Skip to content
CyberByteSecurity

Packages & pricing

Fixed price. Fixed scope. No hourly billing.

Every engagement is productised and priced upfront — because transparency is trust. Assess, Engineer and Advise, each priced so you see the number, the scope and the timeline before you commit a cent.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide

How we price

No timesheets. No open-ended hourly billing.

The way we charge is part of the work. You always know what you're paying and exactly what you're getting for it.

  • Fixed price for the agreed scope

    You get the number before you commit. The scope is written down, and the price holds.

  • No hourly rates

    We don't sell time, we sell outcomes. You never watch a meter or argue over a timesheet.

  • 50% on booking

    Standard project terms: 50% on commencement and 50% on delivery, unless alternative procurement or contractual terms are agreed in writing.

  • No open-ended hourly billing

    One-off assessments and projects stand alone. Security Partnership tiers run on a 12-month initial term, then month-to-month with 30 days' written notice.

01 · Assess — find it

Find exactly where you stand

Fixed-scope assessments that tell you exactly where you stand.

  • Cyber Risk Snapshot

    $4,500ex GST

    1 week

    A fast, lightweight read on where you stand and what to do first.

    • Lightweight risk + external attack-surface scan
    • Executive risk one-pager
    • Top-10 prioritised actions

    Natural next step: Essential Eight Fast Track, M365 Accelerator

  • Best first step

    Microsoft 365 Security Assessment

    $7,500ex GST

    1–2 weeks

    An independent assessment of identity, access, Defender, Purview and relevant Microsoft 365 security controls.

    • Current Microsoft Secure Score
    • Identity, Conditional Access & MFA assessment
    • Defender & Purview configuration review
    • Risk-based interpretation of applicable recommendations
    • Prioritised target-state hardening plan
    • Indicative Secure Score improvement opportunity where supportable

    Natural next step: Microsoft Hardening Sprint, MVM, Partnership

  • External Attack Surface Assessment

    From $5,500ex GST

    1 week

    See exactly what an attacker sees facing your organisation from the internet.

    • Discovery of your internet-facing footprint
    • Exposure & misconfiguration findings
    • Prioritised remediation shortlist

    Natural next step: Penetration Test, MVM

  • Essential Eight Fast Track

    $12,000ex GST

    2–3 weeks

    Know your ML1–ML3 maturity and exactly what it costs to lift it.

    • ML1–ML3 maturity assessment (all eight strategies)
    • Costed, prioritised uplift roadmap
    • Board pack + executive one-pager
    • Technical findings for your IT team

    Natural next step: Security Remediation Sprint, CIP

  • Copilot Security Readiness

    $7,500ex GST

    1 week

    Roll out Microsoft Copilot without turning permission sprawl into a leak.

    • Copilot / AI data-exposure & access review
    • Oversharing remediation plan
    • Acceptable-use policy
    • Go/no-go rollout readiness summary

    Natural next step: AI governance retainer, Partnership

  • AI Security Readiness

    $15,000ex GST

    2–3 weeks

    Adopt AI across the business without leaking it — ISO 42001 aligned.

    • AI usage discovery (sanctioned + shadow AI)
    • Data-exposure & access review
    • AI governance review (ISO/IEC 42001-aligned)
    • Governance framework + acceptable-use

    Natural next step: AI governance retainer

  • Executive Security Review

    $8,000ex GST

    1–2 weeks

    A board-level posture review across people, process and technology.

    • Posture review across people/process/tech
    • Rated, owned risk register
    • 12-month prioritised roadmap
    • Executive summary the board can fund

    Natural next step: Security Partnership

  • Cyber Insurance Readiness

    $6,500ex GST

    1 week

    Answer your insurer's questionnaire with evidence that supports your renewal.

    • Insurer-questionnaire gap analysis
    • Evidence pack for renewal
    • Prioritised remediation shortlist

    Natural next step: Essential Eight uplift, CIP

  • Penetration Test (Assured)

    From $9,000ex GST

    2–3 weeks

    Manual penetration testing with a board-ready report, completion statement and a retest.

    • Scoped ext / int / web / API / AD test
    • Board-ready report + completion statement
    • Prioritised remediation guidance
    • One retest included

    Natural next step: Annual retest, MVM

02 · Engineer — fix it

We don't just find it — we fix it

Senior-led sprints that implement the fixes and verify them.

  • Best first step

    Microsoft Security Hardening Sprint

    From $12,000ex GST

    2–4 weeks

    Implement and verify the priority Microsoft 365 security improvements — Entra ID, Defender, Intune, Zero Trust.

