Pricing

Most firms make you sit through two calls to learn a number

Here it is. Set your cloud scope and timeline, add the services you need, and see an indicative range — then send a short brief and we'll come back with a fixed-price proposal.

Step 1 · Cloud platforms in scope

Platform-scoped services are priced per cloud. Each additional platform is charged at a reduced rate — the methodology carries over, only the provider's native tooling changes.

Step 2 · Delivery timeline

Your timeline affects pricing — faster delivery carries a premium, a relaxed timeline earns a discount.

Step 3 · Choose services

Every figure below is an approximate price for a typical engagement, not a quote. Smaller scopes come in lower, larger or more complex estates higher — final scope is agreed after a short discovery call.

Cloud Security Assessment

typical range$8,000$25,000

Posture evaluation across your cloud estate with a prioritized risk picture.

  • Identity, network, data & detection review
  • Risk-rated findings report
  • Prioritized remediation roadmap

Scope drivers: number of accounts/subscriptions/projects, regions, and workloads in scope. Priced per cloud platform.

Cloud Platform Security Review

typical range$7,000$20,000

Deep, service-by-service review of your AWS, Azure or Google Cloud platform.

  • Identity, networking, logging & detection
  • Native tooling tuned per provider
  • Governance & account-structure guidance

Scope drivers: account structure, regions, and depth of the governance review. Priced per cloud platform.

Kubernetes Security

typical range$9,000$24,000

Securing Kubernetes on EKS, AKS & GKE, cluster to runtime.

  • Cluster security assessment
  • Hardened reference architecture
  • RBAC, network policy & supply-chain controls

Scope drivers: number of clusters, managed vs self-hosted, and runtime scope. Priced per cloud platform.

DevSecOps

typical range$12,000$35,000

Security embedded across your SDLC and pipelines.

  • CI/CD security integration plan
  • IaC & container scanning guardrails
  • Developer-friendly policy design

Scope drivers: number of pipelines and repositories, IaC footprint, and existing tooling.

Compliance & Audit Readiness

typical range$12,000$40,000

Get audit-ready for SOC 2, HIPAA, PCI DSS, ISO 27001 and more.

  • Framework gap analysis & control mapping
  • Remediation plan with owners
  • Evidence-collection guidance

Scope drivers: number of frameworks, current control maturity, and evidence readiness.

Virtual CISO — Advisory

typical range$4,000$8,000/ month

Security direction at a steady cadence — roughly one to two days a month.

  • Security strategy & roadmap
  • Risk register & governance cadence
  • Board, customer & auditor reporting

Scope drivers: days per month, board reporting cadence, and program breadth. Minimum three-month term. Choose one vCISO tier, not both.

Virtual CISO — Operational

typical range$9,000$18,000/ month

Embedded leadership at four to six days a month, running the program rather than advising on it.

  • Everything in Advisory, at depth
  • Hands-on remediation oversight
  • Audit and customer security reviews led for you

Scope drivers: days per month, number of frameworks in flight, and how much of the program we run versus advise on. Minimum three-month term. Choose one vCISO tier, not both.

Security Training

typical range$3,000$9,000/ program

Awareness + technical training for your teams.

  • Role-based training curriculum
  • Cloud-specific technical sessions (AWS, Azure, GCP)
  • Awareness materials & reinforcement plan

Scope drivers: number of roles covered, session count, and delivery format.

Step 4 · Submit your project brief

Tell us about your project

Share a bit of context and any specifics — the more we know, the sharper your proposal. Your selected services are attached automatically.

Selected services

None selected yet — add services above, or describe your needs below.

Required field.

Keep this general. Nothing sent through this site is confidential until we sign an NDA — so please leave out credentials, network diagrams, asset inventories, audit findings and unremediated vulnerabilities. Tell us what you want to achieve; we will agree a secure channel before going into detail. See our Privacy Policy and Terms §6.

We reply to every inquiry within one business day.