Packages + focused services Principal-led delivery Clear deliverables

Services

Start with a package for quick clarity, or choose focused support. All engagements are led directly by Adam and scoped with clear deliverables.

Packages

Start with a clear first step

These packages are designed to help business leaders move quickly from concern to a clear plan.

Security Discovery Assessment

1–2 weeks

Best first step if you are not sure where to start.

  • Workshop to identify what matters most and what could hurt the business
  • Top risks and quick improvements
  • 30, 60, and 90 day improvement plan
  • Short leadership summary

Pricing: Request quote (fixed-scope available)

Security Program Roadmap

2–4 weeks

A security plan your team can actually follow.

  • Define the level of security you are aiming for
  • Prioritized roadmap with milestones
  • Budget and staffing guidance
  • Simple metrics and reporting rhythm

Pricing: Request quote

Ongoing vCISO Advisory

Monthly

Experienced security leadership without hiring full-time.

  • Regular leadership guidance and decision support
  • Vendor and tool reviews
  • Board and executive reporting
  • Security program oversight

Pricing: Monthly retainer

Audit Readiness Sprint

4–12 weeks

Practical preparation for SOC 2, ISO 27001, or PCI.

  • Gap assessment and control mapping
  • Evidence checklist and collection playbook
  • Remediation plan and pre-audit review
  • Support coordinating the people involved

Pricing: Request quote

Want help selecting the right scope?

Book a discovery call and we will propose a clear first step with deliverables and timeline.

Book a call Email Adam
Focused services

If you already know what you need

These are common services that can be done as standalone projects or as part of ongoing advisory work.

Security Leadership / vCISO Support

  • Security strategy aligned to business goals
  • Governance, metrics, and regular check-ins
  • Executive and board-ready reporting

Typical: ongoing monthly cadence

Risk and Vulnerability Discovery

  • Workshops to understand key assets and likely threats
  • Prioritized risk list
  • Quick improvements and a remediation plan

Typical: 1–3 weeks

SOC 2 / ISO 27001 Readiness

  • Gap assessment and control mapping
  • Evidence collection checklist
  • Pre-audit readiness review

Typical: 6–12 weeks

PCI-DSS Consulting

  • Guidance on reducing scope where possible
  • Remediation plan
  • Support through QSA interactions

Typical: 4–10 weeks

Cloud Security Review

  • Identity and access review
  • Logging and monitoring baseline
  • Misconfiguration findings and fixes

Typical: 2–4 weeks

Incident Response Readiness + Tabletop

  • Incident response plan and playbooks
  • Tabletop exercise
  • Improvement plan

Typical: 1–2 weeks

Prefer a one-page capability statement?

Add a PDF later if you want. For now, we can scope everything from a discovery call.

Book a call Call 613-686-1611