Pricing

Scoped first, then quoted, then billed by the hour

We agree what needs doing before we put a number on it. The quote then shows the hours required from each consultant role, so you can see where the effort sits before anything starts.

How it works

  1. 01

    We agree the scope of work

    What is in scope, what is not, and what the finished state looks like — agreed before any number is discussed.

  2. 02

    You get a detailed quote

    Hours broken down by consultant role, so you can see where the effort sits and challenge it before anything starts.

  3. 03

    Work is billed by the hour

    Logged against the agreed scope, and any change of scope is re-quoted rather than absorbed quietly.

Who does the work

Every quote breaks the estimate down by role. Most mandates use more than one, and the mix follows what the work actually needs.

  • Architect

    Designs the target state and the controls that get you there. Owns the security architecture and the decisions the rest of the work depends on.

  • Lead Implementer

    Turns the architecture into a plan and leads its delivery. Runs the technical work day to day and is the point of contact for your team.

  • Implementer

    Builds and configures the controls, and works alongside your engineers so the result is something they can operate without us.

Quoted per mandate

What engagements run to

These are the hours a full engagement of each type runs to, so you know the scale of the work before you talk to us.

EngagementHours
Phase 1 — AssessFixed scope, fixed price. We inventory what you run — what exists, who can reach it, what is exposed, and what you are paying for — and you leave with a prioritized plan you own outright, whether or not there is a phase 2.CA$2,500
Microsoft 365 setup and right-sizingThe configuration nobody did: access, sharing, a backup outside the tenant tested by restoring, logging on and retained — and the licence count matched to who actually uses what.Scales with users — a 25-person tenant is a different job from 150
Copilot and AI rolloutScoped, licensed and secured: what each tool may reach, which teams it is actually for, the right model per task, and the logging and off-switch that come with it.Scales with users and the number of tools in scope
AI implementation reviewWhat the model reaches and as whom, where prompts and code go, agent permissions and injection paths — read against the OWASP LLM and Agentic Top 10s, with the licence and model choices priced.70–90 hours
Security questionnaire responseThe questionnaire answered with evidence behind each line, and the gaps it exposes closed rather than noted — so the next one is a day's work instead of a fortnight's.Scales with the questionnaire — fifty questions or three hundred
Audit readinessThe controls, evidence and documentation an auditor asks for, in place and working. We do not issue the certificate — that is an accredited auditor, on their own timeline.Scales with the framework and the size of the gap
Ongoing advisory (retainer)A defined block of hours each month for decisions, reviews, customer security questionnaires, licence renewals and whatever the month brings.24–40 hours / month

Planning shapes, not quotes. Phase 1 is the one fixed price on this page; everything after it is scoped with you first and quoted against the hours it actually needs.

What a quote looks like

Hours and rates are filled in against your agreed scope — the structure is always this.

RoleHours or priceRate
Architect
Lead Implementer
Implementer

Frequently asked questions

Are the hour ranges a quote?
No. They are typical scopes for organisations of the size we work with, published so you can estimate before speaking to anyone. Your own quote follows an agreed scope and may land outside a range — a twenty-five person tenant is not the same job as a hundred and fifty. If your scope looks likely to exceed the range, we say so while we are scoping it, not afterwards.
We are a small team. Are we too small to work with you?
No — smaller organisations are most of what we do. Several of us built these controls at utility and municipal scale, and the useful part of that experience is knowing which of it applies to a team of twenty and which of it is overhead you should not pay for. An engagement is sized to your organisation, not scaled down from an enterprise template.
What happens if the work takes longer than quoted?
The quote is an estimate against an agreed scope, not a blank cheque. If we can see the hours running over, you hear about it before they are spent — not on the invoice. Work outside the agreed scope is re-quoted rather than absorbed quietly.
Can we engage a single role rather than a full team?
Yes. Some mandates are architecture only; others are implementation against a design you already have. The breakdown in the quote reflects what the work actually needs, not a fixed team shape.
How long does an assessment take?
Most assessments complete within two to three weeks, depending on the scope and the complexity of your systems.
Do you provide ongoing support?
Yes. Beyond project work we take on ongoing advisory and retainer engagements, billed the same way — hourly against an agreed scope.
Can you work with our existing security tools?
Yes. We work with the stack you already run rather than requiring a particular set of products — most engagements involve tooling the client already owns.
Do you offer volume or retainer discounts?
Volume and retainer terms are agreed per mandate. Tell us the shape of the work and we will put it in the quote.

Tell us what you need doing

Send us the shape of the work and we will come back with a scope and a quote. We reply within one business day.

Not ready to scope a mandate? A 60-minute session and a written summary of your risks costs nothing, and tells you what is worth quoting in the first place.