About CRJ Security
Security built on governance, not gadgets.
We help small and mid-sized businesses find out exactly where their security stands, get the governance in place to hold it together, and prove it to anyone who asks — without selling them a single tool.
See where your business stands — free →Why governance-first?
Most businesses think the answer to security is a product. But software doesn't decide who's accountable, doesn't write your policies, and doesn't prove anything to an insurer or an auditor. The foundation of a real security program is clarity, accountability, and documentation — the things a tool can support but never replace.
This is exactly what NIST CSF 2.0 — updated in 2024 — reflects. Its newest core function is Govern, sitting above everything else. Governance isn't peripheral. It's the foundation the rest of the program runs on.
What we do — and what we don't
Our only product is the assessment. That's what makes the report honest — there's nothing else we're trying to sell you.
What you walk away with
A comprehensive report in plain English — the kind you can hand directly to your insurer, your biggest customer, or your IT team.
Maturity score
Overall + 13 domains, scored 1–5 on a recognized maturity scale
Findings & risks
Specific gaps for each domain and the risks they create
Prioritized fixes
Step-by-step recommendations, ordered by impact
30 / 90 / 12-month roadmap
A phased plan so you know what to do and when
Framework mapping
Mapped to NIST CSF 2.0 and CIS Controls — what your insurer uses
Yours to keep
Hand it to anyone who asks — insurer, customer, IT team, MSP
Who's behind CRJ Security
Built by someone who's seen it from the inside.
Chadd Jones
Founder, CRJ Security
I've spent more than 15 years in IT and security operations — most recently building and leading the infrastructure and security programs that kept 50+ small and mid-sized businesses running and protected.
In that time I watched the same thing happen over and over. A business gets a cyber-insurance renewal and can't prove its controls, so the premium jumps or the policy is denied. A major client sends a security questionnaire and a good company can't answer it. Someone gets quoted $10,000 or more for a security audit and walks away — not because they don't care, but because they genuinely can't justify the cost.
None of those businesses were reckless. They just had no affordable, honest way to find out where they actually stood. So I built one.
CRJ Security is the assessment I wish I could have handed those companies — grounded in the same NIST CSF 2.0 and CIS Controls frameworks I used in the field, delivered without the consulting price tag or the sales pressure. And if you ever want to talk through your results with a real person, I'm reachable.
One assessment. One report. No strings.
Free score to start. Buy the full report only if it's what you need. Yours to keep and hand to whoever's asking.
Get my free security score →Free score · full report $750 · less than 24 hours