Independent Consultant | Cybersecurity Architect & vCISO

Currently fully booked. New engagements onboard from early 2027.Join the 2027 waitlist

Retained security advisor

You do not need a full security department to start managing security properly. But customers already want evidence - and someone has to answer the questionnaires, decide what to fix first, close the obvious gaps, and prepare ISO 27001 or NIS2 evidence where it applies.
That is the gap a retained partnership fills.

The Pattern

What happens before companies call me

  1. 01A customer asks for security evidence.
  2. 02The founder forwards it to IT, who answer what they can.
  3. 03No one knows whether the answers are complete.
  4. 04A few tools get bought. A policy is copied from somewhere.

Three months later, the same problem returns. The retainer breaks the cycle.

Who This Is For

This is for you if

Founder-led European SMEs that already feel security pressure but are not ready to hire a full-time CISO.

  • Enterprise customers ask you for security evidence.
  • Tenders mention ISO 27001, CIS Controls, NIS2, or supplier assurance.
  • IT is doing its best, but no one owns security priorities.
  • Policies exist, but the evidence behind them is scattered.
  • You want real progress without building a security department.

Pricing

The monthly retainer

One senior expert, a fixed monthly hour cap, and no tool resale - never an automated report. You are not paying for generic deliverables; you are paying for the judgement and communication that fit them to your situation. Your tier is set after the Starter Assessment or Starter Month, and moves up or down as you grow.

Advisory Line

€950 / mo

up to 8 hours / mo

  • Senior advisory access within a fixed monthly capacity, under NDA
  • Light questionnaire and supplier support, within the cap
  • Quarterly review keeps the roadmap current

For companies that need occasional senior security backup, not active monthly delivery

Security Programme

Core
€2,100 / mo

up to 18 hours / mo

  • Monthly progress against the roadmap, not just advice
  • Quarterly risk and supplier reviews
  • ISO 27001 or CIS work moving every month

For companies that need monthly progress and evidence before customers ask again

Embedded Partner

from €5,800 / mo

up to 48 hours / mo

  • Near part-time, embedded in your team
  • Certification or NIS2 readiness sprints
  • Architecture guidance and board-ready reporting

For companies that need a near part-time senior security lead - the most dedicated model. One embedded engagement at a time

All prices exclude VAT where applicable. I do not invoice minute-by-minute, but I track capacity internally so we both see when the monthly cap is being consumed. The cap covers calls, review, documentation, and email together.

Founding rate

Available for a limited number of early retainer clients while this offer is being introduced. The rate you sign at is guaranteed for your first 12 months.

How it works in practice

  • Each month we agree the priority work and spend the hour cap against it.
  • I choose the tools with you - open-source where it genuinely fits, the right commercial product where it does not. No resale, no commission.
  • You get a short monthly summary: what changed, what is open, what needs a management decision.
  • Async support counts against the monthly cap. Once it is used up, extra work is deferred, quoted separately, or moved to a higher tier - your call.
  • Monthly rolling. Unused hours do not carry over. Two months notice to end.

Not included by default

  • 24/7 monitoring or emergency incident response.
  • Full hands-on tool deployment and rollout - time-heavy, custom-priced.
  • Full penetration tests, audit certification fees, tool licences.
  • Legal advice, on-site work, and travel.
  • Large evidence or questionnaire spikes - scoped separately.

Tools and implementation

I own the security analysis, recommendations, roadmap, and GRC coordination; the final business decisions stay with management. I guide implementation, but full hands-on deployment is time-heavy and sits outside the monthly hour cap - where you want me to run a rollout end to end, we scope it separately at custom pricing. For material residual risk I also flag practical transfer options such as cyber insurance - mature security is a mix of prevention, preparedness, and risk transfer.

Start Here

How to start

Two low-commitment steps before any retainer. You decide after each one.

I'm currently fully booked and onboarding new engagements from early 2027. Run the Discovery Calculator now and join the waitlist - the steps below describe how we work together once a slot opens.

Run the Discovery Calculator if you are not yet sure where you stand, or book a call if you already know you need help. The Starter Assessment is the normal paid entry; the Starter Month is for larger or more involved situations.

01

Discovery Calculator

Free, self-serve

Answer a short set of questions and get an instant read on your likely path - CIS Critical Controls, ISO 27001, or the NIS2 Directive - and a sensible retainer level. Send the results over to open a free 30-minute scoping call.

Start the Discovery Calculator
02

Pick your entry door

Paid, fixed scope - both end with a roadmap and a recommended retainer tier

Starter Assessment

Default
€1,900

Up to 2.5 man-days

Fixed price · one-off

  • Kick-off discovery call
  • Guided gap analysis - CIS or ISO 27001 track
  • Quick wins identified, one fixed together
  • A 6-month roadmap with recommendations
  • An executive presentation for management

Starter Month

Extended
€2,900

Up to 4 man-days

Fixed price · one-off

  • Everything in the Starter Assessment
  • Larger cap for hands-on implementation, not just analysis
  • For larger or more involved situations

Both doors are delivered by one senior expert - no junior handoff, no tool resale.

An NDA is in place up front. €700 (Starter Assessment) or €1,000 (Starter Month) is credited against your retainer if you sign a 6+ month retainer within 30 days. No lock-in before that.

03

Your path + roadmap

The result you walk away with

One framework, chosen against your real systems, plus quick wins, a prioritised 6-month roadmap, and an executive presentation for management. The path is one of three:

CIS Controls
A defensible baseline for customer questionnaires and GDPR basics, no certification overhead.
ISO 27001
A working ISMS with a clear route to certification, for tenders, enterprise customers, and investors.
NIS2
Management-ready evidence, reporting, and governance for regulated or near-regulated companies.

Whichever path, the security core is shared. Moving up later is a scope increase, not a restart - the work you already did stays in scope.

If the way of working fits, we sign a retainer and continue month to month.

Where This Gets You

Where the retainer takes you

The maturity model is not a test you pass on day one. It is the direction the retainer moves you: over the first months security shifts from reactive and fragmented to a managed rhythm that supports real business decisions.

Stage 1

Reactive

Security is handled when something breaks, a customer asks a difficult question, or an incident forces action.

Stage 2

Compliance-Driven

Security work happens around audits, tenders, questionnaires, or regulation - but ownership, evidence, and follow-up are still inconsistent.

Stage 3

Working ISMS

Security is reviewed, evidenced, improved, and used in business decisions before customers, auditors, or regulators force the issue.

Most SMEs start between Stage 1 and Stage 2. Within the first months of the retainer, security becomes a managed operating rhythm instead of occasional project work.

Join the 2027 waitlist

I'm currently fully booked and onboarding new engagements from early 2027. Run the Discovery Calculator and join the waitlist - I'll recommend the entry door and retainer tier when we speak.

Have questions? See the FAQ →