Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Digital forensics, incident response and managed IT in Montana

IT and cybersecurity for Montana businesses that can’t afford compromise.

Your provider says it’s handled. We’re the team that gets called when it wasn’t, so we build managed IT from that side of the problem.

“We transitioned from an in house server to a cloud based server and it has been seamless and absolutely no down time in the transition.”
Tera R., Montana client
A small team gathered around a tablet, talking through a plan
50+
Organizations served
across Montana
7,500+
Devices monitored
under current contracts
10 min
Median first response
for security issues, measured in our own system over the last 90 days
100+
Incidents supported
by our team
5.0
On Google and Birdeye
Our standard

Most IT providers ask for your trust. We put ours in writing.

Every certified client is assessed by a third party risk assessor and keeps the required controls in place. For those clients, we do the response work at no added cost and back our services with a written warranty.

Ransomware
● Response within 1 hour
Business email compromise
● Response within 1 hour
Backup recovery failure
● Response within 4 hours
The Big Sky Guarantee
We do the work.

Containment, forensics, eradication, recovery, and rebuilding if needed, at no additional cost, within defined service limits.

The Big Sky Guarantee is not an insurance policy. It’s our commitment to do the response work ourselves.

PLUS
The Big Sky Service Warranty
Up to $500,000

Eligible payments made directly to the organization, up to $500,000 per covered incident, depending on plan.

The Big Sky Service Warranty is not an insurance policy and does not replace cyber insurance.

For certified clients on Professional, Enterprise, or co-managed plans, with required controls in place. Eligibility requirements, service limits, and exclusions apply. Full terms are provided for your review before you sign. See which plans qualify

Why Big Sky exists

Your IT provider should have skin in the game.

We’ve spent years responding to compromised mailboxes, ransomware, and failed equipment that stopped local businesses cold. Different causes every time but with the same question afterward: who pays for this?

Where incidents usually start
  • 01Updates ignored
  • 02Old staff accounts left open
  • 03Backups never tested
  • 04Security software never installed
  • 05No roadmap for aging equipment
What we believe
Your IT provider should share responsibility.

Most incidents we've responded to start small. The business usually absorbs the cost of the cleanup on top of what it already pays for IT. We think the provider should carry part of that weight.

How we put it into practice
A standard that catches it early.

Every client environment is held to one standard: patches, accounts, backups and security software checked on a schedule, and a roadmap for what’s aging out. A third party risk assessor reviews our environment, our policies and playbooks, and the controls we put in place for clients.

How it’s backed
In writing, not just in the sales pitch.

For certified clients, The Big Sky Guarantee means we do the response work ourselves, within defined service limits. The Big Sky Service Warranty adds eligible payments up to $500,000 per covered incident, depending on plan.

For certified clients. Eligibility requirements, service limits and exclusions apply. Neither is an insurance policy, and the warranty does not replace cyber insurance.

See which plans qualify
Dawn Van Zandt, founder of Big Sky Cybersecurity

Dawn Van Zandt

Founder, Big Sky Cybersecurity

Read how Big Sky started →

From the founder

“We’ve been supporting Montana businesses since 2013. Along the way, the calls started coming from businesses that weren’t ours. Hacked laptops. Email accounts they were locked out of. Ransomware on a Friday afternoon. Same causes most of the time: an old password, an untested backup, an inbox somebody had been in for weeks. Clinics, law offices, family businesses. None of them could afford a week offline and very few could handle the cleanup.

Every IT provider says they’ll stand behind their work. When it goes wrong, most hand you an invoice. We hand you our team and we put our response and warranty in writing.”

If you’re done with “IT that's up” and want to see IT done correctly, call us.

Qualifications our team holds

Given that I was 11 time zones from Great Falls, they made themselves available until the issue was addressed and remedied.

Michael W.

How we work with clients

3 ways to work with our team.

Most clients arrive through one and stay. Each card goes to that service’s page.

Digital forensics and incident response

Digital forensics and incident response

We contain the threat, image the affected devices and keep documented chain of custody. $165 an hour, or under The Big Sky Guarantee for certified clients.

Incident response
Managed IT built security first

Managed IT, built security first

Fully managed infrastructure and support from $75 per device per month, plus a per user charge, with no hourly remote billing and no annual escalators.

Managed IT
Offensive testing and compliance

Offensive testing and compliance

Manual penetration testing by certified testers, plus ongoing HIPAA, PCI and GLBA compliance support with documentation prepared for audits.

Penetration testing and compliance
What the work looks like

Three Montana engagements.

What each client was facing, what we did, and what changed. The full writeups are one click away.

01

The incident was “closed”. The attacker was still in.

A Montana organization's mailbox was compromised, then another provider declared it handled.

✓Sessions revoked and access removed

✓MFA enforced on every account

✓Timeline built for law enforcement

Read the case study

02

One public IP, two vendors sitting on the internet.

A rural clinic assumed a single public IP meant a small attack surface.

✓Legacy any/any firewall rules closed

✓Exposed vendor equipment found and fixed

✓90 day retest that protected grant funding

Read the case study

03

One departing admin held five sets of keys.

Nobody could say what he could still reach across finance, HR, banking and collaboration tools.

✓Every account and entry point inventoried

✓Devices examined with forensics

✓Lockout verified and monitoring added

Read the case study

Want this roadmap for your own systems? The assessment is free: 30 to 45 minutes onsite and the findings are yours either way. Not ready to talk yet? Read the signs your managed IT isn’t really managing anything.

Book a free assessment
Aerial view of Great Falls, Montana
What we hear

Six things we hear from businesses when they call.

