When you need it
Security depends on a few busy people. Teams do not know which findings to fix first or by when, threat modelling happens only when someone insists, and every exception is a one-off conversation that nobody writes down.
What sets the quote
- One engineering organisation of up to 10 teams or 100 engineers.
- Up to 10 security champions, usually one per team.
- One 3-hour training session for up to 25 developers.
- A dashboard built on your existing tools, with no new licences.
- Larger organisations are quoted after the call.
What changes
- Each team has a named security champion with an agreed role and time budget.
- Teams threat model new features the same way, with STRIDE and a shared template.
- Every vulnerability has a fix deadline set by severity, and every exception has an owner and an end date.
- Security criteria are part of the definition of done, so they are checked in normal work rather than in a separate review.
- Leaders see open findings, missed deadlines and exceptions on one dashboard.
What you get
- Security champions programme for up to 10 champions: role, time budget, selection, meeting rhythm and onboarding
- Threat modelling practice: when to run one, a STRIDE-based template and a first session run with one team
- Vulnerability fix deadlines by severity, agreed with your leadership
- Exception register with owners, end dates and a review rhythm
- Security criteria for your definition of done
- Dashboard on your existing tools, showing findings by age and severity, deadlines met and open exceptions
- One 3-hour training session for up to 25 developers
- Handover to your security owner, with a 90-day plan for the champions
This package often follows a DevSecOps gap check. The gap check shows where you stand against OWASP SAMM; this package puts the people and process parts of the 90-day plan in place, so the gates in your pipelines have owners and deadlines behind them.
Not included
- New tool licences or tool rollouts
- Fixing existing vulnerabilities
- Security awareness training for staff outside engineering
- Running the programme after handover (available as fractional platform and security architect support)
What we need from you
- An executive sponsor who approves the fix deadlines and the champions' time budget.
- Your security owner and engineering lead, about 3 hours a week each.
- Up to 10 nominated champions for a 2-hour kickoff.
- Read access to your issue tracker and security scanners for the dashboard, for example Jira and GitHub or GitLab security findings.
- A 3-hour slot in your developers' calendars for the training session.
How it works
Free 30-minute call, then a written fixed quote based on your team and engineer counts.
Workshops with your leads to agree fix deadlines, the exception process and the definition of done.
Select and onboard the champions, and run a first threat model with one team.
Build the dashboard and deliver the training session.
Handover and a 90-day plan for your security owner.
At a glance
- Duration
- 3–4 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
DevSecOps gap check
In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.
Pipeline security check
A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.
Keyless pipelines and secrets cleanup
Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.