Security That Fits Your Budget, Not Ours.
We believe pricing should be transparent. Every retainer is a fixed monthly commitment, so you always know what you are paying and exactly what you are getting for it. No surprise invoices at the end of a project.
Individual Service Retainers
vCISO
Strategic security leadership on a flexible retainer. Your Virtual CISO attends key leadership meetings, manages your risk register, oversees compliance, and reports to your board.
- Security strategy and annual roadmap
- Risk register management and quarterly review
- Policy framework design and maintenance
- Monthly leadership sync and board reporting
- Up to 20 hours of active engagement per month
vDPO
Full Data Protection Officer function on retainer. We manage your compliance programme across PDPL, UAE FDPL, and related frameworks, and serve as your regulatory contact point.
- Initial data mapping and gap analysis
- Privacy notice design and review
- Data subject rights procedure and management
- Breach notification procedure and support
- Up to 16 hours of active engagement per month
VMaaS
Continuous vulnerability scanning, prioritisation, and verified remediation. We identify what is exposed, tell you what matters most, and confirm it is actually fixed.
- Continuous external attack surface scanning
- Internal network and endpoint scanning
- Risk-based prioritisation with threat intel
- Verified remediation before closure
- Monthly executive and technical report
Combined Service Packages
Most businesses benefit from combining two or more services. When you bundle, the services work together more effectively and your overall investment is lower than subscribing to each individually.
Compliance Ready
Strategic security leadership combined with full data protection compliance management. Designed for businesses facing SAMA, PDPL, UAE FDPL, or ISO 27001 requirements that need governance and privacy management running in parallel.
Security Operations
Strategic security leadership with continuous technical monitoring. Your vCISO sets direction and makes risk decisions, while VMaaS provides the ongoing technical visibility to keep vulnerability exposure genuinely under control.
Full Defence Programme
The complete Code Defence programme. Strategic leadership, regulatory compliance, and continuous technical monitoring working together as a single integrated security programme.
Audit Readiness Sprint
A structured ninety-day programme for businesses facing an upcoming regulatory audit with limited preparation time. We run a full gap assessment, close critical gaps, and brief your team. Covers SAMA, NCA, ISO 27001, and PDPL examinations.
What Each Service Covers
Not sure which services your business needs? This table maps core deliverables to the services that include them.
| Deliverable | vCISO | vDPO | VMaaS |
|---|---|---|---|
| Security strategy and roadmap | ✓ | — | — |
| Risk register management | ✓ | Data risks | — |
| Board and executive reporting | ✓ | On request | ✓ |
| PDPL / UAE FDPL compliance | Oversight | ✓ | — |
| Data mapping and ROPA | — | ✓ | — |
| Continuous vulnerability scanning | — | — | ✓ |
| Verified remediation tracking | — | — | ✓ |
| SAMA and NCA audit support | ✓ | Data domains | Tech evidence |
| ISO 27001 preparation | ✓ | Privacy controls | Vuln controls |
Pricing Questions Answered
These are genuine starting prices for businesses at the smaller end of the range we serve. Your actual investment depends on employee count, environment complexity, and how many regulatory frameworks apply. The free consultation gives you a specific, transparent proposal before you commit to anything. We do not use low starting prices to attract interest and then inflate the final number.
Our standard retainers run on a three-month minimum with monthly billing thereafter. We ask for three months because meaningful security work requires time to assess, build, and verify. After that, retainers continue monthly and can be adjusted or ended with thirty days notice.
Each retainer includes a defined number of active engagement hours per month. If a particular month requires significantly more, such as during an audit or a significant incident, we discuss and scope that separately with you rather than silently absorbing or overbilling it.
Get a Proposal Scoped to Your Business
The first conversation is free, it is genuinely useful, and there is no obligation attached to it.
