Skip to content

Cybersecurity

Know where you are exposed, fix what matters first, and prove it to customers.

Starting price · United States

$8,000project

Security assessment

Assessment
2-4 wks
Frameworks
SOC 2 · ISO
Certified tests
Accredited

Assessment 2-4 weeks · SOC 2 readiness 2-4 months · managed security ongoing

The problem

A security questionnaire you cannot answer

A large prospect sends a security questionnaire, or an insurer asks for evidence, and nobody is sure how access is controlled, where the data lives or whether backups actually restore.

  • No inventory of systems or data
  • Shared accounts and old access never removed
  • Vulnerabilities found by customers, not by you
  • Deals stalled on security reviews
What we do about it

Assess, prioritise, fix, evidence

A structured assessment against a recognised framework, a risk-ranked fix list, hands-on remediation and a pack of evidence that answers questionnaires and satisfies auditors.

  • Assessment against CIS, NIST or ISO 27001 controls
  • Findings ranked by real business risk
  • Remediation done, not just recommended
  • Evidence pack for customers and auditors

Always included

What comes with every engagement

Not an upsell list. These are part of the price, on every package.

Assessment against a recognised framework
Findings ranked by business risk
Hands-on remediation support
Evidence pack for questionnaires
Accredited partners for certified tests
Retest after fixes
Plain-language executive summary
Developer and staff awareness training
Incident response plan
Confidential handling of all findings

Packages

Three ways to start

Prices shown for United States in USD. Change your region in the header to see another market.

Starter

Assessment and a ranked fix list.

$24k

one-time project

  • Scoped assessment
  • Vulnerability scanning
  • Risk-ranked report
  • Remediation roadmap
  • Executive briefing
Estimate this package
Most chosen

Growth

Readiness for SOC 2 or ISO 27001.

$50k

one-time project

  • Gap analysis
  • Policies and procedures
  • Control implementation
  • Evidence collection
  • Auditor coordination
Estimate this package

Pro

Managed security programme.

$15k

per month

  • Continuous monitoring
  • Quarterly penetration testing
  • Access reviews
  • Incident response on call
  • Named security lead
Estimate this package

Full price table for United States

Assessments and readiness are fixed-price. Managed security runs monthly.

🇺🇸 United States · USD
Cybersecurity pricing for United States
DeliverableUSD range
Security assessmentCloud, identity, applications and process$8,000 – $40,000
Penetration test, accredited partnerScoping, test, remediation and retest$10,000 – $50,000
SOC 2 or ISO 27001 readinessPolicies, controls and evidence$20,000 – $80,000
Managed securityMonitoring, vulnerability management, response$3,000 – $15,000
US figures are benchmarked; UK, Canada, Australia, Europe, the Gulf and Asia are scaled from them and are indicative until confirmed on a call. Audit fees charged by the certifying firm are separate.

Try it yourself

Security project ballpark

Move the inputs and the numbers move with them. Nothing is submitted until you choose to.

Security assessment · United States

$8,000 – $40k

project

Typical timelines: Assessment 2-4 weeks · SOC 2 readiness 2-4 months · managed security ongoing

Ballpark only. Scope, integrations, data readiness and compliance move the figure, and the full calculator asks about each of them.

Get a detailed estimate

Process

How the work actually runs

  1. 1Week 1

    Scope

    Assets, data and obligations mapped. Framework and success criteria agreed.

  2. 2Weeks 2-4

    Assess

    Controls reviewed, systems scanned, findings ranked by risk.

  3. 3Weeks 4-10

    Remediate

    Highest risks fixed first, with retesting to confirm.

  4. 4Ongoing

    Evidence

    Policies, logs and reports assembled for customers and auditors.

Tools and platforms we work in

OWASP ZAPBurp SuiteSnykTrivyWizMicrosoft DefenderCrowdStrikeVantaDrataAWS Security HubOkta1PasswordOWASP ZAPBurp SuiteSnykTrivyWizMicrosoft DefenderCrowdStrikeVantaDrataAWS Security HubOkta1Password

Case study

Sample profile: B2B SaaS, 40 staff

Two enterprise deals were stalled on security reviews, and the company had no policies, no access reviews and no evidence to show.

What we did

  • Ran a gap analysis against SOC 2 criteria
  • Wrote the policy set and implemented missing controls
  • Coordinated an accredited penetration test and retest
  • Built an evidence pack for security questionnaires

Critical findings open

140

Closed

Questionnaire turnaround

3 weeks2 days

-90%

SOC 2 Type I

NonePassed

Achieved

Stalled deals

20

Unblocked

Sample engagement profile showing the kind of result this service targets. It is replaced with a client-approved case study, with names and logos, before launch.

Cybersecurity for growing software companies

What should a first security assessment cover?

A useful first assessment reviews cloud configuration, identity and access, endpoints, your main applications and security processes against a recognised framework such as CIS, NIST or ISO 27001, then ranks findings by business risk so the most dangerous gaps are fixed first.

Which regulations apply in the Gulf and Asia?

The UAE and Saudi Arabia both have Personal Data Protection Laws (PDPL), and Saudi Arabia’s National Cybersecurity Authority (NCA) publishes Essential Cybersecurity Controls. Singapore has the PDPA and Japan the APPI. We map your controls to the rules that apply where your customers and data are.

Related searches

  • cybersecurity services
  • security assessment services
  • penetration testing services
  • SOC 2 readiness consulting
  • ISO 27001 consulting
  • application security services
  • managed security services
  • vulnerability assessment

Cybersecurity for clients in the US, UK, Europe, the Gulf and Asia

Pricing is published for each region, and engineering hours overlap with your working day.

Frequently asked questions

Cybersecurity: your questions answered

Formal certified tests are delivered through accredited partners, with scoping, triage, remediation and retesting managed by us. We will not present our own review as an accredited certificate.

Put a number on it

The calculator opens on cybersecurity already selected. Seven questions and you have a range in USD.

Rough estimate only. Final pricing is confirmed after a consultation.