£35,000. Three to four weeks.
Cybersecurity + 90-Day Plan
Everything in Cybersecurity Strategy, plus the plan for what you do about it. You close knowing not just what is exposed, but what gets fixed first, what it costs, and who does it.
BOOK A SECURITY CALL
What it is
Cybersecurity + 90-Day Plan is our full security engagement for businesses that are going to act, not just assess.
It is the strategy, plus the answer to "and then what".
You get everything in Cybersecurity Strategy, your posture assessed, your risks ranked, the honest view of what matters, and then the remediation plan on top: a costed, sequenced 90-day plan that says what gets fixed first, what it costs, who needs to do it, and how it maps to your business risk.
A senior fractional CISO spends three to four weeks with your business and ends with a working session that puts the plan in your team's hands and, where you want it, helps start putting it in place.
When to use it
Take this when you own the risk and intend to move on it.
It fits a business that has decided to get its security in order and wants to be executing inside a quarter. It fits a leadership team that needs a resourced, costed remediation plan the board can fund. It fits any situation where the gap between knowing you are exposed and actually fixing it is the thing that leaves you at risk, and you want that gap closed from the start.
If you are still establishing where you stand, start with the Cybersecurity Review.
If you want the strategy but will resource remediation separately, Cybersecurity Strategy at £22,000 may be enough.
What we look at
Everything in Cybersecurity Strategy, plus:
- Sequencing. What gets fixed first, second, third, ordered by risk rather than noise.
- Cost. What the first 90 days of remediation actually cost, in tools, people, and time.
- Resourcing. Who does the work, and whether you build, hire, or bring it in.
- First-quarter decisions. The security calls leadership needs to make in the first ninety days, surfaced now.
- Fit to your risk. The 90-day plan mapped to your actual business risk, not written in isolation.
What you receive
Everything in the Cybersecurity Strategy report, plus:
- A costed 90-day security plan, sequenced by risk and value
- The fixes to make first, and how to resource them
- The spend, the skills, and the decisions needed in the first quarter
- Supplier and third-party actions, prioritised
- The whole plan mapped to your business risk
Plus a working session with your leadership team and, where you want it, a fractional CISO to start putting it in place.
Three ways to buy it
Fixed prices, published, no hourly rates. You know what the work costs and what you get before you commission it.
How it runs
Weeks one and two. The full Cybersecurity Strategy engagement, as above. Week three. Planning. We build the costed, sequenced 90-day remediation plan: what gets fixed, what it costs, who does it.
Week three to four. Plan delivered, working session held. Your team leaves with the strategy, the plan, and the first fixes underway.
Who it is for
- Businesses that have decided to get their security in order and want to be executing inside a quarter.
- Leadership teams that need a resourced, costed remediation plan the board can fund.
- Companies that want the strategy and the remediation roadmap in one engagement.
- Any business where closing the gap between knowing and fixing is the whole point.
What it does not cover
This engagement gives you the strategy and the 90-day plan, and starts remediation in the working session. It is not, by itself, an open-ended security delivery contract or a managed service. Where you want ongoing execution or day-to-day security operations beyond the first steps, that is a fractional CISO or a managed provider, which we can help put in place off the back of the plan.
Find out where you're exposed, before someone else does
No pitch. A straight, independent read on your security from a CISO who has no tool to sell you.
BOOK A SECURITY CALLFrequently asked questions
What is included in the 90-day plan?
How is this different from Cybersecurity Strategy?
Do you fix the problems as well?
Who should choose this over Cybersecurity Strategy?
How long does it take?
What do you need from us?
Get actionable advice every Saturday
The CTO’s Playbook
Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.