Scoping & rules of engagement
A written scope defines every system in play, the testing windows, and the exact boundaries — signed before a single packet is sent. Typically a one-week intake.
Est. Milton, New Hampshire · Retained Security Counsel
Kryptomend tests the systems your business runs on, documents where they can fail, and stands ready when something goes wrong — so a single breach never becomes the end of the story.
The engagement, in order
Every engagement follows the same disciplined sequence. You know what we are doing, why, and what you receive at each stage.
A written scope defines every system in play, the testing windows, and the exact boundaries — signed before a single packet is sent. Typically a one-week intake.
We map your external and internal surface, then attempt real-world exploitation the way an adversary would — credential attacks, misconfigurations, and known ransomware entry points.
Every issue is ranked by exploitability and business impact, with reproduction steps and a remediation path a working IT team can actually follow. Delivered within ten business days.
We walk your team through the fixes, then retest the high and critical items at no additional charge to confirm each one is closed. Retainer clients keep us on standing recall thereafter.
What clients rely on us for
The same lead consultant signs your scope, runs your test, and briefs your board.
No 200-page automated dump. Each report leads with a plain-language executive summary and a prioritised remediation list your team can start on the same afternoon.
A mutual NDA precedes every engagement. Test data, credentials, and findings are held under a documented retention and destruction policy.
Our audit deliverables map to the control language on common cyber-liability questionnaires — attestation, MFA coverage, and backup posture included.
We test what matters to your business and say so up front. You never receive a bill for hours spent scanning systems that were never in scope.
Retainer clients reach a named responder directly. When ransomware hits, the clock is the enemy — a triage call inside the first hour changes the outcome.
Who we work with
A breach doesn't check whether you're a Fortune 500 or a fourteen-person firm. It checks whether the door was locked.
— Kryptomend, on why small businesses need real testing
Law, accounting, and medical offices holding sensitive records under regulatory obligation.
Manufacturers, distributors, and trades running on a mix of legacy and cloud systems.
Town offices and community organisations with lean IT and high accountability.
Startups that need a credible third-party test before an enterprise customer will sign.
Two ways to engage
Most clients begin with a fixed-scope assessment and move to a retainer once they see the surface they were carrying.
Policy, access, and backup posture review with a written remediation roadmap.
Backup validation, segmentation check, and a tabletop of your response plan.
Containment, forensics, and recovery when an active breach is underway.
The window that matters most
If ransomware is spreading right now, do not wait on a form. Call the line below — a Kryptomend responder answers.
Where we are · how we work
Consultations are booked ahead so the consultant on your account is the one across the table.
On-site across the Seacoast, the Lakes Region, and greater Rochester & Dover. Remote engagements nationwide.
Engagements are quoted, scoped, and invoiced on net-15 terms. We accept: