The largest loss in this industry is a priority for one firm in ten
NAR’s 2025 Profile of Real Estate Firms, published 19 November 2025, asked brokers of record what they expect their biggest challenges to be over the next two years. Wire fraud was named by 10%, where it ranks seventeenth of twenty-two. Keeping client data secure was named by 8%. The same survey describes who is answering: 81% of firms operate a single office, the median single-office firm has two full-time licensees, and it closed a median of 12 transaction sides in 2024. NAR reports n=4,672, a 2.2% response rate and a confidence interval of plus or minus 1.42%.
Read that ranking the right way round. It is not evidence that wire fraud is a small problem. It is evidence that it is an unattended one, and the two are opposite findings. A firm closing twelve sides a year meets the risk twelve times, and each time the amount in motion is a multiple of everything else the firm handles that month. The sixteen items ranked above wire fraud are mostly things that cost a firm a percentage. This one is the item that can cost a firm the whole of a client’s proceeds, once, on a Tuesday. Attention has not gone where the size of the loss is, which is the condition an attacker selects for.
The tooling numbers point the same way. NAR’s 2025 Technology Survey, published 18 September 2025, reports that 19% of REALTORS® use cyber security tools such as antivirus or VPN. That is the survey’s own scope, antivirus and VPN, rather than a measure of security tooling in general, and it is quoted narrowly for that reason.
What the loss actually costs you is the client, and it costs you the client even when the money comes back. CertifID’s 2026 State of Wire Fraud Report, published 9 March 2026, a survey of roughly 1,200 consumers and written by a vendor that sells wire protection, found that “56% of consumers said they would not work with a title company or real estate firm again after a wire fraud incident, even if all of their funds were fully recovered.” 68% say a guarantee of protection strongly influences which provider they choose. The same report puts the share who would pay extra for it at 85%, and that figure travels only alongside its own qualifier, that 71% would pay $51 or more.
How often it arrives. ALTA and CertifID surveyed 360 title companies about calendar 2023 and published on 27 February 2025, with CertifID sponsoring the work: more than 40% received at least one wiring-change email a month, 7% wired funds to a fraudulent account, and 13% had a customer do so. Earlier, in an ALTA survey of March 2021 of nearly 550 title agents, attempts touched about a third of transactions. That third is agent perception rather than a counted rate, and the more useful numbers from the same March 2021 survey are that funds actually reached a fraudulent account in “a little over 8%” of attempts, that full recovery followed in 29% of cases, and that 81% of respondents worked at firms of ten or fewer people. That last figure is this reader.
One correction worth making, because getting it wrong is how a firm ends up quoting a number that argues against itself. IC3’s 2025 Internet Crime Report counts its Real Estate category at 12,368 complaints and $275,110,419, and IC3’s own glossary scopes that category to a real estate investment or fraud involving rental or timeshare property. Closing wire fraud is not in it. Closing wire fraud is counted under Business Email Compromise, at $3,046,598,558 across 24,768 complaints, and Appendix C of the same report states that “Each complaint will only have one crime type”, so the two lines cannot be added. IC3 makes the point itself: its 2025 case study describes buyers who wired $449,000 after an attorney-impersonation email at closing, and files it as a BEC incident.
A word on the fine, since that is what most compliance pages sell. There probably is not one. The FTC has obtained no monetary penalty under the Safeguards Rule against a firm in this industry, and its own legal library lists no GLBA enforcement action of any kind since 2020. The honest other half is that a state regulator can, and one did: the New York Department of Financial Services penalised First American Title Insurance $1,000,000 under 23 NYCRR 500 over a breach discovered in 2019. If you are an appointed title agent, the regulator with the shortest route to you is your state insurance department, not the FTC. And the realistic exposure is still none of the above. It is the wire, and the client who does not come back.
Who this page is for
Title agencies, escrow and settlement offices, and real estate brokerages, at the size where one person carries the technology and nobody carries the paperwork. Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly.
This is the closing-table version of our managed security and compliance offering for small regulated firms, which carries the same plans and the same evidence discipline for firms outside this industry. If you want the background reading first, we have written on how a real estate closing wire fraud is actually run and on the controls that stop a wire transfer fraud before it starts.
