When you need it
Security questions arrive every week, from customer questionnaires and new suppliers to designs nobody has reviewed. It is too much to ignore and not enough for a full-time security architect.
What sets the quote
- Agreed days each month, typically 2, 4 or 6, planned a month ahead.
- Two days usually suit one product team. Four or six suit several teams, frequent design reviews or a steady flow of customer questionnaires.
- Minimum term of 3 months, then one month's notice.
What changes
- Security decisions get a senior review before they reach production, not after an incident.
- Customer security questionnaires are answered quickly and consistently, from evidence you can stand behind.
- Your policies match how your systems actually work, and stay current.
- Leadership sees one security roadmap with owners and dates, reviewed every quarter.
What you get
- Security roadmap, reviewed with leadership every quarter
- Design and change reviews with written findings
- Answers to customer security questionnaires, and a reusable answer library
- Security policies kept current as systems and requirements change
- Security reviews of new and critical suppliers
- Incident advice during business hours
- A monthly note of work done, decisions made and risks still open
A senior architect leads every engagement; vetted specialists join when the scope needs them, for example for hands-on fixes. The role gives security advice and reviews, not legal, audit or certification opinions.
Not included
- Legal advice, audits or certification, including ISO 27001 certification audits
- Incident advice outside business hours, 24/7 incident response or security monitoring
- Penetration testing (we can refer you to a certified partner)
- Hands-on build work beyond the agreed days (quoted as a separate package)
What we need from you
- A named sponsor, usually the CTO or head of engineering, and a 30-minute planning call each month.
- Read-only cloud access: SecurityAudit and ViewOnlyAccess on AWS, Reader and Security Reader on Azure, or Viewer and Security Reviewer on Google Cloud.
- Access to your ticket system and document space, and a channel where your team can ask questions.
- Your current policies, open questionnaires and supplier list at the start.
How it works
Free 30-minute call, then a written fixed quote for the monthly retainer.
In the first month, review your architecture, policies and open risks, and draft the roadmap.
Each month, agree priorities, work the agreed days and send a short note of what was done.
Every quarter, review the roadmap with leadership and adjust the days if needed.
At a glance
- Duration
- Monthly
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
Zero Trust assessment
In 1–2 weeks, a review of identity for people, devices and workloads, cloud guardrails and CI/CD, with every control checked as declared, refused and in effect, ending in a maturity rating per area and a roadmap.
Threat modelling workshop
A STRIDE threat model of one system or major feature, built with your team in two half-day sessions over one to two weeks, with a data-flow diagram, trust boundaries and prioritised mitigations in your backlog.
OS hardening baseline
Linux and Windows Server hardened to CIS Benchmarks Level 1 in two to six weeks, built as code with golden images, enforced settings, drift checks and compliance evidence for every host.