Services & Engagements
Equity Solutions Network is led by a CISSP with executive accountability in CIO and CISO roles, backed by full-scope IT consulting for small businesses since 1998. That range is the point. The same person who built a HIPAA security program for a 2,000 employee healthcare organization has also been the entire IT department for a 12 person firm.
Every engagement below has a defined scope and a published price. No discovery call required to find out what something costs.
Nothing starts until the scope is written down and both sides agree on it. That is not a formality. It is how you avoid paying for work that solves a problem you did not have.
Engagements
For organizations carrying real security obligations without a full-time security executive. Ongoing ownership of the security program, board and executive reporting, vendor and audit management, incident response readiness, and the risk conversations that leadership actually needs answered.
Best fit: 50 to 500 employees, regulated or handling sensitive data, no dedicated security leader.
A fixed-scope assessment against the HIPAA Security Rule and NIST CSF, delivered as a written report with prioritized findings, remediation guidance, and the documentation required for audit and insurance purposes.
Built by someone who ran HIPAA programs inside behavioral health and community health organizations — not a checklist vendor.
CISSP-level delivery under your brand, at your client, on your paper. HIPAA and compliance assessments, risk assessments, policy development, security program buildout, cyber-insurance application support, and vCISO coverage when a client wants a named security executive.
You keep the relationship. I do the work. Partner rates are available for MSPs and consultancies bringing recurring volume — ask and I will quote it against the engagement.
A working session for the renewal application nobody on staff knows how to answer. Three hours, live, walking the application question by question so the answers are accurate and the gaps are visible before the carrier finds them.
Includes a one-year Whitestance subscription for tracking posture between renewals.
A fixed-scope assessment of where AI actually fits in your operation — and where it does not. Process review, opportunity ranking by effort and return, risk and governance considerations, and a recommended sequence.
The fee credits toward any build engagement that follows.
Acceptable use policy, data handling standards, vendor evaluation criteria, and staff training for organizations adopting generative AI without a framework. Written for regulated environments and for the people who have to follow it — not for a compliance binder.
Full-stack technology guidance for owner-led businesses. Systems selection, vendor management, security baseline, and the decisions that are hard to unwind later.
I build the site, host it, and keep it visible. That's the same practice that builds and operates ESN's own production software and runs AEOCheck. Design and development to start, then managed hosting with ongoing SEO, AEO, and GEO so the site keeps showing up in Google and the AI answer engines your customers are actually using.
Best fit: businesses that want one accountable practice for the build and the ongoing visibility work, instead of a dev shop, a host, and an SEO vendor who don't talk to each other.
How it works
A published price tells you what something costs. It does not tell you whether it is the right thing to buy — and those are different questions.
So every engagement begins the same way. A conversation about what is actually going on, then a written scope covering the specific outcomes, what is included, what is not, the timeline, and who is responsible for what. You see that document before any money changes hands.
Two things follow from that. If the work you need is different from the work you asked for, you find out before you pay, not three weeks in. And if the honest answer is that you do not need me, you get that answer too. I have talked people out of engagements they were ready to buy, because selling someone a security program they were not ready to operate helps nobody.
The prices on this page hold for the scope described. If your situation is genuinely larger, you will hear that up front with a number attached, and you can decide from there.
Track record
30 years in IT. CIO and CISO accountability since 2021. CISSP.
Cybersecurity posture built from 35% to 89% over three years in a regulated healthcare environment. HIPAA and security programs owned across organizations up to 2,000 employees and 30+ sites. ISO 27001 certification support in a legal-technology SaaS environment. Two businesses founded and run to $10M+ in combined sales.
Proof, not portfolio
The services above are informed by systems that are live and in production. ESN builds and runs its own software — which means the security and architecture advice comes from someone currently responsible for both.
Get started
The Blueprint, the HIPAA assessment, and the renewal session are fixed scope and fixed price — the number you see is the number, with no hourly surprise. Tell me which one fits and we'll start with a short conversation and a written scope, before anything is committed.
Tell me what is going on. No phone number required — I read these myself.