Packages & pricing
Fixed price. Fixed scope. No hourly billing.
Every engagement is productised and priced upfront — because transparency is trust. Assess, Engineer and Advise, each priced so you see the number, the scope and the timeline before you commit a cent.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide
How we price
No timesheets. No open-ended hourly billing.
The way we charge is part of the work. You always know what you're paying and exactly what you're getting for it.
Fixed price for the agreed scope
You get the number before you commit. The scope is written down, and the price holds.
No hourly rates
We don't sell time, we sell outcomes. You never watch a meter or argue over a timesheet.
50% on booking
Standard project terms: 50% on commencement and 50% on delivery, unless alternative procurement or contractual terms are agreed in writing.
No open-ended hourly billing
One-off assessments and projects stand alone. Security Partnership tiers run on a 12-month initial term, then month-to-month with 30 days' written notice.
01 · Assess — find it
See where you stand
Fixed-scope assessments that tell you where you stand.
Cyber Risk Snapshot
From $4,500ex GST1 week
A fast, lightweight read on where you stand and what to do first.
- Lightweight risk + external attack-surface scan
- Executive summary one-pager
- Top-10 prioritised actions
Natural next step: Essential Eight Assessment, M365 Accelerator
- Best first step
Microsoft 365 Security Assessment
From $7,500ex GST1–2 weeks
An independent assessment of identity, access, Defender, Purview and relevant Microsoft 365 security controls.
- Current Microsoft Secure Score
- Identity, Conditional Access & MFA assessment
- Defender & Purview configuration review
- Risk-based interpretation of applicable recommendations
- Prioritised target-state hardening plan
- Indicative Secure Score improvement opportunity where supportable
Natural next step: Microsoft Hardening Sprint, MVM, Partnership
External Attack Surface Assessment
From $5,500ex GST1 week
See what an attacker sees facing your organisation from the internet.
- Discovery of your internet-facing footprint
- Exposure & misconfiguration findings
- Prioritised remediation shortlist
Natural next step: Penetration Test & Retest, MVM
Essential Eight Assessment
From $12,000ex GST2–3 weeks
Know your ML0–ML3 maturity and what it will take to lift it.
- ML0–ML3 maturity assessment (all eight strategies)
- A prioritised roadmap with indicative effort, dependencies and cost ranges where supportable
- Board pack + executive one-pager
- Technical findings for your IT team
Natural next step: Security Remediation Sprint, CIP
Copilot Security Readiness
From $7,500ex GST1 week
Roll out Microsoft Copilot without turning permission sprawl into a leak.
- Copilot / AI data-exposure & access review
- Oversharing remediation plan
- Acceptable-use policy
- Go/no-go rollout readiness summary
Natural next step: AI governance retainer, Partnership
AI Security & Governance Review
From $15,000ex GST2–3 weeks
Adopt AI across the business without leaking it — informed by relevant ISO/IEC 42001 principles.
- AI usage discovery (sanctioned + shadow AI)
- Data-exposure & access review
- AI security and governance review, informed by relevant ISO/IEC 42001 principles
- Governance framework + acceptable-use
Natural next step: AI governance retainer
Executive Security Review
From $8,000ex GST1–2 weeks
An executive-level posture review across people, process and technology.
- Posture review across people/process/tech
- Rated, owned risk register
- 12-month prioritised roadmap
- Executive summary the board can fund
Natural next step: Security Partnership
Cyber Insurance Readiness
From $6,500ex GST1 week
Answer your insurer's questionnaire with evidence that supports your renewal.
- Insurer-questionnaire gap analysis
- Evidence pack for renewal
- Prioritised remediation shortlist
Natural next step: Essential Eight uplift, CIP
Cloud Security Assessment
From $9,000ex GST1–2 weeks
An independent review of your Azure and/or AWS security posture — identity, configuration and exposure.
- Cloud configuration & identity review (Azure / AWS)
- Exposure & misconfiguration findings
- Alignment to cloud security good practice
- Prioritised remediation roadmap
Natural next step: Security Remediation Sprint, Partnership
Penetration Test & Retest
From $9,000ex GST2–3 weeks
Manual penetration testing with a clear report, a testing summary and retest-status letter, and one agreed retest.
- Scoped ext / int / web / API / AD test (agreed test type)
- Report with executive summary + testing summary and retest-status letter
- Prioritised remediation guidance
- One agreed retest included
Natural next step: Annual retest, MVM
02 · Engineer — fix it
We don't just find it — we fix it
Senior-led sprints that implement the agreed improvements and verify them.
- Best first step
Microsoft Security Hardening Sprint
From $12,000ex GST2–4 weeks
Implement and verify the priority Microsoft 365 security improvements — Entra ID, Defender, Intune, Zero Trust.
