Retained technical cyber security advisory

A senior security opinion for the decisions you cannot settle alone.

Practical cyber security advice for teams that need senior input but do not have a full security function in-house.

Bring us the design, finding or security concern that is holding up a decision. We will examine the technical context, explain what matters and give your team a practical next step.

Free 30-minute intro call. No obligation, no sales handoff. You speak directly with a senior consultant.

  • More than 20 years' experience per consultant
  • ISC2-certified consultants
  • HRD Corp accredited trainers
  • Your work stays with a senior consultant
  1. 01Break
  2. 02Build
  3. 03Defend
  4. 04Fix

The technical security gap

The security questions still come, even without a security lead.

A new release, cloud change or pentest finding can force a decision before the team has the right expertise in-house. That is where a retained advisor is useful.

The cost of waiting

Security decisions rarely stay cheap to reverse.

A release ships, a design hardens, a finding sits. Each one is easier to settle now than after it has spread through the system you are building. The question is not whether you can afford the review. It is what unwinding it costs later.

Retained technical advisory

Senior technical input when the decision cannot wait.

We work with the people who build and run your systems. We challenge designs, make sense of findings and recommend what to do next. Your team keeps ownership of the system and the final decision.

The framework

Break. Build. Defend. Fix.

One advisor who can follow an issue from attack path or design question through to a workable fix.

01

Break

We look at the system as an attacker would and separate credible attack paths from theoretical noise.

  • Exploitability assessment
  • Attack paths
  • Abuse cases
  • Pentest triage
  • Vulnerability validation
  • Attacker review

02

Build

We challenge application, API, cloud and identity decisions before they become costly to change.

  • Application security
  • API security
  • Architecture review
  • Authentication and authorisation
  • Secure SDLC
  • CI/CD security
  • Cloud design

03

Defend

We review whether hardening, monitoring and recovery arrangements will hold up under a realistic incident.

  • Hardening
  • Identity
  • Logging and monitoring guidance
  • Detection readiness
  • Ransomware resilience
  • Backups
  • M365, cloud, and infrastructure defense

04

Fix

We turn findings into an ordered fix plan that the responsible teams can understand and deliver.

  • Triage
  • Remediation guidance
  • Compensating controls
  • Risk priority
  • Retest guidance
  • Monthly tracking
  • Practical recommendations
See what we can advise on →

Who we usually work with

Useful when the expertise is needed, but a full security team is not.

For

Software and SaaS teams

Challenge
The product keeps moving, but nobody senior is consistently challenging security decisions before they become rework.
How we help
Get experienced application, API, cloud and architecture advice while there is still time to change the design.
See relevant examples

For

IT-heavy SMEs

Challenge
Important systems need proper security attention, but a full internal security function is not yet practical.
How we help
Bring difficult risk, hardening, identity and recovery questions to a senior advisor who understands operational constraints.
See relevant examples

For

Solo founders and indie developers

Challenge
The product makes money and ships fast, but the person building it is also the only one carrying the security decisions.
How we help
Get senior technical security judgement a few hours at a time, without a full-time hire or a security team to stand up.
See relevant examples

For

MSPs and IT partners

Challenge
A client raises a security issue that sits outside the normal helpdesk or managed service scope.
How we help
Bring in senior technical support for a client review, difficult decision or escalation, with responsibilities agreed upfront.
See relevant examples
See common client situations →

Retained packages

Choose a sensible level of access for the work you expect.

Display package prices in

Each currency is a separate rate card

Advisory Clinic

Founder-led and small technical teams with a handful of security decisions each month.

Monthly retainer

US$1,400/month

Up to 4 advisory hours per month

A senior opinion on the handful of decisions each month that need one.

  • One 60-minute technical clinic
  • Questions through email or Teams
  • Triage of up to three findings from one system or report
  • A short written action list after the clinic

Security Partner

Active product teams, higher-risk systems or programmes with several technical owners.

Monthly retainer

US$5,400/month

Up to 20 advisory hours per month

Ongoing senior oversight of the systems that carry the most risk.

  • Design challenge before material releases
  • Priority finding and remediation triage
  • Secure architecture and hardening guidance
  • A maintained remediation and risk tracker
  • One two-hour working session each quarter

Embedded Advisor

MSPs, software houses and larger teams that need regular senior cover across agreed workstreams.

From

US$8,000/month

From 32 advisory hours per month

A named senior security voice behind the work you put your name to.

  • Named systems and workstreams agreed in advance
  • Technical assurance across active delivery
  • Senior escalation for complex decisions
  • Quarterly advisory roadmap
  • White-label delivery by separate agreement

New to retained advisory? Start with the Advisory Clinic at US$1,400 a month, and grow into a larger tier when the decisions start piling up.

Review package scope and add-ons →

Have a security question that your team cannot settle?

Tell us what is happening, what decision is due and who is involved. We will tell you plainly whether we are the right fit.

Book a Technical Advisory CallReview our approach

Free 30-minute call, no obligation. If we are not the right fit, we will say so plainly.