Before anything is billed
Scope is agreed up front, not discovered along the way
The discovery call exists to protect your budget as much as ours — nothing moves to the assessment stage until scope, timeline and cost are clear.
Discovery & scoping
A short, no-obligation call to understand your business, current controls and where the risk actually sits.
Assessment
Your vCISO reviews existing policies, architecture and processes, and speaks with key staff to test how things really work.
Roadmap
A prioritised, costed plan — mapped to the five pillars — showing what to fix first and what it will take.
Ongoing advisory
Regular working sessions, board-ready reporting, and hands-on support as your risk landscape and business evolve.
Ways to retain us
Three engagement options, scaled to how much security leadership you need
Most clients start with a discovery call and settle on one of the following — though the model can flex as your organisation grows or your risk profile changes.
Advisory Retainer
A fixed number of days per month for ongoing strategic input, board reporting and hands-on guidance to your team.
Fractional CISO
A part-time, named vCISO who effectively acts as your head of security — attending leadership meetings and owning the roadmap.
Project-Based
A defined piece of work — a certification push, an incident response build, a risk assessment — delivered to a fixed scope and timeline.