Advice and hands-on help after a finding, before a launch, or when something has already gone wrong
Use consulting when you already know the question. You have a report you do not trust. A client or insurer asked for evidence. A site was compromised. A launch is in two weeks and nobody has reviewed the application.
We do not sell a standing “virtual CISO” package as a condition of help. If a short, scoped engagement is enough, that is what we propose.
Turn a findings list into a sequence your developers or IT provider can execute. We distinguish what is urgent from what is noise, and we will say when a recommended fix is worse than the issue.
Containment advice, evidence handling, and recovery of a website or application after unauthorized access. We will tell you quickly if the matter needs counsel or a specialist firm beyond our scope.
Read a draft policy, a proposed hosting design, or a vendor’s security claims and tell you what is missing. Written comments, not a slide deck of platitudes.
Help answering client, insurer, or partner security questionnaires with statements that match what you actually do — not what a template claims you do.
Consulting is quoted as a fixed scope (hours or a defined deliverable) after we understand the question. There is no requirement to retain us monthly.
If we cannot help — wrong specialty, conflict, or the work needs a law firm first — we will say so in the first reply.
Incident details and draft reports are treated as confidential client material. We do not discuss other clients’ incidents as case studies.
If you are in an active incident, say so in the subject line. We prioritize those inquiries during business hours.
A short note is enough: what happened or what decision you need to make, and when.