Transparent pricing. Senior execution.

Four service products designed to match where your company is and what is driving urgency. Every engagement is scoped precisely — no retainer-for-retainer's-sake.

Anchor Service

Fractional CISO Retainer

Ongoing security program leadership for technology companies that need a senior security executive — without the $300K full-time commitment.

$8,500/month
~15 hours/month
Minimum 3 months, then month-to-month

What's Included

  • Monthly security program status review and roadmap update
  • Risk register review and prioritization
  • Quarterly board or executive security reporting
  • Security policy and procedure development
  • Vendor security assessment and third-party risk management
  • Incident response advisory and on-call guidance
  • Compliance framework monitoring (SOC 2, ISO 27001, HIPAA, PCI DSS)
  • Up to 2 hours ad-hoc advisory included; additional at $350/hr

Deliverables

  • Written monthly security program status report
  • Updated risk register with prioritized action items
  • Executive security summary (board-ready on request)
Best For
Series A/B SaaS companies (50–200 employees) facing SOC 2, ISO 27001, or investor/board pressure. No in-house security leadership.
Discuss This Engagement
Fixed Scope

SOC 2 / ISO 27001 Readiness Sprint

Structured readiness program with a hard audit deadline. Four consecutive SOC 2 Type II audits with zero exceptions — across two different organizations.

$18,000–$25,000
Project-based
60–90 days

What's Included

  • Gap assessment against SOC 2 TSC or ISO 27001:2022 controls
  • Risk assessment and remediation roadmap
  • Policy and procedure development (all required domains)
  • Control design and documentation
  • Audit evidence collection setup
  • Auditor selection support
  • Pre-audit internal readiness walkthrough
  • Post-audit findings remediation support

Deliverables

  • Gap Analysis Report with prioritized remediation roadmap
  • Control Documentation Package
  • Audit Readiness Report + Evidence Package
Best For
Companies with a customer-driven audit deadline, first or second SOC 2 engagement, or ISO 27001 certification requirement.
Discuss This Engagement
High Demand 2026

AI Security Governance Framework

EU AI Act enforcement begins August 2026. Only 6% of organizations have an advanced AI security strategy. This engagement builds the framework before regulators or customers force it.

$12,000–$18,000
Project-based
30–45 days

What's Included

  • AI tool and use case inventory across the organization
  • Risk assessment against NIST AI RMF and EU AI Act requirements
  • AI Acceptable Use Policy development
  • Data governance controls for AI training and inference data
  • Vendor AI risk assessment framework and questionnaire
  • Executive and board briefing on AI risk posture
  • Alignment mapping to applicable regulatory frameworks

Deliverables

  • AI Use Case Registry
  • AI Acceptable Use Policy (draft, ready for legal review)
  • AI Risk Assessment Methodology
  • Vendor AI Security Assessment Questionnaire
  • Board-ready AI Risk Summary
Best For
Any technology company using AI tools across the organization — especially those with enterprise customers asking about AI governance.
Discuss This Engagement
Fixed Scope

Incident Response Planning & Tabletop Exercise

Cyber insurance now requires documented IR plans. This engagement builds the plan, assigns the roles, and validates it with a live tabletop exercise.

$8,500–$12,000
Project-based
30 days

What's Included

  • Review or development of Incident Response Plan (NIST SP 800-61 aligned)
  • Role and responsibility matrix development
  • Communication templates (internal, customer, regulatory, media)
  • Tabletop exercise design (2–3 hours with key stakeholders)
  • Tabletop exercise facilitation
  • Post-exercise gap analysis

Deliverables

  • Complete Incident Response Plan
  • Role assignment matrix and contact directory
  • Communication templates package
  • Post-exercise findings report with prioritized action items
Best For
Companies renewing cyber insurance, facing an enterprise customer IR requirement, or that have never tested their incident response capabilities.
Discuss This Engagement
Low-Barrier Entry

Hourly Advisory

Senior security guidance when you need a specific question answered or a decision reviewed. Often the starting point for retainer relationships.

$350/hour
2-hour minimum blocks
On-demand

What's Included

  • Any security topic within scope of expertise
  • Written summary of recommendations upon request
  • Follow-up questions via email for 5 business days after session

Deliverables

  • Varies by engagement — discussed at booking
Best For
Companies that need targeted guidance without an ongoing commitment. Due diligence reviews, vendor assessments, policy reviews, security architecture questions.
Discuss This Engagement
Early Stage

Board / Fractional Advisor

Security credibility and governance for early-stage startups that need to answer investor and customer security questions — not a full program yet.

$3,000/month
~4 hours/month
Ongoing

What's Included

  • Monthly advisory session (2 hours)
  • Investor and customer security questionnaire support
  • Security roadmap for future compliance programs
  • Ad-hoc email advisory (reasonable scope)

Deliverables

  • Security posture summary for investor/board use
Best For
Pre-Series A or Seed-stage companies where investors are asking about security posture.
Discuss This Engagement