Get Started

    Start with a clear answer, not a sales pitch.

    The hardest part of security is knowing where you actually stand. Every engagement below starts there: a senior practitioner reviews your program, shows you the gaps that matter, and gives you a plan you could hand to your board. Pick the door that fits.

    Most popular starting point

    Fixed-Fee Security Posture Assessment

    In two to three weeks, we baseline your entire program against NIST CSF 2.0, across risk, compliance, vendors, and response. You get a written posture report, a board-ready summary, and a prioritized 90-day roadmap. Fixed price, fixed scope, no open-ended discovery.

    Ours is fixed-fee: typically $7,500 to $15,000 depending on your size and scope, and credited toward your program if you move forward with an ongoing vCISO engagement. For larger or heavily regulated organizations, a comprehensive engagement that adds penetration testing and full compliance readiness runs $25,000 to $50,000. Either way, you know exactly what you are buying before you commit to a retainer.

    Investment

    $7,500 to $15,000

    Fixed-fee, credited toward your program

    What you get

    • Full NIST CSF 2.0 baseline across every pillar
    • Written posture report with prioritized findings
    • Board-ready executive summary
    • 90-day remediation roadmap
    • Fee credited toward your first 3 months of vCISO

    More ways to start

    Focused engagements for a specific problem.

    Already know your pain point? These are scoped, fixed, and fast, and each one leads naturally to the next step if it makes sense.

    Ransomware Readiness Assessment

    A focused review of the controls that decide whether an incident is a bad afternoon or a shutdown: identity, segmentation, backups, and response. Includes a tabletop with your team.

    Compliance Gap Assessment

    SOC 2, ISO 27001, HIPAA, CMMC, or PCI DSS 4.0. We scope your environment, measure it against the framework, and hand back a gap analysis mapped to a realistic certification timeline.

    AI & Agent Security Assessment

    If you ship AI features or run agents against real data, you have a new attack surface. We assess model, data, and agent access, grounded in our AI Agent Security Report research.

    Board Security Briefing

    We produce one board-ready security narrative for your next meeting: posture, top risks, and the plan, in language leadership actually uses. A fast way to see the work firsthand.

    Security Questionnaire Rescue

    Stuck on an enterprise security review or RFP that is holding up a deal? We help you answer it credibly and fix what the answers expose, so the deal moves.

    Tabletop Exercise Workshop

    A facilitated incident simulation with your leadership team. It builds real readiness and surfaces the gaps worth fixing, without waiting for a live incident to find them.

    Vendor & Third-Party Risk Snapshot

    An external attack-surface scan plus a review of your most critical vendors, summarized into the risks that matter and what to do about them first.

    vCISO First 30 Days

    A fixed-fee starter month: assessment, a working risk register, early quick wins, and one board-ready artifact. The lowest-risk way to try a fractional CISO before a retainer.

    Next step

    Thirty minutes, then a real plan.

    Tell us what is keeping you up at night. We will point you to the right starting engagement, or tell you honestly if you do not need one yet.