I do this differently. You pay a flat rate per device. I run your security, I administer your IT, and when something goes wrong, I handle it — not "I'll send a quote." Handle it.
You have antivirus, so you think you're covered. Antivirus catches known malware. It does not catch a valid login from a stolen password at 3am, an admin account quietly created last Tuesday, or your backups silently failing for six weeks.
Something breaks. Now you're negotiating an hourly rate during the worst week of your year, with someone who benefits from it taking longer. Incident response billed by the hour is a conflict of interest, and everybody knows it.
Because calling costs money, you don't call. You defer the patch, you reuse the password, you leave the old employee's account active. Not out of ignorance — out of a completely rational desire to not get invoiced again.
Every one of those is a pricing problem wearing a security costume. So I fixed the pricing.
Everything in Monitored, plus:
Fewer than 5 devices, or a mixed environment? The per-device number bends. Tell me what you've got and I'll quote it straight.
No emergency rate. No "that's out of scope." No invoice arriving after the worst week of your year.
This is a service plan, not an insurance policy. What's included is my work: my time, my response, my expertise, for as long as it takes, at the flat rate you're already paying.
What it isn't: I don't reimburse financial losses, pay ransoms, cover third-party costs, or replace hardware. If you want a dollar figure paid out after a breach, that's cyber insurance, and it's a separate product from a separate company — I'll happily help you get one, and being on this plan usually makes you cheaper to insure.
What I'm selling is simpler and, for most businesses, the thing that was actually missing: somebody competent whose job it is to make sure it doesn't happen, and to handle it if it does — without reaching for the invoice book first.
Every device, account, and system inventoried. What matters, what would hurt if it stopped, who has keys to what. Most clients find out here that they have accounts they forgot existed.
Coverage on endpoints, identity, and network. Backups verified — actually restored, not just green-checked. Baseline established, so abnormal means something.
Default and stale accounts, dormant admin rights, unpatched externals, exposed services, missing MFA. On Fully Managed I don't send you the list — I do it and tell you it's done.
Alerts get triaged by a human who knows your environment. On Fully Managed, they also get resolved. You find out from a summary, not from a customer.
What happened, what I did, what changed, what I'm doing next. Written for an owner, not an auditor. If nothing happened, it says that too.
Mine. You will never explain your environment to a stranger reading a script, and you will never be told your problem isn't covered by your plan.
A defender who has never run an attack builds what the vendor brochure told them to build. They cover the front door beautifully and leave the service account with a five-year-old password and domain admin. I know that, because that account is how I get in.
When I harden your environment, I'm not working from a compliance checklist. I'm working from the list of things that have actually worked on people like you. I published a set of them — read the advisories and you'll see the shape of it.
You get the senior person. Every time. Not a level-one tech reading a decision tree, not a rotating cast who each need your environment explained again. The person who assesses you is the person who defends you.
I take a small number of Fully Managed clients, because the promise — I will handle it — is only true if I have the room to handle it. When I'm full, I'll tell you I'm full rather than sell you a promise I can't keep.
Kalispell and the Flathead Valley, with remote coverage beyond it. If a machine has to be physically touched, someone can physically touch it.
Most providers at this size resell somebody else's stack. When it misses something, they're stuck: they can't see inside it, and they can't change it. I'm not stuck. When I find a gap in coverage, I go fix the platform — and every client I have gets that fix.
You don't have to care about any of this. You will never be asked to log into it. It's mentioned only because it's the reason I can make the promise on the Fully Managed tier without hedging: I control the whole chain, from what gets detected to who picks up the phone.
$300 a device sounds like a lot.
Compare it to the real alternative, not to zero. Fifteen devices on Fully Managed is $4,500 a month — less than a junior IT hire, who wouldn't be able to run incident response anyway. And that number does not move when something goes wrong. One serious incident handled hourly — forensics, recovery, rebuild — runs well past a year of this plan. The whole point is that the bad month costs the same as the good month.
What stops you from just... not showing up when it matters?
Reputation and capacity. I'm a named individual in a small valley with a public advisory record, and I deliberately cap how many Fully Managed clients I take so the promise stays true. A provider who oversells this tier and then can't answer the phone is finished, and I know it.
Is there any incident so bad it stops being included?
My labor is included, period — I don't stop responding because a job got hard. What's outside my scope is money: I don't pay ransoms, cover your losses, or replace hardware. If an incident requires outside counsel, a forensics firm for a legal proceeding, or a data-breach notification service, those are real third-party costs and I'll say so up front — and I'll manage them with you.
We already have an IT guy.
Then Monitored is probably your tier — I watch, they fix. That works well. Fully Managed is for people who'd rather that whole function just belonged to somebody, and be done with it.
What if we're already breached and don't know it?
Then we'll find out in the first two weeks, and it's the best money you'll ever spend. It happens. I don't charge extra for what I discover during onboarding — that would be a perverse incentive, and it would make you not want me to look.
Are you going to lock us in?
No contract term, 30 days' notice, and your data and documentation are yours to take. If I'm only keeping you by making it painful to leave, I've already lost.
Tell me how many devices you have and what's keeping you up. I'll tell you which tier you actually need — including if that's neither one.
No pitch deck, no discovery call with a salesperson, no pressure. You'll be talking to the person who'd be doing the work.
Barr Cyber LLC · Kalispell, Montana · Serving the Flathead Valley and remote clients nationwide