- Entra ID / Conditional Access / PIM hardening
- Defender deployment & tuning
- Intune device hardening
- Zero Trust controls + verification re-test
Natural next step: Security Partnership, MVM
Security Remediation Sprint
From $8,000ex GST2–4 weeks
Senior-led remediation of the priority findings from any assessment.
- Fixed-scope remediation of priority findings
- Senior-led implementation (no junior hours)
- Change documentation
- Verification re-test of the work
Natural next step: Security Partnership, managed
03 · Advise — sustain it
Keep the gains compounding
Recurring leadership and assurance that keeps the gains compounding.
CyberByte Security Partnership
From $2,500/mo · tiered · ex GSTTiered senior leadership — Essentials, Core and Premium.
- Quarterly roadmap & board reporting
- Vendor & Microsoft posture reviews
- Risk register & incident planning
- Tender assistance & annual testing (higher tiers)
Managed Vulnerability Management
From $1,500/mo · ex GSTRecurring automated scanning with prioritised, human-triaged guidance. Priced by assets, not users.
- Recurring automated external and internal vulnerability scanning, subject to the agreed asset scope and scan schedule
- Monthly prioritised report
- Remediation guidance (a human in the loop)
- Risk-reduction trend line
Scoping
How we land on your price
The prices above are the starting point for a typical small organisation. Your number reflects the size and complexity of your environment — never an hourly rate. Here's exactly how we get there.
- Step 01
A 20-minute scoping call
A few quick questions: how many staff and sites, one Microsoft tenant or several, and — for testing — how many hosts or apps.
- Step 02
Sized to your environment
We scope to what we'll actually secure — users for Microsoft work, assets for scanning, attack surface for a test. Bigger or more complex means more scope.
- Step 03
One fixed price, in writing
A single number with a defined scope — priced on the outcome it delivers, never an open-ended hourly meter that creeps.
- Step 04
50% secures your start
A deposit books your slot; the balance is due on delivery. No unapproved variations — scope, price and timing changes are documented and approved before additional work begins.
Same rate, sized to you. Whether you're 30 staff or 300, a larger engagement reflects more scope — more users, sites or systems to secure — not a higher hourly rate. And once it's agreed, the price for that scope holds.
Bundles
Go further for less — the whole arc, one fixed price.
When you already know you need more than one engagement, a bundle fixes the price across the lot — including the signature Assess → Engineer → Advise path.
Secure Foundations
From ~$21,000 ex GST
Cyber Risk Snapshot + Microsoft 365 Security Assessment + Essential Eight Assessment — around $24,000 separately, approximately $21,000 bundled, subject to confirmed scope.
Assess → Engineer → Advise
From $20,000 ex GST + Partnership
Assessment and remediation from $20,000 ex GST, plus the selected Security Partnership tier under a 12-month initial agreement. Find it, fix it, keep it secure.
Microsoft Secure
From $25,000 ex GST
M365 Security Assessment + Microsoft Hardening Sprint + Copilot Readiness — around $27,000 separately, from $25,000 bundled, subject to confirmed scope.
FAQ
The pricing questions buyers ask
If something isn't covered here, a scoping call answers it in 20 minutes.
Standard SME project terms are 50% on commencement and 50% on delivery. Enterprise, government and approved partner engagements may follow agreed purchase-order and procurement terms. Security Partnership tiers run on a 12-month initial agreement, and Managed Vulnerability Management on a 6-month initial agreement — both billed monthly in advance, then month-to-month with 30 days' written notice. No hourly rates, no unapproved variations.
Microsoft 365 Security Assessment assumes one tenant, an agreed user range and Microsoft workloads and licences, a read-only review (implementation scoped separately), defined stakeholder interviews, and a report and briefing. Essential Eight Assessment assumes the system boundary is agreed before commencement, that evidence availability affects scope and timing, assessment against the current ASD model, and uplift implementation excluded unless separately scoped. Penetration Test & Retest assumes the test type and asset count are defined during scoping, one agreed retest, and that complex applications, APIs, internal networks and Active Directory may require a higher quote.
Assess finds what's exposed (fixed-scope assessments). Engineer fixes it (senior-led remediation sprints). Advise keeps it secure (the recurring Security Partnership). A common starting point is a focused assessment, followed where required by remediation and ongoing advisory. We'll recommend the smallest credible first step for your situation.
Yes. The productised packages cover the most common shapes, but scope flexes to your environment. A 20-minute scoping call confirms the fit and, if needed, we'll quote a tailored fixed price before you commit.
They're the starting point for a typical small organisation. Your number depends on the size and complexity of your environment — more users, sites, tenants or systems mean more scope, so a larger organisation pays more for more work. It's never a different hourly rate, and we confirm the exact fixed price after a short scoping call, before you commit.
All prices are quoted ex GST. GST is added on invoice as required for an Australian Pty Ltd. You'll see the full inclusive figure before you pay anything.
Request a scoping call
Talk to a senior advisor — not a salesperson.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide