Fixed Scope, Retainer, Hourly Rate options available

Services & engagement packages

Services can be scoped as fixed fee, time based retainer, or hourly Time and Materials.

🛒

MSSP Buyers

Everything a buyer needs to select, contract, and manage a managed security services provider — for OT/ICS/IT environments. Time & Material, Retainer and Fixed Fee options Available.

MSSP Onboarding Readiness Assessment
Understand MSSP procurement and onboarding information and resources needs to bring the most value
  • Understand scoping information needs ahead of time
  • Clearly understand the managed functionality needed from a service provider
  • Conducting threat model assessments against the MITRE ATT&CK for Enterprise and ICS
  • Total cost of ownership assessment
  • MSSP integration requirements
  • Acquisition roadmapping
RFP Build Support
A document that explains the Managed Functionality needs and Scope
  • Managed Functionality Requirements & Scope gathering workshop
  • RFP document to gather the best proposals
  • Total Cost of Ownership definition
  • Vendor shortlist assessment
Acquisition & Procurement Process Support
Independent guidance from RFP to signed contract
  • Proposal scoring & side-by-side vendor evaluation
  • Contract, SLA, and pricing review before you sign
  • Negotiation talking points for your procurement team
  • Reference checks and red-flag review
Technology POV with MSSP Integration Support
Test the vendor and the integration, not just the demo
  • POV scope, success criteria, and scoring rubric
  • Bake-off structure for finalist vendors
  • Independent observation & results readout
  • Integration plan for how the tool fits your existing MSSP
🛰️

MSSP and MDR Providers

Consulting for providers building, scaling, or repositioning a managed security service line. Time & Material, Retainer and Fixed Fee options Available.

OT Threat Detection Service Development
Build an OT detection service that holds up in the field
  • OT/ICS detection use-case & tooling strategy
  • Playbook and escalation design for OT-specific incidents
  • Staffing and skills-gap plan for OT coverage
  • Launch readiness checklist
Operations Center Optimization
Fix what's slowing your SOC down
  • Detection, triage, and escalation workflow review
  • Alert-fatigue and false-positive rate analysis
  • Staffing & tooling efficiency recommendations
  • Customer-facing SLA and reporting review
Go to Market & Sales Strategy
Sell the service you actually built
  • Positioning & messaging by buyer persona
  • RFP response framework and proposal templates
  • Sales-team enablement materials and battlecards
  • Win/loss review of recent deals
Vendor Partnership Strategy
Choose the right technology partners for your service line
  • Technology & channel-partner fit assessment
  • Partnership and reseller agreement structure review
  • Margin and packaging impact analysis
  • Partner roadmap aligned to your service strategy
🏭

Critical Infrastructure Operators — Fractional CISO

Advisory for utilities, energy, water, and industrial operators securing OT and ICS environments — including regulatory-driven programs. Time & Material, Retainer and Fixed Fee options Available.

Managed Security Integration Readiness
Get your environment ready before an MSSP walks in the door
  • Asset visibility and network segmentation review
  • Data and telemetry sourcing gap analysis
  • Escalation and communication path design
  • Integration readiness scorecard
OT Security Technology Acquisition, Selection & Advisory
Vendor-neutral guidance on OT security tooling
  • Capability-gap review across your OT environment
  • Independent evaluation of specialized point solutions
  • Build vs. buy vs. integrate recommendation
  • Vendor shortlist with rationale — no resale margin
OT Security Posture & Maturity Planning
Know where you stand and what to fix first
  • OT/ICS asset visibility & segmentation review
  • Maturity assessment against a recognized framework
  • Findings mapped to business and safety risk
  • Prioritized, budget-aware remediation roadmap
Incident Response Plans & TTX
Know what happens in the first hour, not just after
  • OT-specific incident response plan development or review
  • Roles, escalation paths, and communication plan
  • Tabletop exercise (TTX) design and facilitation
  • After-action report with remediation priorities
Executive Advisory Retainer
A standing second opinion for CISOs and boards
  • Recurring advisory calls with direct access
  • Board and executive briefing support
  • Vendor and contract review as needed
  • Direct line for incident-adjacent questions

Don't see exactly what you need?

Most engagements start as a conversation, not a package selection. Tell me your situation and I'll scope something that fits — or point you to the closest package above.