Figure out what you are buying before you shop
The phrase security audit gets used for at least four different services, and firms will happily sell you whichever one they offer.
A risk assessment maps what could go wrong and how badly. A compliance gap assessment measures you against a specific standard your customers or regulators require. A technical audit reviews your actual settings: email, cloud accounts, firewalls, backups. A penetration test pays someone to try breaking in.
Most DMV small businesses shopping for an audit actually want a technical review plus a prioritized fix list. Decide which question you need answered before you take a single sales call, because the price difference between these services is thousands of dollars, and the wrong one answers a question you did not ask.
Credentials to check, on the person, not the logo
Company logos and partner badges tell you little. Ask who will actually do the work on your account, then check that person.
- CISSP signals broad, senior security experience.
- Security+ is the respected baseline; I hold it myself, and I would expect at least this from anyone touching your systems.
- OSCP matters if hands-on testing is included.
- CISA is the credential for formal audit work.
For defense contractors, check the Cyber AB marketplace for Registered Practitioners. Every one of these can be verified online in minutes, because certification bodies maintain public directories. A firm that gets vague when you ask who is assigned to your engagement is telling you the senior person sold you and a junior person delivers.
Scoping and deliverables to demand in writing
Before signing, the proposal should state:
- Exactly what is in scope: which systems, accounts, locations, and how many hours.
- A severity-ranked findings list, not an alphabetical dump of scanner output.
- Plain-English fix instructions with rough effort estimates, so you can act without hiring a translator.
- An executive summary a non-technical owner can read in five minutes.
- A live debrief call, because a PDF alone always leaves questions.
For a small DMV business, a solid technical security assessment generally lands between $2,000 and $10,000 depending on size and depth. Pay attention to what is excluded. A low quote that leaves out your cloud accounts or your one custom application is not actually low.
Findings-only versus remediation-included, and local versus remote
A findings-only engagement hands you the report and leaves. It is cheaper, but the report becomes your homework, and in my experience half of unassisted fix lists are still open a year later. Remediation-included costs more but ends with problems actually closed.
One caution: if the same firm audits and fixes, there is a mild conflict of interest, since they are grading work they hope to sell. It is a manageable conflict, but ask them to separate the audit fee from any fix quote so you can take the report elsewhere if you choose.
Local versus remote matters less than it used to, but a local firm can walk your office, check the physical things like the server closet and the sticky notes with passwords, and sit with you for the debrief. In the DMV you have plenty of local options, so make remote firms earn the distance with a better price or deeper expertise.
Red flags in security sales tactics
Walk away when you see these:
- The pitch opens with fear: breach statistics, worst-case stories, and pressure to sign this week.
- A free scan that somehow always finds critical issues, followed by a big quote.
- A promise of guaranteed compliance or guaranteed prevention. No honest firm guarantees either.
- No scoping questions. If they can quote without understanding your business, the quote is not about your business.
- Refusal to provide a sanitized sample report or to name the people doing the work.
Good security firms behave like good doctors: they examine before they prescribe, they explain in plain language, and they tell you when you do not need the expensive procedure.
What to do next
- Write one sentence about why you want an audit: a client questionnaire, an insurance renewal, a bad feeling after a phishing email. Share it with every firm you talk to.
- Ask two or three firms for a sample report and a written scope. Comparing those two documents tells you more than any sales call.
- Verify one credential of the person assigned to you. It takes five minutes.
- Budget for fixes, not just the report. A fair rule of thumb is to reserve at least as much as the audit itself costs.
HashWhales does plain-English security reviews for small businesses across DC, Maryland, and Northern Virginia, and you talk directly to the person doing the work. If we are not the right fit, I will say so and point you somewhere better.