What actually binds you
Two firms sit at the same closing table and do not share a mandate. A settlement agent holding escrow is a financial institution under the Safeguards Rule. A brokerage doing only traditional brokerage work, on the National Association of REALTORS®’ own reading, should not be. So this section answers separately rather than once, because a page that gives you one answer is giving at least one of you the wrong one.
If you handle settlement and escrow
The Safeguards Rule reaches you by activity, not by job title. 16 CFR 314.2(h)(2)(x) gives the reasoning in full: “An entity that provides real estate settlement services is a financial institution because providing real estate settlement services is a financial activity listed in 12 CFR 225.28(b)(2)(viii).” That sits in a list the rule labels examples of financial institutions. The definition itself turns on whether you are significantly engaged in an activity that is financial in nature, so the example is how you recognise yourself, and the activity is what does the binding.
Which regulator holds the other end depends on the line of business. 15 U.S.C. 6805(a)(6) assigns enforcement for a person engaged in providing insurance to the state insurance authority of the relevant state, and it says that authority acts under State insurance law. That qualifier is doing real work and is quoted rather than dropped. A title insurance agency appointed in a state with an insurance data security statute answers to that department first, and the practical consequence is on the next heading.
Size changes what the program contains. It does not remove the program. 16 CFR 314.3(a): “You shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts.” The same sentence requires safeguards appropriate to your size and complexity, which is the accommodation a small agency actually gets.
16 CFR 314.6 is one sentence, and below five thousand consumers it removes exactly four provisions. The written risk assessment at 314.4(b)(1). The continuous monitoring, or the annual penetration test and twice-yearly vulnerability assessment, at (d)(2). The written incident response plan at (h). And the annual written report to your board or governing body at (i). Everything else stands. Encryption of customer information in transit and at rest is 16 CFR 314.4(c)(3), which lets you substitute effective alternative compensating controls where encryption is infeasible, reviewed and approved by your Qualified Individual. Multi-factor authentication is 16 CFR 314.4(c)(5), required for any individual accessing any information system unless your Qualified Individual approves reasonably equivalent or more secure access controls in writing. Neither is among the four.
One date worth getting right, because vendors get it wrong in both directions. The Safeguards Rule has bound non-bank financial institutions since May 2003. The 9 June 2023 date belongs to nine enumerated provisions of the 2021 amendments, and it is a compliance date for those provisions rather than the day the rule arrived.
If your state has adopted the NAIC model
Twenty-eight jurisdictions had adopted the NAIC Insurance Data Security Model Law, Model #668, on the NAIC adoption map dated 1 April 2026. What follows is model text, and that distinction matters more here than anywhere else on this page, because the model is law nowhere. Your legislature enacted a version of it, and the versions diverge on the exact number below.
Model #668 § 9.A(1) exempts a licensee with fewer than ten employees, including independent contractors, from Section 4 alone. Section 4 is the information security program. Sections 5 and 6, investigation of a cybersecurity event and notification to the commissioner, apply at any size, so a small agency is released from the written program and still owes the investigation and the notice. § 9.B then gives 180 days to comply once the exception is lost.
Your state’s version of the NAIC model may differ on the employee count, so read your own statute before treating the exemption as settled. Michigan enacted the exception at fewer than 25 employees and independent contractors, and Connecticut ran fewer than 20 until 30 September 2021. A Michigan licensee working from the model number gets the wrong answer about its own obligation.
Two more exemptions run in the same direction and are the ones most often missed. § 9.A(3) exempts an employee, agent, representative or designee of another licensee, to the extent that person is covered by that licensee’s information security program. For a small agency appointed by an underwriter, that is the exemption most likely to apply, and it is worth asking your underwriter in writing whether its program covers you. § 9.A also exempts a licensee compliant with HIPAA that has established a program under it.
What Sections 7, 8 and 10 are, since they are sometimes listed as duties a small licensee still owes: the commissioner’s power to investigate, the confidentiality of documents the commissioner obtains, and penalties. They are not obligations you discharge. Sections 5 and 6 are.
Where the map sits for the four largest closing markets. New York runs 23 NYCRR 500, which Model #668’s own drafting note treats as compliance with the model. California runs 10 CCR §§ 2689.12 to 2689.20. Texas and Florida have neither adopted the model nor legislated an equivalent, which makes them different from the states that considered and declined, and is a reason to read the general breach statute below rather than to assume nothing applies.
