Advisory Services

Security Audit & Advisory
Think of this as a health check for your business's security. We look at how you store data, how your systems are set up, and where the gaps are — then give you a clear, plain-English report on what to fix and in what order.
​
THIS IS RIGHT FOR YOU IF…
​
-
You've never had a security review and want to know where you stand
-
A client, investor, or partner has asked about your security and you don't have a clear answer
-
You're about to launch a product and want to make sure you're protected
​​​​
​​​​
​​​​
​​​​
​​​
​​
​​​​​​​
-
​​Full review of your attack surface
-
Prioritised risk register
-
Plain-English report you can share with your board
-
Two advisory sessions to walk through findings
​
​
​
From $999
ONE-OFF Single fixed payment

Security Programme & Penetration Testing (VAPT)
We build your security from the ground up and then test it like an attacker would. You'll end the engagement with a functioning security programme and a tested, documented proof of it — exactly what investors, enterprise clients, and auditors want to see.
​
THIS IS RIGHT FOR YOU IF…
​
-
You're preparing for a funding round and need to demonstrate strong security
-
You're working toward SOC 2, ISO 27001, or Cyber Essentials+
-
An enterprise client has sent a security questionnaire you can't answer
-
You've built a product and want to know if it can be hacked before customers find out
​​​​​
​​​​
​​​​​​​​​​​​​​​​​​​​
-
Manual penetration test — web, API, infrastructure
-
Full security programme design
-
Policy and control templates
-
Documented report for investors and auditors
-
Remediation follow-up session
​
​
​
From $2, 500
ONE-OFF Scope Fixed Fee, confirmed after discovery

AI Governance & Risk Advisory
Your business is using AI — in your product, your operations, or both. Almost no one has a policy for what that means. We help you understand your exposure, build the governance framework regulators now expect, and make sure your use of AI doesn't become your next compliance crisis. This is the newest and fastest-moving area of risk for modern businesses — and most companies are years behind.
​
THIS IS RIGHT FOR YOU IF…
​
-
Your team uses AI tools (internally or in your product) with no formal policy or oversight
-
You're building AI features and need to understand your regulatory exposure
-
An investor, client, or regulator has asked how you govern AI use and you don't have an answer
-
You want to get ahead of AI regulation rather than scramble when it lands on your sector
​​​
​​
​​
-
​​​​AI use and risk audit across your business
-
AI governance framework and policy documentation
-
Regulatory exposure mapping (EU AI Act and sector-specific rules)
-
Board-ready AI risk reporting
​
​
​
From $3, 200
ONE-OFF Scoped fixed fee, ongoing retainer available

Compliance & Certification Readiness — SOC 2, ISO 27001, Cyber Essentials+
Many of our clients come to us with a deadline: an enterprise deal, a tender, or an investor is asking for a certification you don't have yet. We get you there. For companies starting from nothing, we implement a full Information Security Management System (ISMS) — the structured set of policies and controls ISO 27001 requires. For companies with some security in place, we focus purely on audit readiness — closing the specific gaps that stand between you and a pass.
​
THIS IS RIGHT FOR YOU IF…
-
​An enterprise client has told you "we need your SOC 2 report before we sign"
-
You're targeting UK government or public sector contracts and need Cyber Essentials+
-
You have no ISMS in place and need one built from scratch for ISO 27001 certification
-
You have some policies and controls already but aren't confident you'd pass an audit today
-
You have a hard deadline tied to a deal, tender, or funding round
-
Gap analysis against your target framework
-
Full ISMS build — policies, controls, risk treatment plan
-
Audit readiness review and mock audit
-
Evidence collection and documentation support
-
Direct liaison with your certification body or assessor
-
Post-certification maintenance plan
​
​
​
From $4, 500
PROJECT FEE 3-6 month engagement, scoped after gap analysis

Fractional CISO — Ongoing Security Leadership
A Chief Information Security Officer (CISO) is the senior leader responsible for everything security in an organisation. Hiring one full-time costs $250k–$600k a year. Our Fractional CISO service gives you that same level of expertise and accountability — on a monthly retainer, for a fraction of the cost.
​
THIS IS RIGHT FOR YOU IF…
​
-
You're scaling fast and security decisions are piling up with no one owning them
-
You need someone to represent your security posture to a board or investors
-
You want ongoing protection and a long-term partner — not a one-off report
-
You want to hire a CISO eventually but aren't ready for the full-time cost yet
​
​
​
-
​​​​Dedicated senior security practitioner
-
Weekly or bi-weekly leadership check-ins
-
Board and investor security reporting
-
Audit and certification support
-
Unlimited team security advisory
-
Security posture reviews as you scale
​
​
​
From $1, 800
RETAINER Minimum 3-month engagement
NDA included as standard on every engagement
100% confidential — no client referenced without permission
Enterprise and bespoke scopes quoted on request