602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

How to use these four tools, and what each one is actually for

Every tool on this page exists because the same four questions arrive over and over, usually from someone who needs a defensible number before a meeting and does not yet want a sales conversation. None of them is a substitute for an assessment. What they do is convert a vague worry into a figure, a score or a checklist you can put in front of a partner, a board, a landlord or an insurer — and then tell you honestly where the number stops being reliable.

They run entirely in your browser. Nothing you type is transmitted to us, stored, or attached to your email address, and there is no sign-up wall in front of any of them. That is deliberate. A tool that harvests your inputs before it shows you an answer is a lead form wearing a costume, and the answers it gives are worth exactly what you paid in attention to get past the gate.

Security Guard Cost Estimator

Guard pricing is quoted as an hourly bill rate, and that single number hides most of what determines your actual annual spend. Coverage pattern matters more than rate: eight hours on weeknights is a very different staffing problem from twenty-four-hour coverage seven days a week, which requires roughly 4.2 full-time equivalents once you account for shift relief, holidays, sick time and training hours. Armed versus unarmed changes the rate materially, because armed officers in Arizona carry additional state licensing requirements and the liability profile is different.

The estimator walks those variables and returns a range rather than a single figure, because a single figure would be a lie. Use it to sanity-check a proposal you already have in hand, to build a budget line before you go to procurement, or to work out whether a mixed model — a patrol contract rather than a dedicated post, or unarmed presence with armed escalation — gets you closer to the number you can actually approve.

Where it stops: it does not know your site. Post orders, access control integration, a required vehicle, a guard shack with no climate control, a property with fifteen entrances instead of two, a union environment, or a client that insists on a specific uniform standard all move the real number. So does the labour market in your particular corridor, which in Arizona differs noticeably between Phoenix metro, Tucson, and the rural counties.

Data Breach Cost Estimator

The instinct after a breach — or while budgeting to prevent one — is to think about the technical cleanup. The technical cleanup is rarely the largest line. Notification, credit monitoring, legal review, regulatory response, forensic investigation, call-centre capacity and the operational downtime while systems are rebuilt typically dwarf the cost of the incident response engagement itself. Industry matters enormously: a healthcare record and a retail email address are not remotely comparable exposures, because the first triggers HIPAA obligations and the second usually does not.

This estimator asks for record count, industry and the controls you have in place, then models a range. The controls question is not decoration. Encryption at rest, tested backups and a rehearsed response plan measurably reduce both the probability and the per-record cost of an incident, and the model reflects that — which is also why running it twice, once with your current posture and once with the posture you are proposing to fund, produces a useful before-and-after slide.

Where it stops: it models averages. Your actual cost depends on contract terms with customers, whether the data crossed state or national borders, whether a regulator opens an inquiry, and whether anyone sues. Treat the output as an order of magnitude for planning, not as a reserve figure.

Ransomware Readiness Scorecard

Two minutes, a short set of questions, a score. The questions track the controls that insurance underwriters and claims data both identify as the dividing line between an incident and a closure: multifactor authentication on email and remote access, endpoint detection and response across the whole estate, backups that are offline or immutable and have actually been restored from in a test, separated privileged accounts, and a written response plan someone has read.

The score is most useful as an internal argument. It is much easier to get budget for a backup change when the gap is on a page next to the four things you already do well, and much easier to sequence work when you can see which single missing control is dragging the number down. Most organisations that score badly are not missing everything — they are missing one or two things, usually tested restores and privileged account separation.

Where it stops: it cannot see your network. Flat internal networks, domain-joined backup servers, and vendors with standing remote access are the three findings that most often turn a survivable incident into a catastrophic one, and none of them shows up in a questionnaire.

TSCM Self-Audit — “Is your office bugged?”

Most suspected surveillance is not a planted transmitter. It is a phone someone else set up, a conference room system with a default password, a cloud camera account still tied to a former employee, a shared calendar exposing more than it should, or a car with a tracker bought for forty dollars. The self-audit walks the physical and procedural checks that resolve the large majority of these cases before any sweep equipment is involved, in roughly the order a technician would walk them.

It is also designed to slow you down in a specific way. If you genuinely believe a space is compromised, the worst first move is to search it while talking about searching it. The audit says so, and tells you what to do instead — which is usually to stop discussing the matter in that space, move the conversation elsewhere, and preserve rather than disturb anything you find.

Where it stops: it cannot rule anything out. A negative self-audit means the obvious things are clear. Confirming that a space is clean requires RF spectrum analysis, non-linear junction detection, physical inspection of furniture, fixtures and wall cavities, and a technician who has done it before. If the stakes are litigation, an executive protection matter, or a deal, the self-audit is preparation for a sweep, not a replacement for one.

Choosing the right starting point

If you are budgeting physical security coverage, start with the guard estimator. If you are building a cyber budget or justifying one, run the breach estimator and the ransomware scorecard together — one gives you the downside, the other gives you the controls that reduce it, and the pair is a more persuasive case than either alone. If something has already happened, or you suspect it has, the TSCM self-audit and the ransomware scorecard both double as triage: they tell you what to preserve and what not to touch before anyone arrives.

All four are free, and they stay free. We built them because a client who arrives with a rough number and a clear question gets a better, faster and cheaper answer than one who arrives with only a worry — and because the questions they answer come up constantly whether or not anyone hires us.

A note on privacy and how these tools run

All four run client-side. The arithmetic happens in your browser; no inputs are posted to a server, logged, or associated with you in any way. You can confirm that for yourself by opening your browser’s network tab while you use one — there is nothing to see, because nothing leaves the page. Close the tab and the numbers are gone.

That design has a practical consequence worth knowing about: results do not save. If you want to keep an estimate, screenshot it or copy the figures out before you navigate away. It also means you can use them from a machine you would rather not tie to a search for, say, counter-surveillance services — which for some of the people who land on that particular tool is not a hypothetical concern.

If you would rather not run anything at all and simply want a human answer to a specific question, that option is always open and costs nothing either.

Where to go next