If you are a real estate brokerage
NAR’s published position is that a brokerage engaged only in traditional real estate brokerage activities should not be subject to the Safeguards Rule. The hedge is NAR’s and it is kept, because an unhedged version of that sentence is a promise nobody has made to you.
Two provisions support it. 12 CFR 225.126(c) lists real estate brokerage among the activities the Federal Reserve Board determined are not so closely related to banking as to be a proper incident to it. And 12 CFR 225.86(d)(1)(iii)(D) forecloses the theory that a brokerage is a finder, in one line: “A finder may not engage in any activity that would require the company to register or obtain a license as a real estate agent or broker under applicable law.” A licensed broker is therefore the one thing a finder cannot be. Note the scope of that: it closes the finder route specifically. It is not authority for a general exclusion from 16 CFR 314.2(h).
The carve-back is where most brokerages of any size actually land. Run a title, settlement, escrow or mortgage arm and that arm is covered on its own footing. Take compensation for arranging or referring loans, which is a common affiliated-business arrangement, and you are in a different conversation about the same rule. The question is what the entity does, so the answer can differ between two brokerages on the same street.
What does reach a brokerage is the state breach-notification layer, and every state has one. Two examples rather than a national answer, because two statutes cannot give one. Fla. Stat. 501.171(2) requires reasonable measures to protect and secure personal information in electronic form. N.Y. Gen. Bus. Law § 899-bb(2)(a) requires reasonable safeguards and turns on private information, which is a narrower trigger than personal information and is worth reading before you assume your data is outside it.
On what happens if you get it wrong, stated in both directions because both overstatements are common. Florida’s headline penalty tiers at 501.171(9)(b), the ones reaching $500,000, attach to notice failures under subsections (3) and (4), per breach rather than per individual. They do not attach to the security duty. But 501.171(9)(a) does reach it: a violation of this section, which includes the security duty at subsection (2), is treated as an unfair or deceptive trade practice in an action brought by the department under s. 501.207, and (9)(b) opens “in addition to the remedies provided for in paragraph (a)”, which is the text confirming (a) is a live route. 501.207 reaches 501.2075 civil penalties of up to $10,000 per willful violation, and $15,000 where the victim is a senior citizen or a person with a handicap.
Neither statute creates a customer lawsuit of its own, at 501.171(10) and 899-bb(2)(e). New York routes around that, though: 899-bb(2)(d) deems non-compliance a violation of GBL § 349, and § 349(h) carries its own private right of action. So the accurate framing is enforcement by the attorney general under this section, rather than the reassurance that nobody can sue you.
One thing that does not bind you, said plainly because it is sometimes implied. The NAR Code of Ethics contains no occurrence of cybersecurity, data security or information security. Standard of Practice 1-9 concerns revealing and misusing confidential client information, which is a duty about your own conduct rather than a duty to protect that information from a thief.
ALTA Best Practices, Version 4.2, revision stamped 19 August 2025, says of itself that “These practices are voluntary.” Best Practice 3 asks for the written information security program this offering builds, which is why it is the most useful page of the framework for a title agency. ALTA Best Practices are voluntary, and an underwriter that requires them does so through an executed agency agreement rather than through the framework. If your underwriter has one in force, that agreement is the instrument to read, and we will read it with you.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Written information security program | ||||
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Customer notification decision file, including the reasons not to notify | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and written breach-notice terms | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule, and a document pack ready for an underwriter audit or a state examination | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The written program build is a one time $12,500, required once on the two plans that include it.
Your insurance application, control by control
Must have
One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.
Changes the price
You can get a policy without it, but it costs more, or you get lower limits.