    • Entra ID / Conditional Access / PIM hardening
    • Defender deployment & tuning
    • Intune device hardening
    • Zero Trust controls + verification re-test

    Natural next step: Security Partnership, MVM

  • Security Remediation Sprint

    From $8,000ex GST

    2–4 weeks

    Senior-led fix of the priority findings from any assessment.

    • Fixed-scope remediation of priority findings
    • Senior-led implementation (no junior hours)
    • Change documentation
    • Verification re-test of the work

    Natural next step: Security Partnership, managed

03 · Advise — sustain it

Keep the gains compounding

Recurring leadership and assurance that keeps the gains compounding.

  • CyberByte Security Partnership

    From $2,500/mo · tiered

    Tiered senior leadership — Essentials, Core and Premium.

    • Quarterly roadmap & board reporting
    • Vendor & Microsoft posture reviews
    • Risk register & incident planning
    • Tender assistance & annual testing (higher tiers)
  • Managed Vulnerability Management

    From $1,500/mo

    Recurring automated scanning with prioritised, human-triaged guidance. Priced by assets, not users.

    • Recurring automated external and internal vulnerability scanning, subject to the agreed asset scope and scan schedule
    • Monthly prioritised report
    • Remediation guidance (a human in the loop)
    • Risk-reduction trend line

Scoping

How we land on your price

The prices above are the starting point for a typical small organisation. Your number reflects the size and complexity of your environment — never an hourly rate. Here's exactly how we get there.

  1. Step 01

    A 20-minute scoping call

    A few quick questions: how many staff and sites, one Microsoft tenant or several, and — for testing — how many hosts or apps.

  2. Step 02

    Sized to your environment

    We scope to what we'll actually secure — users for Microsoft work, assets for scanning, attack surface for a test. Bigger or more complex means more scope.

  3. Step 03

    One fixed price, in writing

    A single number with a defined scope — priced on the outcome it delivers, never an open-ended hourly meter that creeps.

  4. Step 04

    50% secures your start

    A deposit books your slot; the balance is due on delivery. No unapproved variations — scope, price and timing changes are documented and approved before additional work begins.

Same rate, sized to you. Whether you're 30 staff or 300, a larger engagement reflects more scope — more users, sites or systems to secure — not a higher hourly rate. And once it's agreed, the price for that scope holds.

Bundles

Go further for less — the whole arc, one fixed price.

When you already know you need more than one engagement, a bundle fixes the price across the lot — including the signature Assess → Engineer → Advise path.

Land

Secure Foundations

~$21,000

Cyber Risk Snapshot + Microsoft 365 Security Assessment + Essential Eight Fast Track — the flagship way to start.

Signature

Assess → Engineer → Advise

From $20,000 ex GST + Partnership

Assessment and remediation from $20,000 ex GST, plus the selected Security Partnership tier under a 12-month initial agreement. Find it, fix it, keep it secure.

Microsoft-heavy

Microsoft Secure

From $25,000

M365 Security Assessment + Microsoft Hardening Sprint + Copilot Readiness — the complete Microsoft environment, hardened.

FAQ

The pricing questions buyers ask

If something isn't covered here, a scoping call answers it in 20 minutes.

Every one-off package is fixed price: 50% on commencement, 50% on delivery, unless alternative procurement terms are agreed in writing. Security Partnership tiers run on a 12-month initial agreement, and Managed Vulnerability Management on a 6-month initial agreement — both billed monthly in advance, then month-to-month with 30 days' written notice. No hourly rates, no unapproved variations.

Assess finds what's exposed (fixed-scope assessments). Engineer fixes it (senior-led remediation sprints). Advise keeps it secure (the recurring Security Partnership). Most clients start with an assessment and follow the arc — and we'll always recommend the smallest credible first step.

Yes. The productised packages cover the most common shapes, but scope flexes to your environment. A 20-minute scoping call confirms the fit and, if needed, we'll quote a tailored fixed price before you commit.

They're the starting point for a typical small organisation. Your number depends on the size and complexity of your environment — more users, sites, tenants or systems mean more scope, so a larger organisation pays more for more work. It's never a different hourly rate, and we confirm the exact fixed price after a short scoping call, before you commit.

All prices are quoted ex GST. GST is added on invoice as required for an Australian Pty Ltd. You'll see the full inclusive figure before you pay anything.

Request a scoping call

Talk to a senior advisor — not a salesperson.

A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide