Skip to content
CyberByteSecurity

Packages & pricing

Fixed price. Fixed scope. No hourly billing.

Every engagement is productised and priced upfront — because transparency is trust. Assess, Engineer and Advise, each priced so you see the number, the scope and the timeline before you commit a cent.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide

How we price

No timesheets. No open-ended hourly billing.

The way we charge is part of the work. You always know what you're paying and exactly what you're getting for it.

  • Fixed price for the agreed scope

    You get the number before you commit. The scope is written down, and the price holds.

  • No hourly rates

    We don't sell time, we sell outcomes. You never watch a meter or argue over a timesheet.

  • 50% on booking

    Standard project terms: 50% on commencement and 50% on delivery, unless alternative procurement or contractual terms are agreed in writing.

  • No open-ended hourly billing

    One-off assessments and projects stand alone. Security Partnership tiers run on a 12-month initial term, then month-to-month with 30 days' written notice.

01 · Assess — find it

See where you stand

Fixed-scope assessments that tell you where you stand.

  • Cyber Risk Snapshot

    From $4,500ex GST

    1 week

    A fast, lightweight read on where you stand and what to do first.

    • Lightweight risk + external attack-surface scan
    • Executive summary one-pager
    • Top-10 prioritised actions

    Natural next step: Essential Eight Assessment, M365 Accelerator

  • Best first step

    Microsoft 365 Security Assessment

    From $7,500ex GST

    1–2 weeks

    An independent assessment of identity, access, Defender, Purview and relevant Microsoft 365 security controls.

    • Current Microsoft Secure Score
    • Identity, Conditional Access & MFA assessment
    • Defender & Purview configuration review
    • Risk-based interpretation of applicable recommendations
    • Prioritised target-state hardening plan
    • Indicative Secure Score improvement opportunity where supportable

    Natural next step: Microsoft Hardening Sprint, MVM, Partnership

  • External Attack Surface Assessment

    From $5,500ex GST

    1 week

    See what an attacker sees facing your organisation from the internet.

    • Discovery of your internet-facing footprint
    • Exposure & misconfiguration findings
    • Prioritised remediation shortlist

    Natural next step: Penetration Test & Retest, MVM

  • Essential Eight Assessment

    From $12,000ex GST

    2–3 weeks

    Know your ML0–ML3 maturity and what it will take to lift it.

    • ML0–ML3 maturity assessment (all eight strategies)
    • A prioritised roadmap with indicative effort, dependencies and cost ranges where supportable
    • Board pack + executive one-pager
    • Technical findings for your IT team

    Natural next step: Security Remediation Sprint, CIP

  • Copilot Security Readiness

    From $7,500ex GST

    1 week

    Roll out Microsoft Copilot without turning permission sprawl into a leak.

    • Copilot / AI data-exposure & access review
    • Oversharing remediation plan
    • Acceptable-use policy
    • Go/no-go rollout readiness summary

    Natural next step: AI governance retainer, Partnership

  • AI Security & Governance Review

    From $15,000ex GST

    2–3 weeks

    Adopt AI across the business without leaking it — informed by relevant ISO/IEC 42001 principles.

    • AI usage discovery (sanctioned + shadow AI)
    • Data-exposure & access review
    • AI security and governance review, informed by relevant ISO/IEC 42001 principles
    • Governance framework + acceptable-use

    Natural next step: AI governance retainer

  • Executive Security Review

    From $8,000ex GST

    1–2 weeks

    An executive-level posture review across people, process and technology.

    • Posture review across people/process/tech
    • Rated, owned risk register
    • 12-month prioritised roadmap
    • Executive summary the board can fund

    Natural next step: Security Partnership

  • Cyber Insurance Readiness

    From $6,500ex GST

    1 week

    Answer your insurer's questionnaire with evidence that supports your renewal.

    • Insurer-questionnaire gap analysis
    • Evidence pack for renewal
    • Prioritised remediation shortlist

    Natural next step: Essential Eight uplift, CIP

  • Cloud Security Assessment

    From $9,000ex GST

    1–2 weeks

    An independent review of your Azure and/or AWS security posture — identity, configuration and exposure.

    • Cloud configuration & identity review (Azure / AWS)
    • Exposure & misconfiguration findings
    • Alignment to cloud security good practice
    • Prioritised remediation roadmap

    Natural next step: Security Remediation Sprint, Partnership

  • Penetration Test & Retest

    From $9,000ex GST

    2–3 weeks

    Manual penetration testing with a clear report, a testing summary and retest-status letter, and one agreed retest.

    • Scoped ext / int / web / API / AD test (agreed test type)
    • Report with executive summary + testing summary and retest-status letter
    • Prioritised remediation guidance
    • One agreed retest included

    Natural next step: Annual retest, MVM

02 · Engineer — fix it

We don't just find it — we fix it

Senior-led sprints that implement the agreed improvements and verify them.

  • Best first step

    Microsoft Security Hardening Sprint

    From $12,000ex GST

    2–4 weeks

    Implement and verify the priority Microsoft 365 security improvements — Entra ID, Defender, Intune, Zero Trust.