On the form
They ask, and the answer goes on file, but on its own it rarely stops anything.
| What the application asks | Monitor | Managed IT | Monitor + Comply | Complete |
|---|---|---|---|---|
| Must have | ||||
| Two-step login (MFA) on email | Covered | Covered | Covered | Covered |
| Two-step login on any way in from outside the office | Covered | Covered | Covered | Covered |
| Security software on every laptop and server | Covered | Covered | Covered | Covered |
| Backups an attacker cannot reach or overwrite, and proven to restore | Covered | Covered | Covered | Covered |
| Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole. On a closing desk it is the whole ballgame. | Covered | Covered | Covered | Covered |
| Changes the price | ||||
| Two-step login on the accounts that can change everything, and on the backup system | Covered | Covered | Covered | Covered |
| What share of devices are covered, and whether the software cuts an infected one off the network by itself | Covered | Covered | Covered | Covered |
| Backups kept apart from the day-to-day network, so one break-in cannot take both | Covered | Covered | Covered | Covered |
| Someone has actually restored a file from backup and written down that it worked | Covered | Covered | Covered | Covered |
| Email screened before it arrives, and attachments opened somewhere safe first | Not covered | Covered | Not covered | Covered |
| How fast you install urgent security updates, and how often you hit that target | Not covered | Covered | Not covered | Covered |
| How many accounts can change anything, and why each one needs to | Covered | Covered | Covered | Covered |
| On the form | ||||
| Software the maker has stopped fixing, still in use | Covered | Covered | Covered | Covered |
| Staff training, and test phishing emails sent to see who clicks | Not covered | Covered | Not covered | Covered |
| A written plan for a break-in, rehearsed once a year | Not covered | Not covered | Covered | Covered |
| Checking the outside companies that touch your client data | Not covered | Not covered | Covered | Covered |
These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.
The one control that matters at a closing
Every plan includes a written wire verification procedure. Call-backs go to a number agreed at the time of onboarding rather than to a number supplied in the request, which is the whole of the control, because the number in the request is the thing the attacker changed. Transfers above ten thousand dollars need dual control, approved by someone other than the person who initiated them, on a different device.
We write the procedure, we train your staff on it, and once a year we test that it was followed and file the dated result. We never approve or release a wire ourselves. That stays with your people, because the control only works if the person with the authority is the person doing the checking.
What we do, and how often
Every month
- Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
- Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
- Evidence packProduces: A dated snapshot of every device and user, filed to your archive
Every quarter
- Restore testProduces: A written result for a real file set restored from backup
- Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
- Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
- Report to the person your firm made responsibleProduces: One page: what changed, what lapsed, what needs a decision
Every year
- Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
- End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
- Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
- Wire procedure rehearsalProduces: A dated record that the call-back and dual-control steps were tested, not assumed
The written information security program
Included in Monitor + Comply and Complete. This is the part that produces the documents themselves, not just the evidence that controls are running. The incident response program is written with its three parts kept separate and visible: assessment, containment and control, and notification. The notification decision file is a template for the decision, and a filing structure that records the reason you decided not to notify where that was the outcome, which is the part firms skip and the part that is hardest to reconstruct afterwards.
The vendor program is the inventory, the due diligence file, a written breach-notice expectation put to each provider, and a monitoring cadence. Your settlement software, your escrow accounting host and your document portal all sit on that list, and for most firms of this size they are the three that matter.
An annual tabletop exercise and a written after-action report are also included. That one is not required by any instrument we cite on this page, and we say so plainly rather than imply otherwise. It is what turns a written plan into a tested one.
An honest boundary. We prepare these documents for your firm and your counsel to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to your firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
What is included, what is not, and what stays yours
We do
- Configure, monitor and maintain every product in your plan
- The monthly, quarterly and annual work in the service calendar above
- Deliver a dated evidence pack to your archive every month
- Support one insurance application or renewal each year
- Escalate anything we find, with a written record
- On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month
We do not
- Helpdesk on the two Monitor plans, which stays with your own IT
- Incident response and forensics inside the monthly fee, which is billed separately
- Buying or owning your hardware, software licenses, phones or cabling
- Legal, regulatory or insurance advice
- Writing or sending your breach notifications
- Acting as, or standing in for, the person your firm makes responsible for information security
- Approving or releasing any wire, which stays with your own staff
- Work on site or outside business hours, except by arrangement
You do
- Name a primary and a backup technical contact, and tell us if that changes
- Respond within four business hours when we escalate something urgent
- Adopt the policies we prepare, with your counsel
- Own the accuracy of anything you file with a regulator, an underwriter or an insurer
- Tell us before you add people, offices, systems or vendors
- Keep your own IT resource in place on the Monitor plans, or tell us if that ends
Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.
