What We Do

Services

Background Image

What we do

Our core services

Three services anchor how we work with mid-size regulated businesses and enterprise organisations — fractional CISO leadership, fixed-fee security assessments and AI security & governance — supported by a broader advisory practice.

Core service 01

Fractional CISO (vCISO)

A $300K-plus full-time CISO is a hire most mid-size companies cannot keep busy. We carry the CISO mandate — strategy, board narrative and accountability — as a fractional appointment, from light advisory to embedded leadership.

Retainer tiers

  • Advisory — $5,500 + GST / month
  • Leadership — $11,000 + GST / month
  • Embedded — $19,000 + GST / month
  • All tiers: board reporting, obligations mapped, uplift governance

Outcome: structured leadership, executive clarity, accountable security.

Core service 02

Fixed-Fee Security Assessments

Principal-led, two-week assessments delivered to a fixed scope, a fixed price and a fixed date. Findings and a ranked view of what matters — written for a board, not a tool dashboard.

Includes

  • Security Solution Assessment — one system, $9,500 + GST
  • Security Architecture Maturity Assessment — $19,000 + GST
  • AI Readiness Security Assessment — $19,000 + GST
  • Two weeks, fixed price, no procurement panel required

Outcome: an independent, board-ready read on where you actually stand.

Core service 03

AI Security & Governance

Your teams are already using AI — the only question is whether it is governed. We put the guardrails, controls and architecture patterns around AI adoption so it moves fast without creating tomorrow’s incident, and so the answer holds up when the regulator or the board asks.

Includes

  • AI governance: policy, acceptable use and decision rights
  • Controls for data flowing into and out of AI systems
  • AI security architecture patterns for regulated environments
  • AI Readiness Security Assessment — $19,000 + GST, two weeks

Outcome: AI adoption the board can approve and the regulator can inspect.

More ways we help

Security Strategy & Architecture

Pragmatic, enterprise-grade security capability aligned to business objectives: 3–5 year strategies and roadmaps, SABSA-aligned enterprise architecture, capability maturity assessments and vendor evaluations.

Outcome: clear direction, prioritised investment, measurable risk reduction.

Assurance & Compliance

Practical support to prepare for audits and regulatory requirements across IRAP, the Essential Eight, ISO 27001, NIST CSF and APRA CPS 234: gap assessments, control uplift planning, internal audits, policy and standards development.

Outcome: audit readiness with defensible evidence.

Security Talent Advisory

Building the right security capability: team structure design, role definition and assessment, and executive hiring support.

Outcome: the right people aligned to your security maturity goals.

Not ready to talk? Start with the free “Are we OK?” board questions pack, written for executives who chair the security conversation.

Get the free pack

Schedule a Discovery Consultation

Free resources for executives

The security brief for executives

Plain-language security insight for leaders of regulated businesses. No noise, unsubscribe any time.

Subscribed. The next brief will land in your inbox.