Straightforward pricing, scoped to your business
The prices below are starting points. Every engagement is scoped to your company's size, vendor count, and current maturity, so book a discovery call for an exact quote.
Third-Party Risk Management
Know the risk every vendor brings before it becomes your problem.
Per project. Scope grows with vendor count and program maturity.
- Vendor tiering
- Security reviews
- Due diligence
- Continuous monitoring
GRC Program Development
The governance foundation everything else gets built on.
Per project. Covers policies, risk register, governance, and control mapping.
- Policies
- Risk registers
- Governance
- Control mapping
SOC 2 Readiness
Walk into your audit with confidence, not a last-minute scramble.
Per project. Scales up for larger environments or Type II audits.
- Gap assessment
- Evidence collection
- Audit preparation
Fractional GRC Leadership
Senior GRC guidance on call, without a full-time hire.
Monthly retainer. Scoped to meeting cadence and program size.
- Monthly meetings
- Policy updates
- Vendor reviews
- Audit support
Penetration Testing
Find the gaps before an attacker does.
Per engagement. Scope depends on environment size and testing depth.
- External network testing
- Web application testing
- Internal network testing
- Reporting and retesting
Cyber Forensics Investigation
Find out what happened, when, and how it started.
Per investigation. Scope depends on incident complexity and evidence volume.
- Evidence preservation
- Root cause analysis
- Impact assessment
- Investigation report
Not sure which one fits?
Book a discovery call and we'll recommend a starting point based on where your program stands today.