£7,500. Five working days.
Cybersecurity Review
A fast, independent read on where your security actually stands, and where you are most exposed. No tool to sell you, no scare tactics, just the honest picture and the quick wins you can act on now.
BOOK A SECURITY CALL
What it is
The Cybersecurity Review is a short, senior read on your security posture, run before you commit to a bigger programme or spend.
It answers one question quickly: where are you exposed, and how badly? A fractional CISO spends five working days looking at your security the way an attacker, an insurer, or an investor would, and comes back with the five risks that matter most, ranked, and the quick wins you can act on immediately.
It is not a full security strategy and does not pretend to be. It is the fast, honest health check most businesses should do first, before they buy another tool or sign another contract in the hope it fixes something.
When to use it
Take the Cybersecurity Review when you suspect you are exposed and want a straight answer fast.
It fits a leadership team that has never had an independent look at its security. It fits a board that wants a quick, honest read on cyber risk before a bigger decision. It fits a business that has bought security tools and an MSP and still is not sure it is actually protected. And it fits anyone facing a customer security questionnaire or investor scrutiny who needs to know where they stand before they answer.
If you already know you need a full plan, look at Cybersecurity Strategy at £22,000.
What we look at
Five days is short, so we spend it on the exposures most likely to hurt you rather than covering everything shallowly.
- Your overall security posture, at a senior level, where the real weaknesses are.
- The top risks, ranked. What an attacker would go for, and what would hurt most.
- Obvious exposure. The gaps that should not still be open, and often are.
- Suppliers and cloud, at headline level. Where third-party risk is sitting.
- People and process. The human gaps that tools do not close.
What you receive
A short written report, usually five to eight pages, containing:
- Your top five security risks, ranked by real exposure
- A clear view of where you are most vulnerable, and why
- The quick wins you can act on immediately
- A recommendation on whether a full security strategy is warranted, and where it should focus
- A thirty-minute debrief with your leadership team
- Plus a thirty minute debrief with the deal team, where you can ask the questions the report will not have anticipated.
Written for leaders, in plain language, independent of any tool or supplier.
Three ways to buy it
Fixed prices, published, no hourly rates. You know what the work costs and what you get before you commission it.
How the week runs
Day one. Scoping call. We agree what matters most so the five days are well spent.
Days two to four. Assessment. We review your posture, exposure, suppliers, and people, with working sessions where useful.
Day five. Report delivered, debrief held. You have it in hand for your board.
If we find something serious on day two, you hear about it on day two, not day five.
Who it is for
- Leadership teams that have never had an independent security review.
- Boards wanting a fast, honest read on cyber risk.
- Businesses with tools and an MSP that still are not sure they are protected.
- Companies facing a customer or investor security questionnaire.
What it does not cover
The Cybersecurity Review is a fast posture read. It does not build a full security strategy, produce a costed remediation roadmap, or deliver the fixes. It gives you the ranked exposure and the quick wins, not a complete programme.
If you need those, Cybersecurity Strategy covers them at £22,000 over two to three weeks.
Find out where you're exposed, before someone else does
No pitch. A straight, independent read on your security from a CISO who has no tool to sell you.
BOOK A SECURITY CALLFrequently asked questions
What is a cybersecurity review?
What is the difference between this and a security posture assessment?
Is five days really enough?
What if you find something serious?
Can we upgrade to a full strategy afterwards?
Is this just fear-selling with a fee attached?
Get actionable advice every Saturday
The CTO’s Playbook
Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.