A security engagement starts with a fixed-scope, fixed-fee review against read-only access, two to three weeks depending on the size of the estate. Remediation is quoted after the findings exist, never before: a remediation quote written ahead of the review is a guess with an invoice attached, and it is always the wrong shape.
- 01The review. Read-only access. No agents installed, no change window, no production risk. The output is a written findings register in which every entry carries the blast radius, a named owner, and the remediation as we would actually build it. You keep the document whether or not you engage us to act on it.
- 02The remediation. Scoped per cluster of findings, landing in your repositories as reviewed infrastructure-as-code. Preventive controls go in ahead of detective ones: a guardrail that makes the mistake impossible outranks an alert that reports it on Monday morning.
- 03How it is priced. Fixed fee for the review against a stated scope. Scoped outcome per remediation cluster. Senior retainer for ongoing posture. We do not resell security products and we take no margin on the tooling we recommend, which is why the recommendation is worth reading.
- 04What we will not do. Quote remediation before the review exists. Claim accreditation we do not hold. Staff a 24/7 console. Export a console’s findings list and call it an audit. Act as your engineer and your certification body at the same time.
// start the conversation · [email protected]