Fixed engagement
For organizations carrying real security obligations without a full-time security executive. Ongoing ownership of the security program, board and executive reporting, vendor and audit management, incident response readiness, and the risk conversations that leadership actually needs answered.
What's included
Who this fits
Best fit is an organization of roughly 50 to 500 employees that is regulated or handles sensitive data, and does not have a dedicated security leader on staff today.
How it works
A published price tells you what something costs. It does not tell you whether it is the right thing to buy — and those are different questions.
So the engagement begins with a conversation about what is actually going on, then a written scope covering the specific outcomes, what is included, what is not, the timeline, and who is responsible for what. You see that document before any money changes hands.
Questions
Ongoing ownership of the security program: board and executive reporting, vendor and audit management, incident response readiness, and the risk conversations leadership actually needs answered — about 30 hours a month.
From $8,000 per month, roughly 30 hours of work monthly, with a three-month minimum engagement.
Organizations of roughly 50 to 500 employees that are regulated or handle sensitive data, and that don't have a dedicated security leader on staff today.
With a conversation about what's actually going on, then a written scope covering outcomes, what's included, what isn't, the timeline, and who's responsible for what. You see that document before anything is committed.
Tyson McKay, CISSP, with roughly 30 years of IT leadership including CIO and CISO roles in regulated healthcare and legal-technology environments — including taking a healthcare organization's security posture from 35% to 89% over three years.
Get started
Tell me what's going on and I'll send back a written scope before anything is committed.