Scoped first, then quoted, then billed by the hour
How it works
- 01
We agree the scope of work
What is in scope, what is not, and what the finished state looks like — agreed before any number is discussed.
- 02
You get a detailed quote
Hours broken down by consultant role, so you can see where the effort sits and challenge it before anything starts.
- 03
Work is billed by the hour
Logged against the agreed scope, and any change of scope is re-quoted rather than absorbed quietly.
Who does the work
Every quote breaks the estimate down by role. Most mandates use more than one, and the mix follows what the work actually needs.
Architect
Designs the target state and the controls that get you there. Owns the security architecture and the decisions the rest of the work depends on.
Lead Implementer
Turns the architecture into a plan and leads its delivery. Runs the technical work day to day and is the point of contact for your team.
Implementer
Builds and configures the controls, and works alongside your engineers so the result is something they can operate without us.
Quoted per mandate
What engagements run to
These are the hours a full engagement of each type runs to, so you know the scale of the work before you talk to us.
| Engagement | Hours |
|---|---|
| Phase 1 — AssessFixed scope, fixed price. We inventory what you run — what exists, who can reach it, what is exposed, and what you are paying for — and you leave with a prioritized plan you own outright, whether or not there is a phase 2. | CA$2,500 |
| Microsoft 365 setup and right-sizingThe configuration nobody did: access, sharing, a backup outside the tenant tested by restoring, logging on and retained — and the licence count matched to who actually uses what. | Scales with users — a 25-person tenant is a different job from 150 |
| Copilot and AI rolloutScoped, licensed and secured: what each tool may reach, which teams it is actually for, the right model per task, and the logging and off-switch that come with it. | Scales with users and the number of tools in scope |
| AI implementation reviewWhat the model reaches and as whom, where prompts and code go, agent permissions and injection paths — read against the OWASP LLM and Agentic Top 10s, with the licence and model choices priced. | 70–90 hours |
| Security questionnaire responseThe questionnaire answered with evidence behind each line, and the gaps it exposes closed rather than noted — so the next one is a day's work instead of a fortnight's. | Scales with the questionnaire — fifty questions or three hundred |
| Audit readinessThe controls, evidence and documentation an auditor asks for, in place and working. We do not issue the certificate — that is an accredited auditor, on their own timeline. | Scales with the framework and the size of the gap |
| Ongoing advisory (retainer)A defined block of hours each month for decisions, reviews, customer security questionnaires, licence renewals and whatever the month brings. | 24–40 hours / month |
Planning shapes, not quotes. Phase 1 is the one fixed price on this page; everything after it is scoped with you first and quoted against the hours it actually needs.
What a quote looks like
Hours and rates are filled in against your agreed scope — the structure is always this.
| Role | Hours or price | Rate |
|---|---|---|
| Architect | ||
| Lead Implementer | ||
| Implementer |
Frequently asked questions
- Are the hour ranges a quote?
- No. They are typical scopes for organisations of the size we work with, published so you can estimate before speaking to anyone. Your own quote follows an agreed scope and may land outside a range — a twenty-five person tenant is not the same job as a hundred and fifty. If your scope looks likely to exceed the range, we say so while we are scoping it, not afterwards.
- We are a small team. Are we too small to work with you?
- No — smaller organisations are most of what we do. Several of us built these controls at utility and municipal scale, and the useful part of that experience is knowing which of it applies to a team of twenty and which of it is overhead you should not pay for. An engagement is sized to your organisation, not scaled down from an enterprise template.
- What happens if the work takes longer than quoted?
- The quote is an estimate against an agreed scope, not a blank cheque. If we can see the hours running over, you hear about it before they are spent — not on the invoice. Work outside the agreed scope is re-quoted rather than absorbed quietly.
- Can we engage a single role rather than a full team?
- Yes. Some mandates are architecture only; others are implementation against a design you already have. The breakdown in the quote reflects what the work actually needs, not a fixed team shape.
- How long does an assessment take?
- Most assessments complete within two to three weeks, depending on the scope and the complexity of your systems.
- Do you provide ongoing support?
- Yes. Beyond project work we take on ongoing advisory and retainer engagements, billed the same way — hourly against an agreed scope.
- Can you work with our existing security tools?
- Yes. We work with the stack you already run rather than requiring a particular set of products — most engagements involve tooling the client already owns.
- Do you offer volume or retainer discounts?
- Volume and retainer terms are agreed per mandate. Tell us the shape of the work and we will put it in the quote.
Tell us what you need doing
Send us the shape of the work and we will come back with a scope and a quote. We reply within one business day.
Not ready to scope a mandate? A 60-minute session and a written summary of your risks costs nothing, and tells you what is worth quoting in the first place.