Advisory retainers

Clear monthly scope. Senior advice when the decisions matter.

You should know what you are paying for before the first call. Each package reserves senior technical security capacity, with the working rhythm and limits stated upfront.

Rates are shown in US Dollars by default, with separate rate cards for Malaysia and Singapore. If the work is better handled as a project, we will say so and quote it separately before anyone starts.

  • More than 20 years' experience per consultant
  • ISC2-certified consultants
  • HRD Corp accredited trainers
  • Your work stays with a senior consultant
  1. 01Break
  2. 02Build
  3. 03Defend
  4. 04Fix

Before you compare tiers

Monthly retainers are for recurring decision load.

If your team has one contained question, we can scope it as a focused review and quote it separately. A retainer earns its place when the same kinds of decisions keep returning: release conditions, pentest findings, architecture changes, cloud controls, customer security questions and remediation that needs tracking.

We will recommend the smallest package that fits the work you actually expect. If a retainer is not warranted yet, we will say so.

See work we quote separately →

Monthly retainers

Choose based on decision load, not company size.

The right tier depends on how often your team needs review, how many systems are in play and how quickly a senior response is needed.

Display package prices in

Each currency is a separate rate card

Advisory Clinic

Founder-led and small technical teams with a handful of security decisions each month.

Monthly retainer

US$1,400/month

Up to 4 advisory hours per month

A senior opinion on the handful of decisions each month that need one.

  • One 60-minute technical clinic
  • Questions through email or Teams
  • Triage of up to three findings from one system or report
  • A short written action list after the clinic
Working rhythm
One scheduled clinic each month
Response target
Initial response within 3 business days
See a fictional sample deliverable

Security Partner

Active product teams, higher-risk systems or programmes with several technical owners.

Monthly retainer

US$5,400/month

Up to 20 advisory hours per month

Ongoing senior oversight of the systems that carry the most risk.

  • Design challenge before material releases
  • Priority finding and remediation triage
  • Secure architecture and hardening guidance
  • A maintained remediation and risk tracker
  • One two-hour working session each quarter
Working rhythm
Weekly working session when needed
Response target
Initial response within 1 business day
See a fictional sample deliverable

Embedded Advisor

MSPs, software houses and larger teams that need regular senior cover across agreed workstreams.

From

US$8,000/month

From 32 advisory hours per month

A named senior security voice behind the work you put your name to.

  • Named systems and workstreams agreed in advance
  • Technical assurance across active delivery
  • Senior escalation for complex decisions
  • Quarterly advisory roadmap
  • White-label delivery by separate agreement
Working rhythm
Weekly cadence and agreed office hours
Response target
Initial response within 1 business day
See a fictional sample deliverable

New to retained advisory? Start with the Advisory Clinic at US$1,400 a month, and grow into a larger tier when the decisions start piling up.

Each currency is a separate rate card rather than a live conversion, so the figure you see is the figure we quote. Clients domiciled in Malaysia are contracted and invoiced in Ringgit; clients elsewhere are contracted in US Dollars. Taxes are excluded and charged where applicable. Standard retainers begin with a three-month term and are invoiced monthly in advance. After that, either side may end the retainer with 30 days' written notice.

Which package fits?

Match the tier to the decisions you expect, not the size of the company.

Read these as signals rather than rules. If your situation sits between two tiers, start with the smaller one — moving up mid-term is straightforward.

Advisory Clinic

Best if

  • You can save a few questions up for one session each month
  • The team is founder-led or small
  • Decision load is low, but it does keep returning
  • You want senior judgement available without a standing commitment

Retained Advisor

Best if

  • You ship regularly and releases raise security questions
  • There are findings or technical artefacts to review most months
  • You need monthly priorities with named owners
  • There is no in-house security lead to escalate to

Security Partner

Best if

  • The systems carry higher risk, or hold sensitive data
  • Several technical owners are involved in the same decisions
  • Remediation and hardening need tracking, not just advice
  • A weekly working session would be used if it existed

Embedded Advisor

Best if

  • You are an MSP, software house or larger delivery team
  • Several systems, clients or workstreams need senior cover
  • White-label or partner delivery is part of the arrangement
  • You need agreed office hours and escalation capacity

Focused work often leads into a retainer once the issue reveals an ongoing need. A pentest remediation sprint can become monthly remediation tracking, an architecture review can become release-cycle advisory, and a one-off escalation for an MSP client can become an embedded arrangement. None of that is automatic — we scope it only when the decision load is real.

The baseline

What every retainer includes.

The tier changes the amount of access and depth of involvement. The senior standard does not change.

