Working With Us
What does the process look like?
Reach out through the contact form or email [email protected]. We reply personally with a link to schedule a free intro call — no prep, no pitch, just enough time to confirm Trailhead is the right fit for what you’re dealing with.
During that call, I take notes while we talk. Right after we hang up, I send you a preliminary itemized estimate. Once you’ve reviewed and approved it, a QuickBooks invoice goes out — and as soon as it’s paid, you’ll automatically receive a link to book your 1-hour tech consultation. No back-and-forth needed.
On that consultation, I walk through your environment and priorities with you in detail. I handle all the documentation — there’s nothing for you to fill out or prepare on either call. Afterward, I deliver your full IT assessment and prioritized roadmap.
How is an IT Assessment priced?
IT Assessments are fixed-fee projects. Pricing is based on three factors: organization size (number of employees), the number of domains your business owns, and any optional add-ons you choose.
The full flow — from intro call to delivered report — is described in What does the process look like? above. There are no surprise fees and no open-ended retainers.
Optional add-ons include a phishing simulation (a controlled test of how your staff responds to phishing emails), an internal network infrastructure scan, and cloud platform security reviews for Microsoft 365 or Google Workspace.
Do you offer ongoing re-assessments?
Yes. After the initial assessment, you can subscribe to recurring re-assessments on a quarterly or annual basis. Each cycle re-runs the full assessment suite and delivers an updated report — so you can track progress and stay ahead of new threats.
We also offer independent advisory support on an on-demand hourly basis for clients who want a trusted contact without a recurring schedule, billed at $125/hr with a 2-hour minimum.
How long does an IT Assessment take?
A typical IT Assessment takes two to four weeks from kickoff to delivered roadmap, depending on organization size and how much documentation already exists. We move at a pace that works for you — we know your team has day-to-day responsibilities.
What happens after the assessment?
You receive a written report and roadmap you can act on immediately — whether that means tackling projects yourself, handing it to a vendor, or continuing to work with Trailhead. There’s no obligation to continue. Many clients do choose to engage on a recurring basis so the roadmap stays current as their business evolves.
What We Do (and Don’t Do)
Do you provide ongoing IT support or manage our systems?
Trailhead is a consulting and advisory practice — we help you build a clear technology strategy, plan the right projects, and make better decisions. We don’t manage your day-to-day IT or act as your on-call tech team. If you need hands-on managed support, we can help you identify the right partner for your organization — and stay independent while doing it.
Do you sell hardware, software, or cloud services?
No. Trailhead does not resell hardware, software licenses, or cloud services. We have no vendor affiliations and no referral kickbacks. Our only incentive is giving you the right advice. We keep a vendor-neutral mindset in every evaluation and can work within your existing stack or help you select a better-fit option when needed.
What services do you offer?
We offer three core services. Technology Assessment is a thorough review of your entire technology environment — infrastructure, security, web presence, and software — with a clear report and prioritized roadmap for what to do next. Vendor Proposal Review is a flat-fee, independent analysis of an IT contract or vendor proposal you’ve received — we explain what you’re agreeing to, flag anything unusual, and give you an honest opinion before you sign. Ongoing Advisory keeps that roadmap current on a quarterly or annual basis, giving you an independent advisor to call before you commit to a technology decision. All three are scoped upfront with fixed deliverables and no ongoing commitments unless you choose them.
Common IT Situations
What should I do if a business email account gets hacked?
Act immediately from a device you trust. Change the password, enable two-factor authentication, then check your email settings for rules you didn’t create — attackers often set forwarding rules to silently copy messages, or inbox rules that delete replies to fraudulent emails. Check your sent folder for messages you didn’t send, and notify your bank or payroll provider if those accounts use the same email for login or recovery.
Once the immediate crisis is contained, a technology assessment can help you understand how it happened and close the gaps. Most small business email breaches trace back to a weak or reused password, missing two-factor authentication, or a phishing link clicked weeks earlier.
How does cyber liability insurance relate to IT?
Cyber liability insurance covers costs associated with a data breach or cyberattack — legal fees, notification costs, recovery expenses, and sometimes business interruption losses. Most carriers now require businesses to meet a baseline of security controls before they’ll bind coverage, and they ask about it on the application.
Common requirements include: multi-factor authentication on email and remote access, documented backup procedures, and basic employee security training. If you apply and answer these questions inaccurately, a claim can be denied later. A technology assessment helps you answer those questions honestly — and fix the gaps before you apply.
What are my legal obligations if my business has a data breach in New England?
All six New England states have data breach notification laws that require businesses to notify affected individuals — and in most cases the state Attorney General — if personal information is exposed. The thresholds, timelines, and definitions of “personal information” vary by state. Vermont requires notification within 45 days. Massachusetts requires “as soon as reasonably possible.” Connecticut allows up to 60 days. These obligations apply regardless of business size.
The most important thing to know before a breach happens: you need to know what data you have and where it lives. If you don’t know what customer information is stored on your systems, you can’t assess your exposure when something goes wrong. That’s one of the core things a technology assessment documents. Verify current obligations with your state Attorney General or legal counsel — laws update and specifics matter.
What’s the difference between an MSP and an independent IT consultant?
A managed service provider (MSP) is a company that manages your IT infrastructure on an ongoing basis — monitoring systems, running a help desk, handling software updates, and responding to issues. They typically charge a monthly per-device or per-user fee and are the right fit for businesses that need continuous hands-on IT support.
An independent IT consultant like Trailhead works differently. We don’t manage your systems or run a help desk. We help you understand your technology environment, make smarter decisions, and avoid getting steered wrong by vendors who have a financial interest in what you buy. We have no products to sell and no referral arrangements — our only incentive is giving you accurate advice. Many businesses use both: an MSP for day-to-day support, and an independent consultant to evaluate whether that MSP relationship is the right fit and the right price.
What should I do with IT access when an employee leaves?
The same day they leave — not the following week. Disable or transfer their business email, change any shared passwords they knew (Wi-Fi, point-of-sale, accounting software), and remove them from cloud storage, payroll, and banking portals. Also check whether their personal email is set as a recovery contact on any business accounts — a common oversight that leaves access open long after someone has gone. If you’re not sure you’ve covered everything, a technology assessment documents your full vendor and access inventory so future offboarding is a checklist instead of a scramble.
Is This Right For Us?
We’re not a technology company — is this still relevant?
Absolutely. Most of our clients are not technology companies — they are professional services firms, nonprofits, construction companies, healthcare practices, and other New England businesses that rely on technology to operate but don’t have dedicated IT staff. That is exactly who we built this practice for.
We already have an IT person or vendor. Can Trailhead still help?
Yes — and this is actually one of the most common situations we work in. Your IT vendor has a financial interest in what they recommend. Trailhead doesn’t. Many clients use us as an independent layer on top of their existing IT support: reviewing vendor proposals before signing, evaluating whether their current MSP is the right fit, or helping leadership understand what they’re actually getting from their IT spend. We’re not here to replace your vendor — we’re here to make sure you have someone in your corner who isn’t selling you something.
Which states do you serve?
We serve organizations across all of New England: Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, and Vermont. Trailhead is based in Vermont and most engagements can be conducted remotely, with on-site visits available as needed.