How we work

Defined scope, a firm price before you commit, and a handover that leaves your team able to run it without us.

A typical engagement

01

Assessment call

A short call to understand what's driving the work and what "done" looks like. No cost, no obligation.

02

Scope & proposal

We come back with a defined scope, the deliverables, a realistic timeline and a fixed or capped price. You see exactly what you're buying.

03

Gap assessment

Most engagements start by assessing where you are against the target — a framework, a benchmark, or a specific threat model — and turning that into a prioritised plan.

04

Implementation

We work alongside your team to close the priority gaps: policies, controls, tooling, evidence. You keep ownership; we bring the method and the hands.

05

Readiness & handover

Before any audit or launch, a readiness review. Afterwards, everything is documented so your team can run it without us.

How pricing works

We don't publish fixed price lists because the range is too wide to be honest without your scope. Here's how it actually works.

Fixed-scope projects

Assessments, penetration tests, ISO 27001 or SOC 2 readiness — priced as a fixed fee against a written scope once the assessment call has defined it.

Retained / fractional

Virtual CISO and ongoing GRC support — a set number of days per month at a monthly rate, adjustable as needs change.

What drives the number

Scope size (systems, people, locations), the framework, your starting point, and how much you want us to do versus guide. We confirm all of this before you commit.

Questions

Start with a short assessment call

A 30-minute call with a security architect to map where you are against the framework you need and agree the next step. No obligation, no sales sequence.