  • 01

    Direct access to a named senior technical security consultant

  • 02

    Scheduled sessions plus an agreed email or Teams channel

  • 03

    Concise written decisions, priorities and next steps

  • 04

    One contracting entity and the systems agreed at onboarding

  • 05

    Confidential handling of technical and commercial context

Working terms

A retainer reserves senior judgement. It is not unlimited labour.

These are the practical rules we use to keep the relationship fair for both sides. The engagement letter will record the final scope.

  1. 01

    Everything that takes time counts

    Meetings, preparation, research, document review, written notes and between-session replies all use the monthly allocation. Time is recorded in 15-minute blocks.

  2. 02

    We do not run past the clock quietly

    We flag usage before the allocation is exhausted. Extra work starts only after written approval and is billed in one-hour blocks at US$395 per hour, or RM1,700 per hour for clients contracting in Ringgit.

  3. 03

    The package follows the agreed systems

    A package covers one client entity and the systems or workstreams agreed at onboarding. Client portfolios, unrelated products and white-label work need an Embedded scope.

  4. 04

    A response target is not an incident SLA

    Response targets mean an acknowledgement or a proposed next step, Monday to Friday from 9.00am to 6.00pm MYT, excluding Malaysian public holidays. They do not promise completion within that window or provide 24/7 emergency cover.

  5. 05

    Unused hours do not roll over

    The retainer reserves senior capacity for that month. Unused hours expire at month end, and sessions moved with less than two business days' notice may still be counted.

  6. 06

    Your team still owns delivery

    We advise, review and challenge. Your team remains responsible for access, business decisions, implementation, change approval and testing in production.

Separately scoped work

Work we can quote separately.

The monthly retainer is for advice and review. The services below involve a defined piece of delivery work, so we agree the output, timing and fee before starting.

Subject to consultants' availability. A booking is confirmed only after the scope, schedule and fee are agreed in writing. These figures follow the same per-market rate cards as the retainers above.

Additional advisory time

For months when the included hours are likely to run out. We confirm the extra time in writing before doing the work.

US$395 / hour

Pre-pentest readiness review

We review scope, architecture, access models and known risks before an independent test begins, so the testing budget goes on the paths nobody has considered. Running the test is arranged separately.

From US$1,150

Developer security clinic

A half-day session for one engineering team to work through current findings, code questions or design concerns with a consultant.

US$1,500

Pentest remediation sprint

We take one existing pentest report, group the findings, agree priorities and help the team plan the fixes. Retesting is not included.

View a fictional sample report

From US$1,950

Architecture review workshop

We review one proposed design with the people building it, then record the decisions and actions. Includes preparation and a two-hour session.

US$2,250

Focused cloud security review

A review of one agreed cloud environment or control area, followed by prioritised actions. This is not a full cloud audit.

From US$2,500

Incident readiness tabletop

A facilitated incident exercise for the people who would make the calls. You receive a decisions log and a list of readiness gaps to address.

From US$2,950

Secure SDLC setup

We define practical security roles, checks and release gates for one delivery workflow. Tool implementation is quoted separately if needed.

From US$3,750

What is not included

What the monthly retainer does not cover.

If a request falls into one of these areas, we will explain why and agree a separate scope before any work starts. No surprise assumptions on either side.

  • Monitoring and alert response

    We do not watch logs, operate a SOC or MDR service, or respond to security alerts around the clock.

  • Penetration testing and full code audits

    We can help decide what should be tested and review the results. Running a pentest or reviewing an entire codebase needs a separate proposal.

  • Emergency incident response and forensics

    The monthly retainer is not an emergency hotline. Containment, investigation, evidence handling and recovery work must be arranged separately.

  • Changes to production systems

    We can recommend or review a change. Your team or appointed provider remains responsible for implementing and approving it.

  • Certification and audit sign-off

    We can help interpret gaps and plan the work. Certification and formal audit opinions must come from the relevant independent body.

  • Large documentation or compliance programmes

    Writing a full policy suite, collecting audit evidence or implementing an ISMS is project work, not routine advisory support.

  • Unrelated products, entities or client accounts

    The retainer covers the contracting entity and agreed systems. It cannot be shared across unrelated products or used as pooled support for multiple clients.

  • Guaranteed security outcomes

    No consultant can honestly guarantee that a breach, finding or audit issue will never occur. Our job is to help you reduce risk and make sound decisions.

Bring the actual decision load. We will recommend the smallest package that fits.

The first call is for fit and scope: systems, owners, likely monthly demand and any work that should be quoted separately.