Currently dealing with a breach or active incident?Call 406-924-3731×
≡
About Big Sky

Montana's organizations call us when something's gone wrong.

Most of them stay so it doesn't happen again.

Big Sky Cybersecurity Inc. investigates breaches and helps reduce the risk of the next one, from offices in Great Falls, Billings and Helena and staff across the state.

When an insurer or an auditor asks who looked at your systems, our credentials are the ones they recognize.

Great Falls · Billings · Helena · Staff across MontanaGiant Springs Park in Great Falls, Montana
50+
Montana organizations
2013
Our team serving Montana
supporting businesses and nonprofits across the state
3
Montana offices
5.0
On Google and Birdeye
Read our Google reviews
Why we exist

We started this after watching it happen to a neighbor.

Big Sky Cybersecurity started with something we kept seeing in her own community: a local business hit by a cyberattack and a community business gone in months. Those weren't big companies with security teams. They were clinics, law firms, and small family run businesses that couldn't afford being down or the response. Today more than 50 organizations including clinics, law firms, accounting firms and small businesses rely on our team.

Big Sky Cybersecurity Inc. was founded in 2023 and is Montana owned and women owned (WOSB certified). Our team has supported Montana business and K12 technology since 2013 through Schoolhouse IT as well.

The people behind it
Dawn Van Zandt, founder of Big Sky Cybersecurity
Founder

Dawn Van Zandt

Dawn leads our forensics work. When something goes wrong, she figures out exactly what happened and turns it into a clear timeline you can act on. Her focus is clinics, law firms and Montana businesses that can't afford downtime.
GCFAGCFEGNFAGCIH
James Krippes, Vice President of Big Sky Cybersecurity
Vice President

James Krippes

James has spent more than 20 years in technology, including running Schoolhouse IT for K12 schools. He builds our managed IT around how your organization actually works, and he's in it for the long haul.
CISSPCySA+Project+
What we value

Three things guide every decision we make.

Secure every step

We fit the work to your business, not a template. Every change has a reason, and you'll know what it is.

Lead with expertise

We don't just do the work. We help you figure out what you actually need, then tell you straight, even when the answer is "you don't need us for that."

Protect today, plan for tomorrow

We fix what matters now and get you ready for what's coming next, without selling you things you don't need.

Your story

Sound familiar?

We hear the same frustrations from owners all over Montana. None of them are your fault, and every one of them has a fix you can see.

“

Your IT guy keeps coming out. It works while he's there but stays an issue.

What changes

We fix the cause, then show you the note that says what it was.

“

Somebody reboots the switch and it works again. Until Thursday.

What changes

We map the network first, and you keep the diagram either way.

“

You approve the invoice. You've never seen anyone check the backups.

What changes

Restores tested on a schedule, with the date written down.

“

The insurer's questionnaire takes three weeks to answer.

What changes

We answer it from evidence we already keep, usually in days.

“

Something breaks, and then a second bill arrives.

What changes

Flat monthly pricing, and every price is published.

“

Your one IT person is carrying the whole thing alone.

What changes

We back them up, without replacing them.

Our standard

5 things we check every month. And what the report shows you.

Most incidents we respond to start with one of these five. Here’s how our standard handles each one, and what you see in your monthly report.

01
Updates ignored

Patches applied on a schedule, including third party software, not only Windows.

02
Old staff accounts left open

Access removed when someone leaves, and every account reviewed each month.

03
Backups never tested

Backups proven by restoring them every month, not just by checking that they ran.

04
Security software never installed

Endpoint detection on every device, monitored by our team.

05
No roadmap for aging equipment

A five year roadmap of what’s aging out and when to budget for it, reviewed with you.

What you receive
Monthly report
October 2026
Sample client · 42 devices
Patch status for every device✓ Checked
Account review, and anything removed✓ Checked
Restore test results✓ Checked
Coverage by device, and anything caught✓ Checked
What’s approaching end of support✓ Checked
Illustrative sample. Your report covers your own environment.
How working with us starts

Three steps before anything changes.

A 30 minute call

With one of our security engineers. Nothing installed, nothing scanned.

We look at what’s really there

What’s on your network and how it’s set up, onsite if it helps.

You decide what to fix, and who fixes it

The findings are yours either way, whether we do the work or your current provider does.

Already have a provider? See exactly how switching works. It takes about two weeks, and nothing is touched until it’s documented.

Who you'll work with

The people behind your account.

When you call

The helpdesk

Answered in Montana, 8 to 5 on weekdays, with someone on call outside those hours.
When it needs hands

Your onsite engineer

Same day onsite for contract clients, from our offices in Great Falls, Billings and Helena and our staff across Montana.
Around the clock

Security monitoring

Watching your network while you're closed, and escalating what matters.
If something goes wrong

Forensics team

The investigation your insurer and attorney will ask about, led by the founder.
You'll have everyone's names and direct numbers from onboarding.
What our team is trained to do

Training that covers forensics, offensive testing, and security operations.

01
Tell your insurer what happened, in a form they'll accept
Forensic findings built to the standard insurers and examiners expect.
03
Determine whether anything actually left your network
What your counsel needs to decide whether you're required to notify anyone.
05
Watch, harden, and respond day to day
Monitoring and response run to a documented standard.
02
Reconstruct a single computer's history
What opened, when, and who did it including a timeline your attorney can use.
04
Break into your systems on purpose
Offensive testing, done before someone does it for real.
06
Keep the ordinary things working
The everyday infrastructure the rest of it rests on.
Electric Peak in the Montana corner of Yellowstone
Next step

Book a quick call with our team.

You describe what you need help with. We tell you whether it's a real risk or a nuisance. Nothing installed, nothing scanned.

01
Want to talk it through?
Book the call. It's free and it's with a tech not a sales rep.
02
Ready for someone to look?
The assessment is free: 30 to 45 minutes onsite, and the findings are yours either way.
03
Rather see numbers first?
Every price we charge is published. See pricing
5.0 on Google and Birdeye · Or call 406-924-3731
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We reply within one business day. No commitment, no sales pressure.