Services
Cybersecurity services built for your business
Practical, threat-informed cybersecurity and IT services for small and midsize businesses in Tampa Bay and select nationwide clients. Choose a focused engagement or combine services into a roadmap aligned with your risks, team, and business goals.
- SDVOSB Service disabled veteran owned
- CISSP GICSP, GCIP, K-FiveFour RTAC
- USMC Marine Corps cyber operations
- 18 yrs In IT and cybersecurity
What we offer
Five ways to work together
Every engagement is built around a clear business problem, defined deliverables, and measurable outcomes. Custom engagements are scoped after an initial consultation and priced according to your organization’s needs. Not sure where to begin? Start with a security assessment and prioritized roadmap.
Security Assessments & Roadmaps
Understand where your greatest risks are and what to address first.
We evaluate your security posture across technology, processes, people, and relevant requirements. Engagements may include vulnerability assessment, control-gap analysis, policy and incident-response review, and stakeholder interviews.
- What you receive
- Clear findings, business-focused risk ratings, prioritized recommendations, realistic timelines, and a practical security roadmap.
- Ideal for
- Small and midsize businesses preparing for growth, responding to customer or compliance questions, recovering from a security scare, or unsure where to invest.
- Outcome
- A defensible plan that directs limited time and budget toward the improvements that matter most.
Virtual CISO Advisory
Experienced security leadership without adding a full-time executive.
We help align security decisions with business priorities through practical planning, risk management, governance, vendor oversight, leadership reporting, and incident guidance.
- What you receive
- Recurring leadership sessions, a prioritized security roadmap, policy and governance guidance, risk and vendor oversight, leadership-ready reporting, and support for important security decisions.
- Ideal for
- Growing organizations that need accountable security leadership, face customer or compliance requirements, or have outgrown an informal security approach.
- Outcome
- A practical, sustainable security program aligned with your risks, goals, and budget.
Purple Teaming & Threat Emulation
Test your defenses against realistic attack scenarios before a real adversary does.
We emulate relevant threats, collaborate with defenders, and evaluate how well your controls, detections, and response processes perform under pressure.
- What you receive
- A scoped exercise plan, documented attack paths, validated detections and controls, prioritized findings, and a practical improvement roadmap.
- Ideal for
- Organizations with an internal security or IT team that want evidence of what works and clear guidance on where to improve.
- Outcome
- Stronger detection and response capabilities, better coordination, and defensible priorities for future security investment.
Security Training & Team Development
Build confident defenders through practical training tied to your team, tools, and real-world risks.
Engagements can include workshops, tabletop exercises, detection engineering, threat-informed defense, and hands-on skill development tailored to your environment.
- What you receive
- Customized training content, facilitated exercises, practical reference materials, observed capability gaps, and prioritized recommendations for continued development.
- Ideal for
- IT and security teams that need stronger security habits, clearer response roles, or focused development in high-priority areas.
- Outcome
- Better-prepared staff, stronger coordination, and measurable improvement in the skills your organization relies on.
Tailored IT & Cybersecurity Consulting
Secure, scalable technology that supports the way your business actually operates.
We assess your current environment, identify operational and security gaps, and design practical improvements across networks, cloud services, backups, system integrations, and recovery planning.
- What you receive
- A prioritized technology plan, implementation support, documented configurations, and recommendations that can scale with your business.
- Ideal for
- Growing businesses dealing with outdated systems, recurring IT problems, fragmented tools, or technology that distracts from core operations.
- Outcome
- More reliable operations, stronger security, and a clearer path for future technology decisions.
Our approach
How an engagement runs
Four steps, start to finish. You will know what happens next at every stage.
- 01
Discovery call Free
We listen to your challenges, assess your current state, and determine if we are the right fit.
- 02
Assessment and roadmap
We evaluate your environment and create a prioritized action plan with clear timelines and costs.
- 03
Implementation
We execute the plan with minimal disruption to your operations, with regular check-ins, continued support, and transparent communication.
- 04
Continued support
Security is not one and done. We provide continuous support, monitoring, and updates as your business evolves.
Working with TreyCraft
What to expect before you call
The practical details most people want answered before they reach out.
Service area
Onsite work across the Tampa Bay area, including Hillsborough, Pinellas, Pasco, and Hernando counties. Remote engagements are available for clients nationwide, accepted selectively.
- Tampa
- St. Petersburg
- Clearwater
- New Port Richey
Engagement models
Most work falls into one of three shapes. Scope and pricing are set after the discovery call, based on your environment and goals.
- Fixed scope project
- An assessment, a purple team exercise, or a training program with a defined start and end.
- Ongoing advisory
- Recurring virtual CISO sessions and support on a monthly cadence.
- Blended
- Start with an assessment, then move into ongoing support against the roadmap it produces.
Who we work with
Small and midsize businesses without a dedicated security team, and IT teams that need specialist depth they do not carry in house.
We work alongside your existing IT provider or managed service provider rather than replacing them. If you already have a team, our job is to make them measurably better, not to compete with them.
What happens next
- You send a request through the form below.
- We reply within one business day to schedule a discovery call.
- The discovery call is free and carries no obligation.
- If we are a fit, you get a written scope and price before any work begins.
Common questions
Before you reach out
What does an engagement cost?
Every engagement is scoped after the discovery call and priced according to your environment, goals, and budget. You receive a written scope and price before any work begins, so there are no surprises. The discovery call itself is free.
Do you replace our current IT provider?
No. We work alongside your existing IT provider or managed service provider. Our role is security expertise most general IT firms do not carry in house, and the usual outcome is that your existing team gets clearer priorities and better support, not a replacement.
Do you work onsite or remotely?
Both. Onsite work is available across the Tampa Bay area. Most assessment, advisory, and training work can be delivered remotely, which is how we support clients outside the region.
We are a small business. Are we too small for this?
Almost certainly not. TreyCraft exists because small and midsize businesses deserve strong cybersecurity without the price tag of a major security brand. If a full engagement is not the right use of your budget right now, we will tell you that on the discovery call.
Can you help with compliance requirements?
Assessments include a review against the requirements that apply to your business, and virtual CISO engagements cover the governance and policy work those requirements depend on. Bring the specific framework or customer questionnaire you are facing to the discovery call and we will tell you honestly whether we are the right fit for it.
How long does a security assessment take?
It depends on the size and complexity of your environment. Scope and timeline are set together after the discovery call, and the timeline is part of the written scope you approve before work starts.
Who actually does the work?
Trey does. Every engagement is scoped, delivered, and explained by the same person who assessed your environment. You will not be handed to a junior analyst after the sales conversation.
Get started
Request a consultation
Tell us about your business, current challenges, and the services you are considering. We will review your request and follow up to discuss practical next steps.
- The discovery call is free and carries no obligation.
- You get a written scope and price before any work begins.
- You talk to Trey, not a salesperson.
