Cancel with 30 days' notice.
Monitored
$100 /device / month
For teams with their own IT who want a real set of eyes.
  • 24/7 monitoring across endpoints, identity, and network
  • Real detection — behavior and credential abuse, not just known-malware signatures
  • Alerts that reach a human — me, with context, not a dashboard notification nobody reads
  • Monthly report in plain English: what happened, what I'd fix, what I'd fix first
  • Quarterly posture review — the gaps, ranked by what an attacker would actually use
  • Vulnerability and patch visibility across your fleet
I find it and tell you. Your team does the fixing — or you call me and we go hourly.
Start with Monitored
Most clients pick this
Fully Managed
$300 /device / month
For teams who want to stop thinking about IT and security entirely.

Everything in Monitored, plus:

  • I administer your IT. Accounts, machines, patching, backups, permissions, new hires, departures. It's mine to run.
  • Your IT problems are my problems. Laptop won't boot, printer's down, email is bouncing, VPN broke — you call me, I fix it. Not billable. Included.
  • Incident response is included. If something happens, I respond. Contain, investigate, evict, recover, and write it up. No emergency rate. No quote. No meter.
  • Hardening, done — not recommended. I don't hand you a list of findings. I close them.
  • Backups I actually test — a backup you've never restored is a rumor, not a backup.
  • Direct line to me. Not a ticket queue. Not a level-one script. Me.
You pay the plan. You're covered. I take care of it.
Get Fully Managed →

Fewer than 5 devices, or a mixed environment? The per-device number bends. Tell me what you've got and I'll quote it straight.

[ THE PREMIUM TIER // IN PLAIN ENGLISH ]

What "Covered" Actually Means

This is the part everyone gets vague about, so here it is with no hedging.

On Fully Managed, when it breaks — I fix it. Included.

  • A machine is compromised → I respond. Contain it, find out how, evict them, rebuild it, tell you the truth about what happened.
  • Ransomware hits a share → I run the recovery. Isolate, restore from tested backups, close the hole they came through.
  • Someone phishes an employee → I take it from there. Kill the sessions, reset the credentials, check what they touched, check what else they touched.
  • A server dies at 4pm on a Friday → that's my Friday now, not yours.
  • Day-to-day IT that isn't security at all → still mine. That's the point of the tier.

No emergency rate. No "that's out of scope." No invoice arriving after the worst week of your year.

And the honest boundary — because a promise without edges is a lie

This is a service plan, not an insurance policy. What's included is my work: my time, my response, my expertise, for as long as it takes, at the flat rate you're already paying.

What it isn't: I don't reimburse financial losses, pay ransoms, cover third-party costs, or replace hardware. If you want a dollar figure paid out after a breach, that's cyber insurance, and it's a separate product from a separate company — I'll happily help you get one, and being on this plan usually makes you cheaper to insure.

What I'm selling is simpler and, for most businesses, the thing that was actually missing: somebody competent whose job it is to make sure it doesn't happen, and to handle it if it does — without reaching for the invoice book first.

[ DAY ONE // WHAT YOU ACTUALLY GET ]

What Signing Up Gives You

Not a login to a dashboard you'll never open. Concrete things, on a schedule.
Week 1

I learn your business

Every device, account, and system inventoried. What matters, what would hurt if it stopped, who has keys to what. Most clients find out here that they have accounts they forgot existed.

Week 1–2

Monitoring goes live

Coverage on endpoints, identity, and network. Backups verified — actually restored, not just green-checked. Baseline established, so abnormal means something.

Week 2–4

I close the obvious doors

Default and stale accounts, dormant admin rights, unpatched externals, exposed services, missing MFA. On Fully Managed I don't send you the list — I do it and tell you it's done.

Ongoing

Someone is watching

Alerts get triaged by a human who knows your environment. On Fully Managed, they also get resolved. You find out from a summary, not from a customer.

