£22,000. Two to three weeks.
Cybersecurity Strategy
Our core security engagement, and the one most businesses need. A full, independent assessment of your security posture, and a prioritised plan to close the gaps that matter, led by a senior fractional CISO.
BOOK A SECURITY CALL
What it is
Cybersecurity Strategy is a full, independent assessment of your security posture and cyber risk, and a prioritised plan to fix what matters.
It is the difference between having security tools and having a security strategy.
Most businesses arrive here with an MSP, some tools, and a nagging sense that it does not all add up to real protection. This engagement gives you the plan: your posture assessed properly, your risks ranked by real exposure, and a prioritised set of actions to close the gaps that matter, led by someone who has done this in real businesses.
A senior fractional CISO spends two to three weeks with your business and comes back with a prioritised security strategy written for leaders, and a debrief that answers the questions a document cannot.
When to use it
Take Cybersecurity Strategy when you want security led properly, not patched.
It fits a business that knows security matters and wants a real plan rather than more tools. It fits a leadership team that needs to show a board, an insurer, or an investor a credible security posture. It fits a company where security has grown piecemeal and now needs direction and priority. And it fits any business that wants its cyber risk understood and managed, not just insured against.
If you are not yet sure where you stand, start with the Cybersecurity Review at £7,500.
If you will be acting on the plan and want the costed roadmap to run it, look at Cybersecurity + 90-Day Plan.
What we look at
- Security posture, across the whole business. Assessed properly, not just the IT estate.
- Cyber risk, ranked. Your real threats, assessed and prioritised, with a clear sense of where an incident would hurt most.
- Maturity. Where your security actually sits against where a business your size needs to be.
- Suppliers, cloud, and third parties. The risk outside your own walls.
- People and process. Where most breaches start, and what has to change.
- Tooling and spend. Whether what you pay for protects you, assessed independently of any vendor.
- Governance. Who owns security, and the controls a board and insurer expect.
What you receive
A prioritised cybersecurity strategy document, written for leaders, containing:
- Your security posture assessed, and where you are most exposed
- Your cyber risks ranked, in plain business terms
- A view of your security maturity against where you need to be
- A prioritised plan to close the gaps that matter
- Supplier, cloud, and third-party risk addressed
- The governance and accountability needed to keep security led
Plus a debrief with your leadership team.
Written for leaders, commercial, and independent of any tool or supplier.
Three ways to buy it
Fixed prices, published, no hourly rates. You know what the work costs and what you get before you commission it.
How it runs
Week one. Scoping and discovery. We agree your risk appetite and constraints, then assess your posture, exposure, suppliers, and people. Week two. Analysis and prioritisation. Risks ranked, maturity assessed, the plan built.
Week two to three. Strategy delivered, debrief held. You have a plan your board can act on.
Where something is clearly urgent, we flag it early rather than at the end.
Who it is for
- Businesses that want security led properly, not patched with more tools.
- Leadership teams that need to show a board, insurer, or investor a credible posture.
- Companies where security has grown organically and needs direction.
- Any business that wants its cyber risk understood and managed.
What it does not cover
Cybersecurity Strategy gives you the plan. It does not, on its own, deliver it, and it does not include the costed 90-day remediation roadmap or the working session to kick delivery off.
If you will be acting on the strategy and want the roadmap, the sequencing, the spend, and the first-quarter decisions, Cybersecurity + 90-Day Plan covers all of it at £35,000.
Find out where you're exposed, before someone else does
No pitch. A straight, independent read on your security from a CISO who has no tool to sell you.
BOOK A SECURITY CALLFrequently asked questions
What is a cybersecurity strategy?
How is this different from a cyber risk assessment?
Do we need a strategy if we already have security tools and an MSP?
How long does it take?
Can we start with something smaller?
Who does the work?
Get actionable advice every Saturday
The CTO’s Playbook
Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.