Services & Pricing

Consulting Packages

Fixed-scope engagements with defined deliverables, clear timelines, and measurable outcomes. No hourly billing. No ambiguity. You know exactly what you're getting — and what it costs — before we begin.

Fixed-scope, fixed-price
Executive-ready deliverables
US & UK regulatory expertise
100% remote delivery
PACKAGE 01 2 weeks · Remote

Security Risk Assessment

"Know your exposure before your attackers do."

A structured assessment of your organisation's security posture — identifying the gaps that represent the greatest business risk. Designed for boards, CFOs, and leadership teams who need clarity on where they stand, not a 200-page technical document nobody reads.

What's Included

  • Discovery questionnaire and stakeholder interviews
  • Assessment against NIST CSF and ISO 27001 controls
  • Prioritised risk register with business impact ratings
  • Executive summary (board-ready, 2 pages)
  • Technical findings report with remediation priorities
  • 60-minute executive debrief call

Ideal For

Organisations preparing for cyber insurance renewal, M&A due diligence, regulatory audit, or board-level security review. Also suitable as a starting point before any larger engagement.

Investment

$5,000

Fixed fee · No hidden costs

Timeline 2 weeks
Delivery 100% Remote
Frameworks NIST · ISO 27001
Regions US · UK · EU
Enquire About This Package →

Response within 2 business days

PACKAGE 02 2–3 weeks · Remote

Data Protection & Privacy Audit

"Turn compliance from a cost centre into a competitive advantage."

A comprehensive audit of your data protection practices against GDPR, UK DPA 2018, and CCPA obligations. Identifies compliance gaps, quantifies regulatory risk, and delivers a clear remediation roadmap — before the regulator comes to you.

What's Included

  • Data mapping and processing activity review
  • GDPR / UK DPA / CCPA gap analysis
  • Privacy policy and notice review
  • Vendor and third-party data flow assessment
  • Breach notification readiness review
  • Prioritised remediation roadmap
  • Executive summary and board presentation pack

Ideal For

US companies with UK or EU customers, UK organisations post-ICO inquiry, businesses scaling their data operations, or any organisation seeking to demonstrate privacy compliance to enterprise clients or investors.

Investment

$5,500

Fixed fee · No hidden costs

Timeline 2–3 weeks
Delivery 100% Remote
Frameworks GDPR · UK DPA · CCPA
Regions US · UK · EU
Enquire About This Package →

Response within 2 business days

PACKAGE 03 2 weeks · Remote HIGH DEMAND

AI Security Assessment

"Your AI is only as safe as its weakest prompt."

As organisations deploy large language models, chatbots, and AI-powered tools, new attack surfaces emerge that traditional security assessments miss entirely. This engagement evaluates your AI systems against real-world threats — prompt injection, data leakage, model misuse — and delivers actionable remediation guidance.

What's Included

  • AI system inventory and deployment review
  • Threat modelling against OWASP LLM Top 10
  • Prompt injection and jailbreak risk assessment
  • Data leakage and privacy risk evaluation
  • EU AI Act obligations assessment
  • AI risk register and remediation roadmap
  • Executive briefing deck

Ideal For

Any organisation deploying LLMs, AI chatbots, AI-powered customer service tools, or internal AI assistants. Particularly relevant for financial services, healthcare, legal, and any sector handling sensitive data through AI systems.

Investment

$6,000

Fixed fee · No hidden costs

Timeline 2 weeks
Delivery 100% Remote
Frameworks OWASP LLM · EU AI Act
Regions US · UK · EU
Enquire About This Package →

Response within 2 business days

PACKAGE 04 3 weeks · Remote

Incident Readiness Programme

"Don't plan your response during the crisis."

Most organisations discover gaps in their incident response capability only when it's too late. This engagement builds and stress-tests your response infrastructure — so when a breach happens, your team executes with confidence rather than chaos.

What's Included

  • Current IR capability assessment
  • Custom incident response playbook (ransomware, data breach, insider threat)
  • Tabletop exercise — live scenario walkthrough with your team
  • Regulatory notification checklist (ICO, SEC, FTC)
  • Crisis communications framework
  • Executive debrief and lessons-learned report

Ideal For

Organisations renewing cyber insurance, those that have experienced a recent incident, or leadership teams that want confidence their organisation can respond effectively to a major security event.

Investment

$5,500

Fixed fee · No hidden costs

Timeline 3 weeks
Delivery Remote + 1 live session
Frameworks NIST · ISO 27035
Regions US · UK · EU
Enquire About This Package →

Response within 2 business days

PACKAGE 05 Ongoing · Monthly retainer RECURRING

Fractional CISO Advisory

"C-suite security thinking — without the C-suite salary."

A dedicated monthly advisory relationship that gives your organisation access to senior security leadership without the cost of a full-time hire. Covers strategy, policy, board reporting, vendor oversight, and security programme development — the way a CISO would, at a fraction of the cost.

What's Included Monthly

  • 2 x 60-minute strategic advisory sessions
  • Security programme oversight and roadmap management
  • Monthly threat intelligence briefing relevant to your sector
  • Policy and procedure review and development
  • Vendor and supplier security oversight
  • Board and investor security reporting support
  • Async support via secure messaging (48hr response)

Ideal For

Growth-stage companies, Series A/B funded startups, SMEs with 50–500 employees, and any organisation that needs senior security leadership but cannot yet justify a full-time CISO hire. Minimum 3-month commitment.

Investment

$2,500

Per month · 3-month minimum

Commitment 3 months minimum
Delivery 100% Remote / Async
Sessions 2 x 60 min / month
Regions US · UK · EU
Enquire About This Package →

Response within 2 business days

Custom Engagements

Need Something Different?

Not every challenge fits a standard package. If your organisation has specific requirements — a larger scope, multiple workstreams, or a unique regulatory situation — we scope bespoke engagements on request.

Start a Conversation →

No commitment required · Response within 2 business days