What we hear

How we support

01

We have someone out of state, but it's sporadic when they're onsite.

Remote support works until you need someone in the building. We're local in Great Falls, Billings and Helena.

02

Our provider caused an incident, won't pay for it, and gave us 30 days notice.

This is why we put ours in writing: certified clients get the response work under The Big Sky Guarantee, and both of us keep the required controls in place.

03

We don't have IT. The network's slow and the wireless keeps dropping.

You don't need a crisis to fix it. We assess what you have and schedule the work around your hours.

04

We've been hit with ransomware and we don't understand negotiation or forensics.

We contain it, preserve evidence, find out what happened and work with your insurer and legal counsel.

05

We need compliance help and don't know where to start.

We show you where you stand on HIPAA, PCI, GLBA and insurance requirements before any long term program.

06

We already have IT and we're not looking to replace them.

You don't have to. We work alongside internal teams and existing providers on security and incident response.

Switching

You already have somebody. Here's exactly how leaving works.

Across 50+ transitions, no client has lost a working day. We take on no more than six new clients a month, so every cutover gets the whole team's attention.

Days 1–5

We document before we touch anything

Licenses, credentials and backups — yours to keep either way.

Days 6–10

Monitoring runs alongside

Next to your current provider. You're never without support.

Days 11–14

Cutover, around your calendar

During business hours or after, whichever disrupts you least.

Client outcomes

What our clients say

“They understand that small communities have different needs and resources than large organizations. They take the time to understand how a town operates and recommend security measures that are practical, effective, and make sense for a small municipality.”

Loren T., Mayor of Fairfield

“Even though we call because we have a problem, Dawn and James are eager to help us get our system on track again. Would highly recommend for anyone wanting fantastic service.”

Ashley B., Accounting firm

“Big Sky Cybersecurity consistently goes above and beyond to support our needs as a non-profit business. They are so responsive and always give us the level of support and expertise we need to keep our systems and data safe.”

Melissa T., Nonprofit

Honest fit

Where we’re not a good fit.

01
You want the lowest cost IT option.
If the deciding factor is the cheapest monthly rate or break fix support, we’re not the right choice.
02
Security is a checkbox for you.
If protection exists only for an auditor, we won’t be a good fit, and we’d rather say so now.
03
You prefer reactive support.
Our model is built around prevention, not break fix response after something has already gone wrong.
FAQ

Frequently asked questions

Can you help us with a cyber incident if we're not a client?

Yes. Call 406-924-3731. We take incident response engagements from organizations we've never worked with, including referrals from other IT providers when a client of theirs needs digital forensics support. $165/hour, no emergency or after hours surcharge, with documented chain of custody for insurers, counsel and courts.

What kinds of organizations are the best fit?

Small and midsize organizations where data security, compliance and continuity aren't optional: healthcare practices, dental groups, legal firms, financial advisors and professional services. If you have between 10 and 250 staff and protect sensitive client or patient data, we're likely a strong fit.

Do you only work with healthcare organizations?

No. Healthcare is a significant part of our work because HIPAA obligations and patient care continuity make the stakes explicit, but we support legal firms, financial institutions and any organization carrying real risk exposure.

How is Big Sky different from a general IT provider or MSP?

We're a digital forensics and incident response firm that also runs managed IT. We built the managed IT side on that forensics foundation, which is why other providers call us in when a client of theirs needs digital forensics support.

How does certification work?

Once you sign on to our Professional package or co-managed services, we handle the rest. We put the required controls in place, walk your environment with our third party risk assessor, and provide your certification. From there, we maintain those controls with you so you stay certified. Certified clients get The Big Sky Guarantee and The Big Sky Service Warranty. Eligibility requirements, service limits and exclusions apply. Full terms are provided for your review before you sign.

Are The Big Sky Guarantee and Service Warranty a type of cyber insurance?

No. The Big Sky Guarantee is not an insurance policy. It's our commitment to do the response work ourselves. The Big Sky Service Warranty is not an insurance policy and does not replace cyber insurance, so we recommend keeping a cyber insurance policy. Full terms are provided for your review before you sign.

Can we get pricing guidance before a formal proposal?

Yes, and you can get it without talking to us. Managed IT starts at $75 per device, and every price we charge is published on our pricing page.

What should we expect in the first 30 days?

We start with an assessment of your existing environment. In most cases you won't need new hardware for us to take over. We work alongside your internal staff to transition without disrupting operations, and you'll know what needs addressing now versus what can wait.

We're in the middle of a contract with our current provider. Can we talk?

Yes. Most agreements have a notice period, and we'll tell you what yours says before you commit to anything. We've also started plenty of engagements alongside an existing provider rather than replacing one.

We've never had an IT provider. Where do we start?

With an assessment of what you already have. Usually no hardware purchase is needed, and we'll tell you what needs fixing now versus what can wait.

HOW IT STARTS

Let's talk about what you need.

No contract before you've seen the findings. Here's what happens:

01

You call or send the form. 406-924-3731 rings in Great Falls, and you hear back the same day. After hours, incidents still get a call back that night; everything else, first thing the next morning.

02

A technician comes to you, not a salesperson: 30 to 45 minutes onsite looking at your network, backups and email security.

03

We walk you through the findings on a short call, then you keep the written report. The assessment is free, and the findings are yours either way.

04

You get a written scope and a fixed price. Managed IT starts at $75 per device, and every price is published.

Our offices on Google

DIRECT LINE
406-924-3731

Call during business hours and you'll talk to someone the same day. After hours, incidents still get a call back. Serving Great Falls, Helena, Billings, and across Montana.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.