    • Entra ID / Conditional Access / PIM hardening
    • Defender deployment & tuning
    • Intune device hardening
    • Zero Trust controls + verification re-test

    Natural next step: Security Partnership, MVM

  • Security Remediation Sprint

    From $8,000ex GST

    2–4 weeks

    Senior-led remediation of the priority findings from any assessment.

    • Fixed-scope remediation of priority findings
    • Senior-led implementation (no junior hours)
    • Change documentation
    • Verification re-test of the work

    Natural next step: Security Partnership, managed

03 · Advise — sustain it

Keep the gains compounding

Recurring leadership and assurance that keeps the gains compounding.

  • CyberByte Security Partnership

    From $2,500/mo · tiered · ex GST

    Tiered senior leadership — Essentials, Core and Premium.

    • Quarterly roadmap & board reporting
    • Vendor & Microsoft posture reviews
    • Risk register & incident planning
    • Tender assistance & annual testing (higher tiers)
  • Managed Vulnerability Management

    From $1,500/mo · ex GST

    Recurring automated scanning with prioritised, human-triaged guidance. Priced by assets, not users.

    • Recurring automated external and internal vulnerability scanning, subject to the agreed asset scope and scan schedule
    • Monthly prioritised report
    • Remediation guidance (a human in the loop)
    • Risk-reduction trend line

Scoping

How we land on your price

The prices above are the starting point for a typical small organisation. Your number reflects the size and complexity of your environment — never an hourly rate. Here's exactly how we get there.

  1. Step 01

    A 20-minute scoping call

    A few quick questions: how many staff and sites, one Microsoft tenant or several, and — for testing — how many hosts or apps.

  2. Step 02

    Sized to your environment

    We scope to what we'll actually secure — users for Microsoft work, assets for scanning, attack surface for a test. Bigger or more complex means more scope.

  3. Step 03

    One fixed price, in writing

    A single number with a defined scope — priced on the outcome it delivers, never an open-ended hourly meter that creeps.

  4. Step 04

    50% secures your start

    A deposit books your slot; the balance is due on delivery. No unapproved variations — scope, price and timing changes are documented and approved before additional work begins.

Same rate, sized to you. Whether you're 30 staff or 300, a larger engagement reflects more scope — more users, sites or systems to secure — not a higher hourly rate. And once it's agreed, the price for that scope holds.

Bundles

Go further for less — the whole arc, one fixed price.

When you already know you need more than one engagement, a bundle fixes the price across the lot — including the signature Assess → Engineer → Advise path.

Land

Secure Foundations

From ~$21,000 ex GST

Cyber Risk Snapshot + Microsoft 365 Security Assessment + Essential Eight Assessment — around $24,000 separately, approximately $21,000 bundled, subject to confirmed scope.

Signature

Assess → Engineer → Advise

From $20,000 ex GST + Partnership

Assessment and remediation from $20,000 ex GST, plus the selected Security Partnership tier under a 12-month initial agreement. Find it, fix it, keep it secure.

Microsoft-heavy

Microsoft Secure

From $25,000 ex GST

M365 Security Assessment + Microsoft Hardening Sprint + Copilot Readiness — around $27,000 separately, from $25,000 bundled, subject to confirmed scope.

FAQ

The pricing questions buyers ask

If something isn't covered here, a scoping call answers it in 20 minutes.

Standard SME project terms are 50% on commencement and 50% on delivery. Enterprise, government and approved partner engagements may follow agreed purchase-order and procurement terms. Security Partnership tiers run on a 12-month initial agreement, and Managed Vulnerability Management on a 6-month initial agreement — both billed monthly in advance, then month-to-month with 30 days' written notice. No hourly rates, no unapproved variations.

Microsoft 365 Security Assessment assumes one tenant, an agreed user range and Microsoft workloads and licences, a read-only review (implementation scoped separately), defined stakeholder interviews, and a report and briefing. Essential Eight Assessment assumes the system boundary is agreed before commencement, that evidence availability affects scope and timing, assessment against the current ASD model, and uplift implementation excluded unless separately scoped. Penetration Test & Retest assumes the test type and asset count are defined during scoping, one agreed retest, and that complex applications, APIs, internal networks and Active Directory may require a higher quote.

Assess finds what's exposed (fixed-scope assessments). Engineer fixes it (senior-led remediation sprints). Advise keeps it secure (the recurring Security Partnership). A common starting point is a focused assessment, followed where required by remediation and ongoing advisory. We'll recommend the smallest credible first step for your situation.

Yes. The productised packages cover the most common shapes, but scope flexes to your environment. A 20-minute scoping call confirms the fit and, if needed, we'll quote a tailored fixed price before you commit.

They're the starting point for a typical small organisation. Your number depends on the size and complexity of your environment — more users, sites, tenants or systems mean more scope, so a larger organisation pays more for more work. It's never a different hourly rate, and we confirm the exact fixed price after a short scoping call, before you commit.

All prices are quoted ex GST. GST is added on invoice as required for an Australian Pty Ltd. You'll see the full inclusive figure before you pay anything.

Request a scoping call

Talk to a senior advisor — not a salesperson.

A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide