Pricing

Fixed-scope projects.
Retainers with an owner.

A quote reflects headcount, cloud and tenant count, and how many compliance frameworks are in scope. The quote is fixed — scope changes go through change orders.

Billing
Monthly
Per-ticket charges
None

Retainers

Three levels of ownership.

Pick the level of the function you want to hand over. Modules can be added to any tier.

Essentials

Companies without a cybersecurity owner that need an owner for cybersecurity operations.

Contact Us

  • Cybersecurity roadmap ownership and quarterly strategy review
  • Identity and access hardening — SSO, MFA, privileged access
  • Customer cybersecurity questionnaire support
  • Cybersecurity metrics and reporting
Scope Essentials
Most common

Managed

Teams preparing for SOC 2 or HIPAA without owners for identity, endpoints, or evidence.

Contact Us

  • Detection rules, alert triage and escalation
  • MDM deployment and endpoint management — Intune, Jamf or Kandji
  • Google Workspace or M365 administration and hardening
  • Policy authoring, control mapping and evidence collection
  • Auditor liaison and monthly compliance reporting
Scope Managed

Complete

Companies handing over the cybersecurity and IT function outright.

Contact Us

  • Cybersecurity architecture for new systems and major changes
  • Detection engineering, investigation and incident response
  • IT operations, MDM and identity administration
  • GRC, audit readiness and customer diligence
  • AWS account structure, IAM and cloud monitoring
  • Infrastructure-as-code review and guardrails
Scope Complete

Comparison

Module coverage by tier.

Add-ons are available on any tier and priced separately.

Swipe to compare all columns.

Cybersecurity and IT modules included in each retainer tier
ModuleEssentialsManagedComplete
Cybersecurity ProgramIncludedIncludedIncluded
Detection & ResponseIncluded
IT OperationsIncludedIncluded
GRC & AuditIncludedIncluded
DevOps & CloudIncluded
Application SecurityAdd-onAdd-onAdd-on
vCISOAdd-onAdd-onAdd-on

Projects

Fixed-scope work, without a retainer.

Useful when there is one deadline to clear rather than a function to hand over.
01

Cybersecurity Baseline Assessment

Attack-surface map, identity and access review, endpoint posture, prioritized remediation backlog, findings readout.

02

SOC 2 Readiness Sprint

Gap assessment, policy set, control implementation, evidence workflow, auditor selection support, readiness sign-off.

03

HIPAA Readiness Sprint

ePHI data-flow mapping, risk analysis, policies and BAAs, safeguards implementation, attestation package.

04

Cloud Security Hardening

IAM review and least-privilege rework, network and secrets management, logging and alerting, backup and recovery validation.

05

Identity & MDM Rollout

SSO and MFA deployment, MDM enrolment, onboarding and offboarding runbooks, Workspace or M365 hardening.

06

Incident Response Plan + Tabletop

IR plan, escalation paths and severity model, facilitated tabletop exercise, after-action report.

Next steps

How a quote gets made.

No workshop series and no 40-page assessment before anything gets fixed.
  1. Step 01

    Discovery call

    45 minutes on the problem to solve, the systems involved, and the role we would carry.

  2. Step 02

    Cybersecurity baseline

    Current controls, gaps and priorities documented so the proposal is scoped to reality.

  3. Step 03

    Proposal

    A fixed-scope proposal with a quote, back within 48 hours.

  4. Step 04

    Kickoff

    Work starts in your stack 1–2 weeks after scope approval.

Send the systems and the scope.

Headcount, cloud accounts, audit date and the role that needs an owner. We come back inside 48 hours with a fixed quote.