Package 01 · Executive Advisory Retainer

“You need a CISO’s judgment,
not a CISO’s salary.”

Your company outgrew having nobody in charge of security a while ago. It has not grown into a $400,000 executive with a staff. That gap is where this sits.

$7,000–$10,000 Per month · roughly 2 days a month Book the 30-minute diagnostic

What sets the price

  • Company size, and how many environments you actually run
  • How much board and customer exposure the role carries
  • Regulatory footprint — one jurisdiction or several
  • Whether there is an existing security team to work through, or none yet

Who this is for

A CEO or CTO carrying security on top of a job that was already full. The board has started asking questions in the meeting rather than after it. Enterprise customers are sending security questionnaires your team was never staffed to answer. The cyber-insurance renewal wants attestations nobody owns.

What's actually wrong

In most companies this size, security decisions are being made — they are just being made by whoever is in the room, usually a vendor with a quota. The result is a stack of tools nobody chose on purpose and no one who can tell the board what any of it means. The problem is not that you lack a security team. It is that you lack someone whose job is to say no.

What you get

  • A named security executive on retainer. One person, reachable, who knows your environment. Not a rotating bench and not a junior rep working off a script.
  • Board and audit-committee representation. Someone who has briefed at a $700B institution and can answer the follow-up question, not just deliver the slide.
  • Vendor and tool decisions made with you. Including the ones where the answer is that you do not need the thing you were about to buy.
  • Security-questionnaire and procurement support. The answers that unblock enterprise deals, written once and reused.
  • A defined escalation path. When something breaks, you already know who you call and what happens next.

How it runs

A standing monthly call with you, plus async access in between for the decisions that will not wait a month. Board and customer sessions as they come up. Roughly two days a month of real attention — strategy, architecture review, risk modelling, and the board conversation.

What this isn't

Not a SOC. Not managed detection. Not staff augmentation, and not someone watching your alerts at three in the morning. This is the judgment layer above your tooling — deciding what matters, what to do about it, and what to tell the people who are asking. If what you need is monitoring, say so on the call and you will get a straight answer about that instead.