DEV Community

Hive80-lab
Hive80-lab

Posted on

We sell exactly two services, both fixed fee

We sell exactly two services, both fixed fee: a small-team ops audit ($149, five days) and a custom incident runbook ($249, 48 hours). Before you buy either one — from us or anyone — here is what an audit actually checks, and the parts you can do yourself for free this weekend.

The full service page is here; the free 45-point checklist it is built on is here.

The honest version of the sales pitch

A checklist is all you need if you will actually walk it. The audit exists for the moment every team hits: the checklist is open, the day job is loud, and "we'll run it next quarter" is now in its third quarter. An external pair converts "we should" into "it's booked, it's done, here's the report."

What gets checked (six zones, 45 points)

Identity & access (10 points) — the zone where real breaches start. MFA enforced (not optional) on every provider, no shared logins, separate admin accounts, leavers with zero active accounts, API keys inventoried and rotated, a tested break-glass account.

Devices (7) — full-disk encryption verified on every laptop (verify, don't assume), screen locks, an asset inventory that matches reality, remote wipe actually available, printers treated as computers.

Network (6) — current firmware, guest WiFi isolated, every inbound port-forward owned by a name, remote access via VPN, DNS filtering, and the cloud-console sweep for public buckets and forgotten test servers.

Data & backups (8) — the zone that decides whether an incident is a bad Tuesday or an extinction event: automatic monitored backups, one offline/immutable copy, a restore test in the last 90 days, and written recovery objectives.

Vendors & SaaS (8) — the estate you don't operate: a SaaS inventory, lightweight vendor security reviews, SPF/DKIM/DMARC at enforcement, vendor offboarding that actually deletes data, insurance attestations that are actually true.

Incident readiness (6) — a named on-call human with a tested contact path, a one-page plan with severity levels, log retention decided, a tabletop that ran in the last six months, and a written ransomware recovery sequence.

The evidence rule that makes it real

Screenshot or it did not happen. A control you believe is fine is a finding. This is the single biggest difference between a checklist that's walked and one that's skimmed — and it's what an external pair enforces just by being in the room.

What you get back

One page, three columns: finding → risk in one sentence → fix + date + owner. Triage: criticals fixed within 7 days, highs within 30, hygiene batched. Our guarantee: at least ten actionable findings or the fee comes back. No retainer, no agents installed, no system changes, no upsell ladder — the audit and the runbook are the only two things we sell, and the 160+ free checklists on our site cover everything else.

When to choose the runbook instead

If your fear is not compliance but the 2am call, the artifact you need is a runbook — one page per incident type, written for your stack, with your names and your escalation path, delivered in 48 hours. Best combined: audit first, then the runbook built from its findings, so the document aims at your actual weaknesses.

Both links: Small-Team Ops Audit — $149 · Custom Incident Runbook — $249

Top comments (0)