Cybersecurity services

Work performed, deliverables, and what it takes to start.

Every service below maps to something you can point to when it's done — not a framework name. Each identifies the problem, the work performed, the deliverables, an expected timeline, what we need from you, and the next step.

All services

01

Security readiness & program assessments

Discuss this

You need an honest read on where the program actually stands before you decide what to fix first. We review current state, identify gaps, assign owners, and prioritize — plainly, not against a generic maturity model.

Deliverables
Executive summary, gap list with owners, prioritized improvement roadmap
Timeline
2–4 weeks
Your inputs
Access to relevant systems, docs, and a point of contact
Starting price
Starting at $6,500

02

Vulnerability management support

Discuss this

Scan output is a list, not a program. We validate findings, coordinate remediation with the people who own the systems, track exceptions, and report progress in terms executives will read.

Deliverables
Validated findings, remediation tracker, exception log, executive report
Timeline
Ongoing monthly, or a fixed 4–6 week engagement
Your inputs
Scan tooling access or scan output, stakeholder contacts
Starting price
Starting at $2,500

03

IAM & PAM governance

Discuss this

Administrative and privileged access accumulates quietly. We review who has access to what, document ownership, and build MFA/SSO and privileged access governance that survives staff turnover.

Deliverables
Access review report, ownership map, MFA/SSO and PAM governance documentation
Timeline
3–5 weeks
Your inputs
Directory and IAM/PAM tooling access, org chart context
Starting price
Scoped after intake call

04

Risk & GRC execution

Discuss this

A risk register that lives in a shared drive isn't a program. We build the register, map controls to policy, organize evidence, and set a treatment cadence your team can keep running.

Deliverables
Risk register, third party risk process, evidence organization, treatment tracker
Timeline
4–6 weeks initial build
Your inputs
Existing policy docs, vendor list, prior audit findings if any
Starting price
Scoped after intake call

05

Incident readiness

Discuss this

Most incident response plans are written once and never tested. We build the plan, define roles and escalation paths, run a tabletop, and document what the tabletop actually revealed.

Deliverables
IR plan, roles & escalation matrix, tabletop exercise, after-action report
Timeline
3–4 weeks
Your inputs
Key stakeholder availability for the tabletop session
Starting price
Scoped after intake call

06

Security policies & procedures

Discuss this

Template policy dumps don't survive contact with an auditor. We write policies, standards, and SOPs grounded in what your team actually does — then keep them short enough to be read.

Deliverables
Policy and procedure set matched to your operating environment
Timeline
3–6 weeks depending on scope
Your inputs
Current process documentation, stakeholder interviews
Starting price
Scoped after intake call

07

Fractional BISO support

Explore this

Experienced judgment without a full time hire. Risk translation, business alignment, program coordination, and executive communication on a structured monthly cadence. See the Fractional BISO page for the full model.

Deliverables
Monthly program review, executive reporting, ongoing risk and roadmap coordination
Timeline
Ongoing monthly engagement
Your inputs
Recurring access to leadership and relevant systems
Starting price
Typical $5,000–$12,000 monthly

08

Security workflow automation

Discuss this

Intake forms, evidence requests, and status reporting eat hours every week. We build lightweight workflows — not a new platform — that cut the repetitive parts down.

Deliverables
Working intake/evidence/reporting workflow, handoff documentation
Timeline
2–5 weeks depending on complexity
Your inputs
Access to the systems the workflow touches
Starting price
Scoped after intake call

Productized starting offers

Five ways to get started without a custom proposal cycle.

Vulnerability assessment

Executive and technical findings with prioritized remediation.

Starting at $2,500

Executive risk assessment

Business focused risk summary and treatment priorities.

Starting at $3,500

NIST 800-171 gap assessment

Control review, documented gaps, score support, and roadmap.

Starting at $5,000

Security program assessment

Program review, maturity gaps, ownership, and roadmap.

Starting at $6,500

Fractional BISO support

Structured monthly leadership and execution support.

Typical $5,000–$12,000/mo

All pricing is starting or typical language. Final pricing depends on scope, environment, evidence condition, timeline, travel, and customer responsibilities.

Not sure which service fits?

Tell us where the program stands — we'll point to the right starting offer or scope something custom.