A pack exists because the alternative — an open-ended programme priced after a discovery phase — is how mid-market projects die. Here the scope is written down, the deliverables are listed, and the price is agreed before the first day of work.
Bands are indicative and exclude VAT. The figure inside the band depends on the number of entities, sites and systems in scope, and is fixed in the proposal after the qualification call. What does not change afterwards is the scope: if we discover the estimate was wrong, that is our problem, not a change request.
Cyber 360 Flash
Three weeks to a clear picture: maturity, exposure and the ten things to fix first.
- Duration
- 3 weeks
- Price
- €6,000 to €9,000
- excl. VAT, indicative
Made for
A first objective assessment, usually before a budget decision or a board discussion.
What is included
- Maturity assessment against NIST CSF 2.0
- External attack surface review
- Interviews with IT, business and management
- Costed action plan over twelve months
- Executive readout
OffensiveAssessment
Discuss this pack — Cyber 360 Flash
NIS2 Ready
From applicability to a defensible compliance position, with the governance duties covered.
- Duration
- 8–12 weeks
- Price
- €18,000 to €35,000
- excl. VAT, indicative
Made for
Essential or important entities that need to show progress, not intentions.
What is included
- Applicability and entity scoping
- Gap analysis against Articles 20 and 21
- Incident notification procedure and playbooks
- Management body training with attendance record
- Compliance programme with owners and dates
GRCSOC
Discuss this pack — NIS2 Ready
DORA Essentials
The four DORA pillars covered, including the register of information ready for submission.
- Duration
- 10–16 weeks
- Price
- €30,000 to €60,000
- excl. VAT, indicative
Made for
Financial entities and the ICT providers they depend on.
What is included
- ICT risk management framework
- Register of information, populated and validated
- Incident classification and reporting procedure
- Third-party contract gap review
- Resilience testing and TLPT readiness
GRC
Discuss this pack — DORA Essentials
ISO 27001 in 9 months
A certification project with a date, a fixed price and a certification body engaged early.
- Duration
- 9 months
- Price
- €25,000 to €45,000
- excl. VAT, indicative, excludes certification body fees
Made for
Companies whose customers have started asking for the certificate.
What is included
- Scope, risk assessment and statement of applicability
- Complete documented ISMS
- Control implementation support
- Internal audit and management review
- Stage 1 and Stage 2 audit support
GRC
Discuss this pack — ISO 27001 in 9 months
SOC 2 Fast Track
Type I, then the observation window for Type II, with evidence collected automatically.
- Duration
- 4–6 months
- Price
- €20,000 to €40,000
- excl. VAT, indicative, excludes auditor fees
Made for
SaaS vendors selling into North America or to enterprise security teams.
What is included
- Trust services criteria selection
- Control design and evidence automation
- Policy set and staff attestations
- Readiness assessment
- Auditor coordination through to report
GRC
Discuss this pack — SOC 2 Fast Track
Secure Cloud Start
A landing zone delivered as code in your repository, with guardrails and cost control from the first account.
- Duration
- 6–10 weeks
- Price
- €20,000 to €40,000
- excl. VAT, indicative
Made for
Organisations starting on a hyperscaler, or restarting properly.
What is included
- Account and network topology
- Identity, logging and encryption baseline
- Infrastructure-as-code modules in your repository
- Guardrail policies and exception process
- Cost allocation and budget alerts
Assessment
Discuss this pack — Secure Cloud Start
DevSecOps Kickstart
Security controls inside your pipeline, tuned so the team keeps them after we leave.
- Duration
- 6–8 weeks
- Price
- €18,000 to €30,000
- excl. VAT, indicative
Made for
Engineering teams shipping weekly with security still on the outside.
What is included
- Pipeline threat model and hardening
- SAST, SCA and IaC scanning integrated and tuned
- Secrets removed from repositories and pipelines
- Break-build policy and triage workflow
- Developer enablement session
Assessment
Discuss this pack — DevSecOps Kickstart
Kubernetes Secure
A cluster audit against the CIS benchmark, with the hardening applied and verified.
- Duration
- 3–4 weeks
- Price
- €8,000 to €15,000
- excl. VAT, indicative
Made for
Teams running production workloads on Kubernetes without a dedicated platform security owner.
What is included
- CIS Kubernetes benchmark assessment
- RBAC and admission control review
- Network policy design and rollout
- Secrets and workload identity fixes
- Verification retest
Assessment
Discuss this pack — Kubernetes Secure
Supply-Chain Shield (CRA ready)
SBOM, signing and provenance in place, mapped to what the Cyber Resilience Act will ask for.
- Duration
- 5–8 weeks
- Price
- €15,000 to €28,000
- excl. VAT, indicative
Made for
Software vendors and manufacturers placing products on the EU market.
What is included
- Product classification under the CRA
- SBOM generation and storage
- Artefact signing and SLSA provenance
- Vulnerability handling process
- Technical documentation skeleton
AssessmentGRC
Discuss this pack — Supply-Chain Shield (CRA ready)
AI Act Check
Every AI system inventoried, classified and dated, with the obligations that follow.
- Duration
- 3–4 weeks
- Price
- €6,000 to €12,000
- excl. VAT, indicative
Made for
Any organisation deploying AI without a clear regulatory position.
What is included
- AI system inventory including shadow AI
- Provider or deployer role determination
- Risk classification per system
- Obligation matrix with application dates
- Action plan and decision record
AIGRC
Discuss this pack — AI Act Check
GenAI Secure Launch
An assistant rolled out to the whole company without opening the whole file server with it.
- Duration
- 4–6 weeks
- Price
- €12,000 to €25,000
- excl. VAT, indicative
Made for
Companies switching on Copilot, ChatGPT Enterprise, Gemini or Claude.
What is included
- Permission and oversharing remediation
- Tenant, data and logging configuration
- Acceptable-use policy and user guidance
- Prompt injection and leakage testing
- Adoption and monitoring plan
AI
Discuss this pack — GenAI Secure Launch
Crisis-ready in 30 days
A crisis unit that has met, rehearsed and knows who calls the regulator.
- Duration
- 4 weeks
- Price
- €8,000 to €15,000
- excl. VAT, indicative
Made for
Organisations with a response plan that has never been tested, or none at all.
What is included
- Incident response plan and severity scale
- Playbooks for ransomware and data breach
- Regulatory notification timelines
- Facilitated crisis exercise
- Observation report and improvement plan
SOCTraining
Discuss this pack — Crisis-ready in 30 days
Cyber due diligence (M&A)
What you are buying, in security terms, in time for it to affect the price.
- Duration
- 2–3 weeks
- Price
- €8,000 to €18,000
- excl. VAT, indicative
Made for
Acquirers and investors who need a defensible view of a target's cyber posture.
What is included
- Target posture assessment
- External exposure and breach history review
- Compliance and contractual liability review
- Remediation cost estimate
- Deal-relevant red flags summary
AdvisoryGRC
Discuss this pack — Cyber due diligence (M&A)