Monthly

A report you can read

What happened, what I did, what changed, what I'm doing next. Written for an owner, not an auditor. If nothing happened, it says that too.

Always

One phone number

Mine. You will never explain your environment to a stranger reading a script, and you will never be told your problem isn't covered by your plan.

[ WHY ME // AN UNUSUAL ARGUMENT ]

You Want The Person Who Breaks In,
Running The Defense

My background is offensive — finding the way in. That is not a fun fact; it is the entire reason this works.

A defender who has never run an attack builds what the vendor brochure told them to build. They cover the front door beautifully and leave the service account with a five-year-old password and domain admin. I know that, because that account is how I get in.

When I harden your environment, I'm not working from a compliance checklist. I'm working from the list of things that have actually worked on people like you. I published a set of them — read the advisories and you'll see the shape of it.

Solo — and that's a feature

You get the senior person. Every time. Not a level-one tech reading a decision tree, not a rotating cast who each need your environment explained again. The person who assesses you is the person who defends you.

I'm capacity-limited on purpose

I take a small number of Fully Managed clients, because the promise — I will handle it — is only true if I have the room to handle it. When I'm full, I'll tell you I'm full rather than sell you a promise I can't keep.

Local, and actually here

Kalispell and the Flathead Valley, with remote coverage beyond it. If a machine has to be physically touched, someone can physically touch it.

[ THE PLATFORM // UNDER THE HOOD ]

Running On Tooling I Wrote Myself

Both plans run on Omniscient — the MSSP platform I built, and the one I use on my own clients.

Most providers at this size resell somebody else's stack. When it misses something, they're stuck: they can't see inside it, and they can't change it. I'm not stuck. When I find a gap in coverage, I go fix the platform — and every client I have gets that fix.

You don't have to care about any of this. You will never be asked to log into it. It's mentioned only because it's the reason I can make the promise on the Fully Managed tier without hedging: I control the whole chain, from what gets detected to who picks up the phone.

[ STRAIGHT ANSWERS // THE THINGS PEOPLE ASK ]

Before You Reach Out

$300 a device sounds like a lot.

Compare it to the real alternative, not to zero. Fifteen devices on Fully Managed is $4,500 a month — less than a junior IT hire, who wouldn't be able to run incident response anyway. And that number does not move when something goes wrong. One serious incident handled hourly — forensics, recovery, rebuild — runs well past a year of this plan. The whole point is that the bad month costs the same as the good month.

What stops you from just... not showing up when it matters?

Reputation and capacity. I'm a named individual in a small valley with a public advisory record, and I deliberately cap how many Fully Managed clients I take so the promise stays true. A provider who oversells this tier and then can't answer the phone is finished, and I know it.

Is there any incident so bad it stops being included?

My labor is included, period — I don't stop responding because a job got hard. What's outside my scope is money: I don't pay ransoms, cover your losses, or replace hardware. If an incident requires outside counsel, a forensics firm for a legal proceeding, or a data-breach notification service, those are real third-party costs and I'll say so up front — and I'll manage them with you.

We already have an IT guy.

Then Monitored is probably your tier — I watch, they fix. That works well. Fully Managed is for people who'd rather that whole function just belonged to somebody, and be done with it.

What if we're already breached and don't know it?

Then we'll find out in the first two weeks, and it's the best money you'll ever spend. It happens. I don't charge extra for what I discover during onboarding — that would be a perverse incentive, and it would make you not want me to look.

Are you going to lock us in?

No contract term, 30 days' notice, and your data and documentation are yours to take. If I'm only keeping you by making it painful to leave, I've already lost.

Stop Managing It Yourself

Tell me how many devices you have and what's keeping you up. I'll tell you which tier you actually need — including if that's neither one.

No pitch deck, no discovery call with a salesperson, no pressure. You'll be talking to the person who'd be doing the work.

Barr Cyber LLC · Kalispell, Montana · Serving the Flathead Valley and remote clients nationwide