If a wire goes out anyway
Money is recoverable, and the variable that decides it is how fast the first call is made. In 2025 the FBI’s Recovery Asset Team acted on $1,163,919,846 and froze $679,013,183 of it, in cases where the victim reported immediately. Nothing about that machinery works retrospectively, which is why the wire procedure and the phone number for this practice belong in the same one-page document on your closing desk.
Two numbers to distrust while you are moving, because both are quoted at title agents as deadlines and neither is one. FinCEN puts the 72-hour figure on international wires through its Rapid Response Program, and frames it as when recovery is most likely. There is no FBI 72-hour rule, and no dollar floor below which IC3 declines a report. Report it regardless of the number and regardless of the hour.
Most providers hand you off at the worst possible moment. We do not. The people who protect your firm are the same people who examine the devices and the accounts, write the report, and stand behind it if it is ever challenged.
Hour one to day ten
- Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
- Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether customer information was actually reached. Those are the questions your notification decision turns on.
- By day ten, report. A written forensic report your counsel, your underwriter, your insurer and a state regulator can all read. Written to be defensible, because we write reports that go to court.
- Then notify, rebuild, and if needed testify. The report feeds your notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.
Who does the work
A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.
Two things we put in writing. Where privilege matters, and in a serious incident it usually does, we take our instructions through your lawyer rather than direct. That is the arrangement that gives the report the best chance of staying protected, and we set it up at onboarding so it is ready rather than improvised at 2am. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.
Chain of custody is the unbroken written record of who held a piece of evidence and when, which is what stops the other side arguing it was altered. Privilege means the other side in a lawsuit cannot demand to see a document.
Who we act for
Something you should hear from us rather than find on your own. This practice also runs wire fraud recovery work, and the people who bring us that work are sometimes buyers and sellers whose money went astray at a closing. Some of those matters end up adverse to a title company or a brokerage.
The honest description of how that works is short. We take instructions from whoever retains us. We have acted for parties on both sides of this kind of case, and we expect to keep doing so, because the examination work is the same work whichever chair it is done from. We do not have a published conflicts policy to point you at, so we are not going to imply one. What we can tell you is that conflicts are worth raising on the first call rather than the first invoice, and if you ask us at that call whether we are acting against you, you will get a straight answer.
If your firm has a live incident right now and no relationship with us, the recovery side is the right door and it does not require any of this. Read what happens in the first hours after a wire goes out and call.
The first ninety days
- Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. Your own vendor file needs one for every provider that touches customer information, so we hand ours over before you ask.
- Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
- Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates tested, the wire verification procedure written and trained, vendor inventory built. Your counsel reviews. Your firm adopts.
- Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing insurance, we assemble the control evidence for your broker.
What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches customer information, your current policies however incomplete, your penetration test report if you have one, and your counsel’s name so the program is prepared under their review.
On the penetration test. If you have had one, the findings are a separate project scoped finding by finding against an agreed cap. We do not fold open-ended remediation into a fixed monthly fee, because that is how a fixed fee stops being fixed.
Rates, growth and the small print
Project and hourly rates
| Work | Standard | On a plan |
|---|---|---|
| Remediation beyond the included allowance | $400/hr | $195/hr |
| Security consulting, assessment and hardening | $400/hr | $275/hr |
| Incident response, containment and rebuild | $400/hr | $275/hr |
| Forensic examination and written report | $400/hr | $325/hr |
| Deposition and trial testimony, four-hour minimum | $400/hr | $400/hr Same as the standard rate. |
| Done-for-you device forensics | from $2,000 | from $2,000 Same as the standard rate. |
| Refundable engagement retainer | $5,000 | Waived |
All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.
As your firm grows
Additional named user
$35/mo
Additional workstation
$25/mo
Additional server
$70/mo
New user setup
$150
User departure and offboarding
$100
New device deployment
$200
Term
Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.
Your data
Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.
Our duty to you
We are your service provider, and our agreement says so in writing. We will tell you within 72 hours of becoming aware of a breach affecting a system holding your customer information.
Insurance
We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.
Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.
Why this work matters
A ten-person title agency moves more money in a week than most businesses its size see in a year, and it does it on the strength of an email. What an underwriter and a state regulator both want is not a promise but a dated record, and producing that record every month is the whole of this offering.
















