Get Started
Start with a clear answer, not a sales pitch.
The hardest part of security is knowing where you actually stand. Every engagement below starts there: a senior practitioner reviews your program, shows you the gaps that matter, and gives you a plan you could hand to your board. Pick the door that fits.
Most popular starting point
Fixed-Fee Security Posture Assessment
In two to three weeks, we baseline your entire program against NIST CSF 2.0, across risk, compliance, vendors, and response. You get a written posture report, a board-ready summary, and a prioritized 90-day roadmap. Fixed price, fixed scope, no open-ended discovery.
Ours is fixed-fee: typically $7,500 to $15,000 depending on your size and scope, and credited toward your program if you move forward with an ongoing vCISO engagement. For larger or heavily regulated organizations, a comprehensive engagement that adds penetration testing and full compliance readiness runs $25,000 to $50,000. Either way, you know exactly what you are buying before you commit to a retainer.
Investment
$7,500 to $15,000
Fixed-fee, credited toward your program
What you get
- Full NIST CSF 2.0 baseline across every pillar
- Written posture report with prioritized findings
- Board-ready executive summary
- 90-day remediation roadmap
- Fee credited toward your first 3 months of vCISO
More ways to start
Focused engagements for a specific problem.
Already know your pain point? These are scoped, fixed, and fast, and each one leads naturally to the next step if it makes sense.
Ransomware Readiness Assessment
A focused review of the controls that decide whether an incident is a bad afternoon or a shutdown: identity, segmentation, backups, and response. Includes a tabletop with your team.
Compliance Gap Assessment
SOC 2, ISO 27001, HIPAA, CMMC, or PCI DSS 4.0. We scope your environment, measure it against the framework, and hand back a gap analysis mapped to a realistic certification timeline.
AI & Agent Security Assessment
If you ship AI features or run agents against real data, you have a new attack surface. We assess model, data, and agent access, grounded in our AI Agent Security Report research.
Board Security Briefing
We produce one board-ready security narrative for your next meeting: posture, top risks, and the plan, in language leadership actually uses. A fast way to see the work firsthand.
Security Questionnaire Rescue
Stuck on an enterprise security review or RFP that is holding up a deal? We help you answer it credibly and fix what the answers expose, so the deal moves.
Tabletop Exercise Workshop
A facilitated incident simulation with your leadership team. It builds real readiness and surfaces the gaps worth fixing, without waiting for a live incident to find them.
Vendor & Third-Party Risk Snapshot
An external attack-surface scan plus a review of your most critical vendors, summarized into the risks that matter and what to do about them first.
vCISO First 30 Days
A fixed-fee starter month: assessment, a working risk register, early quick wins, and one board-ready artifact. The lowest-risk way to try a fractional CISO before a retainer.
Next step
Thirty minutes, then a real plan.
Tell us what is keeping you up at night. We will point you to the right starting engagement, or tell you honestly if you do not need one yet.