Consulting

Time-boxed security engagements — not subscriptions.

Fractional vCISO leadership, targeted risk assessments, and advisor-led continuous monitoring. Scope, deliver, then decide whether to keep going. Pricing matches the engagement, not a forever-retainer.

Three engagement models. Pick the fit for now — you can always switch later.

Senior security leadership, right-sized.

A fractional vCISO sits inside your organization across cycles — board prep, incident drills, vendor risk, policy review. The work is conversation-heavy and context-dependent; the value compounds month over month. You pay for the time and judgment, not just for advice.

Typical engagements land between 1 and 5 days per month, with an initial 3-month term. After the first cycle, you can scale up, down, or off — month-to-month with 30 days notice.

Talk through a vCISO engagement →

Targeted review. No retainer.

Sometimes what you need is a third-party read with a written deliverable — for a board pack, a procurement gate, or a roadmap reset before a hiring decision. We scope a fixed-fee assessment against a chosen framework or threat model and deliver a prioritized report your engineering team can execute against.

Common scopes: NIST CSF 2.0 baseline, PCI-DSS 4.0 readiness, HIPAA Security Rule mapping, CMMC Level 1/2 readiness, GDPR readiness, cloud architecture threat model, M&A cyber due diligence.

Scope an assessment →