FAQ
Questions we get, answered plainly.
What the program covers, what it doesn’t, how we work, and what happens when you call. If your question isn’t here, ask us directly — we answer the same way in person.
WHAT YOU GET
What does $250 per seat, per month include?
The $250 per seat monthly program includes 24/7 cybersecurity monitoring, unlimited IT help desk, security awareness training and phishing simulation, and device management. One price, no tiers, no add-ons.
What is not included in the $250 monthly program?
The monthly program does not include breach response and digital forensics, compliance readiness and fractional CISO leadership, or hardware and third-party licenses. We state this plainly on the pricing page rather than letting you find out later.
What counts as a seat?
A seat is a person and their computer. Additional identities not tied to a person — a shared mailbox, for example — are $10 each, and mobile devices are $6 each. You are not charged per server.
Is there a contract or a minimum term?
TRINSEC 7 works on an annual agreement, and we back it with a thirty-day guarantee: if you don't think the first month was worth it, we refund it and release you from the contract. Your judgment, not ours. We'd rather earn the year than trap you in it.
What is your answer-time guarantee?
When your team contacts us, a human answers within 15 minutes. If we miss that, that month is free. It's the promise most providers make informally and never put in writing.
HOW WE WORK
Do you replace our current IT provider?
We replace an existing IT provider in many cases, but not all. Some clients keep that relationship for specialized systems while we own security. We'll tell you honestly which arrangement makes sense for you, including when the answer is that you don't need us.
Is your security operations center based in the US?
Yes — TRINSEC 7's security operations center is US-based, and your environment is monitored by US-based analysts.
What's the difference between responding to an alert and responding to a breach?
Alert response is part of the monthly program: we investigate, act on what's covered, and tell you what happened. Breach response means forensic investigation, evidence handling, and root cause analysis, which is a dedicated engagement quoted per incident.
How do we contact you when something goes wrong?
You reach us by phone or email, any hour. A person answers — not a queue, not a portal, not a bot.
What size organizations does TRINSEC 7 work with?
We work with organizations under 250 people. Being small has never made anyone a smaller target — it usually just means nobody is watching.
TRAINING AND YOUR PEOPLE
We already do annual security training. Isn't that enough?
Annual security training was built to satisfy an auditor, not to change what someone does on a Thursday afternoon when a vendor emails asking to update their bank details. We train in short, frequent sessions and test with simulations modeled on the attacks actually hitting organizations like yours. The goal is a record of people getting better, not a record of people completing a video.
What happens when someone fails a phishing test?
Anyone who fails a phishing simulation gets a short, private coaching moment right then. We don't publish results or single anyone out — organizations that embarrass people teach them to stay quiet, and silence after a click is what turns a mistake into an incident.
Will security awareness training annoy our staff?
It shouldn't. Sessions are short, the simulations are realistic rather than gotchas, and reporting something suspicious gets a thank you instead of an interrogation.
SECURITY AND COMPLIANCE
Can TRINSEC 7 get us CMMC certified?
No firm can certify you and prepare you at the same time — be careful with anyone who says otherwise. CMMC certification is issued by an accredited third-party assessment organization. We get you ready and stand behind the work when the assessor arrives.
Do you handle HIPAA requirements?
Yes — we handle HIPAA Security Rule risk analysis, 405(d) HICP practices, and business associate agreement review.
Will you complete our cyber insurance application or client security questionnaire?
Yes, we complete cyber insurance applications and client security questionnaires. Answering these accurately matters more than it sounds — inaccurate answers can affect whether a claim is paid.
Do you cover physical security as well as cybersecurity?
Yes. We cover doors, cameras, access control, and where the physical and digital meet. Most providers only look at the network, which is a fraction of how organizations actually get hurt.
GETTING STARTED
What is the exposure check?
The exposure check is a free look at what's already visible about your organization from the outside — exposed credentials, email security gaps, and public-facing weaknesses. No obligation.
What happens on the first call with TRINSEC 7?
We come prepared. Before we speak, we look at your organization the way an attacker would and find the easy, obvious openings — then we walk you through what we found. If there aren't any, we'll tell you that too. Fifteen minutes, no pitch deck.
How long does onboarding take?
Most organizations are fully covered within a couple of weeks, and monitoring starts well before that.
What if we already had a breach?
Call us. We take incident engagements from organizations we've never worked with, and a lot of our clients first met us that way.
