Frequently asked questions
Know what you are—and are not—buying.
Clear expectations reduce risk for both sides and help determine whether Prometheus is the right fit.
Is Prometheus an MSP or MSSP?+
No. Prometheus provides focused cybersecurity consulting, advisory, and implementation support. That keeps recommendations vendor-neutral and avoids managed-services lock-in. Monitoring or emergency response is included only when expressly defined in a written engagement.
What types of organizations are the best fit?+
Prometheus is designed primarily for New Jersey municipalities, K-12 districts, and small or mid-sized organizations that need senior cybersecurity judgment but may not have a full internal security leadership team. Healthcare, biotech, and retail environments are also supported where the engagement fits Prometheus capabilities.
What does AI security and governance support include?+
Prometheus helps organizations identify AI use cases, data exposure, vendor and model dependencies, policy gaps, and risks created by copilots, generative AI applications, agents, tools, and MCP-connected systems. The focus is a practical control and governance roadmap. Specialized model testing or AI red teaming is included only when expressly defined in scope.
Can you help implement recommendations after an assessment?+
Yes. The model is intentionally assessment-to-action. Implementation support can include policies, workflows, remediation planning, reporting, governance, tabletop improvements, and coordination with your existing IT team or service providers.
Do you guarantee compliance or that a breach will not occur?+
No responsible cybersecurity firm can make either guarantee. Prometheus helps organizations make defensible, risk-informed improvements and align work to applicable frameworks or requirements. Final compliance determinations may require legal, regulatory, or independent audit expertise.
How are scope, timing, and fees established?+
A short fit conversation identifies the problem, environment, stakeholders, and desired outcome. Prometheus then proposes a defined scope, deliverables, timeline, assumptions, and fee structure. Fixed-scope, targeted hourly, and recurring advisory options are available; public pricing is intentionally not posted because scope varies materially.
How should sensitive information be shared?+
Do not place credentials, vulnerability evidence, regulated records, or other sensitive data in the website form or ordinary email. The initial request should contain business context only. A secure, engagement-appropriate exchange method can be established after fit and confidentiality requirements are confirmed.