Skip to content
A surviving section of Roman wall, its original masonry set clearly apart from the later work built above it.

Fixed price

Packs

Named engagements with a defined scope, a published timeline and a price band you can take to a budget meeting.

A pack exists because the alternative — an open-ended programme priced after a discovery phase — is how mid-market projects die. Here the scope is written down, the deliverables are listed, and the price is agreed before the first day of work.

Bands are indicative and exclude VAT. The figure inside the band depends on the number of entities, sites and systems in scope, and is fixed in the proposal after the qualification call. What does not change afterwards is the scope: if we discover the estimate was wrong, that is our problem, not a change request.

Cyber 360 Flash

Three weeks to a clear picture: maturity, exposure and the ten things to fix first.

Duration
3 weeks
Price
€6,000 to €9,000
excl. VAT, indicative

Made for

A first objective assessment, usually before a budget decision or a board discussion.

What is included

  • Maturity assessment against NIST CSF 2.0
  • External attack surface review
  • Interviews with IT, business and management
  • Costed action plan over twelve months
  • Executive readout
Cyber

Discuss this pack — Cyber 360 Flash

NIS2 Ready

From applicability to a defensible compliance position, with the governance duties covered.

Duration
8–12 weeks
Price
€18,000 to €35,000
excl. VAT, indicative

Made for

Essential or important entities that need to show progress, not intentions.

What is included

  • Applicability and entity scoping
  • Gap analysis against Articles 20 and 21
  • Incident notification procedure and playbooks
  • Management body training with attendance record
  • Compliance programme with owners and dates
ComplianceCyber

Discuss this pack — NIS2 Ready

DORA Essentials

The four DORA pillars covered, including the register of information ready for submission.

Duration
10–16 weeks
Price
€30,000 to €60,000
excl. VAT, indicative

Made for

Financial entities and the ICT providers they depend on.

What is included

  • ICT risk management framework
  • Register of information, populated and validated
  • Incident classification and reporting procedure
  • Third-party contract gap review
  • Resilience testing and TLPT readiness
Compliance

Discuss this pack — DORA Essentials

ISO 27001 in 9 months

A certification project with a date, a fixed price and a certification body engaged early.

Duration
9 months
Price
€25,000 to €45,000
excl. VAT, indicative, excludes certification body fees

Made for

Companies whose customers have started asking for the certificate.

What is included

  • Scope, risk assessment and statement of applicability
  • Complete documented ISMS
  • Control implementation support
  • Internal audit and management review
  • Stage 1 and Stage 2 audit support
Compliance

Discuss this pack — ISO 27001 in 9 months

SOC 2 Fast Track

Type I, then the observation window for Type II, with evidence collected automatically.

Duration
4–6 months
Price
€20,000 to €40,000
excl. VAT, indicative, excludes auditor fees

Made for

SaaS vendors selling into North America or to enterprise security teams.

What is included

  • Trust services criteria selection
  • Control design and evidence automation
  • Policy set and staff attestations
  • Readiness assessment
  • Auditor coordination through to report
Compliance

Discuss this pack — SOC 2 Fast Track

Secure Cloud Start

A landing zone delivered as code in your repository, with guardrails and cost control from the first account.

Duration
6–10 weeks
Price
€20,000 to €40,000
excl. VAT, indicative

Made for

Organisations starting on a hyperscaler, or restarting properly.

What is included

  • Account and network topology
  • Identity, logging and encryption baseline
  • Infrastructure-as-code modules in your repository
  • Guardrail policies and exception process
  • Cost allocation and budget alerts
CloudCyber

Discuss this pack — Secure Cloud Start

DevSecOps Kickstart

Security controls inside your pipeline, tuned so the team keeps them after we leave.

Duration
6–8 weeks
Price
€18,000 to €30,000
excl. VAT, indicative

Made for

Engineering teams shipping weekly with security still on the outside.

What is included

  • Pipeline threat model and hardening
  • SAST, SCA and IaC scanning integrated and tuned
  • Secrets removed from repositories and pipelines
  • Break-build policy and triage workflow
  • Developer enablement session
Cloud

Discuss this pack — DevSecOps Kickstart

Kubernetes Secure

A cluster audit against the CIS benchmark, with the hardening applied and verified.

Duration
3–4 weeks
Price
€8,000 to €15,000
excl. VAT, indicative

Made for

Teams running production workloads on Kubernetes without a dedicated platform security owner.

What is included

  • CIS Kubernetes benchmark assessment
  • RBAC and admission control review
  • Network policy design and rollout
  • Secrets and workload identity fixes
  • Verification retest
Cloud

Discuss this pack — Kubernetes Secure

Supply-Chain Shield (CRA ready)

SBOM, signing and provenance in place, mapped to what the Cyber Resilience Act will ask for.

Duration
5–8 weeks
Price
€15,000 to €28,000
excl. VAT, indicative

Made for

Software vendors and manufacturers placing products on the EU market.

What is included

  • Product classification under the CRA
  • SBOM generation and storage
  • Artefact signing and SLSA provenance
  • Vulnerability handling process
  • Technical documentation skeleton
CloudCompliance

Discuss this pack — Supply-Chain Shield (CRA ready)

AI Act Check

Every AI system inventoried, classified and dated, with the obligations that follow.

Duration
3–4 weeks
Price
€6,000 to €12,000
excl. VAT, indicative

Made for

Any organisation deploying AI without a clear regulatory position.

What is included

  • AI system inventory including shadow AI
  • Provider or deployer role determination
  • Risk classification per system
  • Obligation matrix with application dates
  • Action plan and decision record
AICompliance

Discuss this pack — AI Act Check

GenAI Secure Launch

An assistant rolled out to the whole company without opening the whole file server with it.

Duration
4–6 weeks
Price
€12,000 to €25,000
excl. VAT, indicative

Made for

Companies switching on Copilot, ChatGPT Enterprise, Gemini or Claude.

What is included

  • Permission and oversharing remediation
  • Tenant, data and logging configuration
  • Acceptable-use policy and user guidance
  • Prompt injection and leakage testing
  • Adoption and monitoring plan
AICyber

Discuss this pack — GenAI Secure Launch

Crisis-ready in 30 days

A crisis unit that has met, rehearsed and knows who calls the regulator.

Duration
4 weeks
Price
€8,000 to €15,000
excl. VAT, indicative

Made for

Organisations with a response plan that has never been tested, or none at all.

What is included

  • Incident response plan and severity scale
  • Playbooks for ransomware and data breach
  • Regulatory notification timelines
  • Facilitated crisis exercise
  • Observation report and improvement plan
Cyber

Discuss this pack — Crisis-ready in 30 days

Cyber due diligence (M&A)

What you are buying, in security terms, in time for it to affect the price.

Duration
2–3 weeks
Price
€8,000 to €18,000
excl. VAT, indicative

Made for

Acquirers and investors who need a defensible view of a target's cyber posture.

What is included

  • Target posture assessment
  • External exposure and breach history review
  • Compliance and contractual liability review
  • Remediation cost estimate
  • Deal-relevant red flags summary
Cyber

Discuss this pack — Cyber due diligence (M&A)

What happens after a pack

Every pack ends with a costed action plan. Some clients take it and execute internally, which is a legitimate outcome and one we plan for: the plan is written to be handed over, not to require us.

Most ask us to carry the plan forward — either as targeted missions from the catalogue, or as a recurring service that keeps the work alive at a known monthly cost. We make that proposal within fifteen days of the readout, and there is no obligation attached to it.

See recurring services →

Not sure which pack fits?

Describe the deadline you are working to. We will tell you which pack answers it, or say plainly that none of them does.