Skip to content

Retained advisory

Security judgment, on retainer.

Ongoing advisory for organizations that need senior security input on architecture, tooling and risk without hiring a full-time security leader.

Service

InfoSec Consulting

Engagement

Retained advisory

Retainer

8, 16 or 32 hours a month

The problem

Nobody owns the security decision

Below a certain size there is no security function. Decisions get made by whoever is closest. A vendor recommends a tool, an engineer picks a default, a questionnaire gets answered optimistically. None of it is wrong on purpose. It is just unowned, and the gaps only become visible in an incident or an audit.

Scope

What the engagement covers.

Anything outside this list is quoted separately rather than absorbed quietly.

Security architecture review of new and existing systems
Detection engineering in Microsoft Sentinel and Defender XDR
Vulnerability management process, not just scanning
Third-party and vendor security assessment
Security questionnaire and customer due-diligence support
Incident response preparation: runbooks, roles and tabletop exercises
Policy authoring that reflects what you actually do

Deliverables

What you are left holding.

Every item here is an artifact you own, in your systems, readable by someone who was not in the room.

01

Risk register

Maintained, prioritized, and reviewed on a cadence. Not a one-time spreadsheet.

02

Architecture review notes

Written findings on each system reviewed, with the decision recorded either way.

03

Detection coverage map

What you can currently detect, what you cannot, and what it would take to close the difference.

04

Incident runbooks

Rehearsed in a tabletop with your team, not filed unread.

Retainer: 8, 16 or 32 hours a month

Three-month minimum. The first month is assessment. Every tier includes a monthly review call, a maintained risk register and a reply within one business day. The fee is quoted against your scope.

Fit

Who this is for, and who it is not.

We would rather lose the engagement at this paragraph than three weeks in.

A good fit if

  • You have no CISO and no plan to hire one this year
  • Customers are sending you security questionnaires you cannot answer confidently
  • You have security tooling but no one deciding what it should be doing

Not a fit if

  • You need penetration testing. That requires an independent testing firm, and we will recommend one
  • You need 24/7 monitoring and response. That is a SOC, and we will help you select one

Questions

About InfoSec consulting.

Is this a virtual CISO or vCISO service?

Functionally that is what it is, and most buyers searching for a vCISO are describing this engagement. We avoid the title because it promises an officer of the company, and a retained advisor is not that. What you get is senior security judgment on a defined cadence, with the decisions written down and a risk register that stays current. What you do not get is someone who will sit in every meeting or carry a pager.

Do you do penetration testing?

No, and you should be cautious of anyone who both designs your controls and tests them. We will scope the test, help you select an independent firm, and then own remediation of what they find.

Can you help with a security questionnaire this week?

Usually yes, and it is a common way engagements start. Be aware that answering the questionnaire honestly often surfaces work you had not planned. We would rather find that now than during the customer audit.

Often paired with

What this usually runs alongside.

These are the combinations that come up most often, not an upsell list.

InfoSec Consulting

Thirty minutes, no pitch.

Tell us what the environment looks like today. We will tell you what we would change first, and whether this is the right engagement for it.