Packages & pricing
Fixed price. Fixed scope. No hourly billing.
Every engagement is productised and priced upfront — because transparency is trust. Assess, Engineer and Advise, each priced so you see the number, the scope and the timeline before you commit a cent.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide
How we price
No timesheets. No open-ended hourly billing.
The way we charge is part of the work. You always know what you're paying and exactly what you're getting for it.
Fixed price for the agreed scope
You get the number before you commit. The scope is written down, and the price holds.
No hourly rates
We don't sell time, we sell outcomes. You never watch a meter or argue over a timesheet.
50% on booking
Standard project terms: 50% on commencement and 50% on delivery, unless alternative procurement or contractual terms are agreed in writing.
No open-ended hourly billing
One-off assessments and projects stand alone. Security Partnership tiers run on a 12-month initial term, then month-to-month with 30 days' written notice.
01 · Assess — find it
Find exactly where you stand
Fixed-scope assessments that tell you exactly where you stand.
Cyber Risk Snapshot
$4,500ex GST1 week
A fast, lightweight read on where you stand and what to do first.
- Lightweight risk + external attack-surface scan
- Executive risk one-pager
- Top-10 prioritised actions
Natural next step: Essential Eight Fast Track, M365 Accelerator
- Best first step
Microsoft 365 Security Assessment
$7,500ex GST1–2 weeks
An independent assessment of identity, access, Defender, Purview and relevant Microsoft 365 security controls.
- Current Microsoft Secure Score
- Identity, Conditional Access & MFA assessment
- Defender & Purview configuration review
- Risk-based interpretation of applicable recommendations
- Prioritised target-state hardening plan
- Indicative Secure Score improvement opportunity where supportable
Natural next step: Microsoft Hardening Sprint, MVM, Partnership
External Attack Surface Assessment
From $5,500ex GST1 week
See exactly what an attacker sees facing your organisation from the internet.
- Discovery of your internet-facing footprint
- Exposure & misconfiguration findings
- Prioritised remediation shortlist
Natural next step: Penetration Test, MVM
Essential Eight Fast Track
$12,000ex GST2–3 weeks
Know your ML1–ML3 maturity and exactly what it costs to lift it.
- ML1–ML3 maturity assessment (all eight strategies)
- Costed, prioritised uplift roadmap
- Board pack + executive one-pager
- Technical findings for your IT team
Natural next step: Security Remediation Sprint, CIP
Copilot Security Readiness
$7,500ex GST1 week
Roll out Microsoft Copilot without turning permission sprawl into a leak.
- Copilot / AI data-exposure & access review
- Oversharing remediation plan
- Acceptable-use policy
- Go/no-go rollout readiness summary
Natural next step: AI governance retainer, Partnership
AI Security Readiness
$15,000ex GST2–3 weeks
Adopt AI across the business without leaking it — ISO 42001 aligned.
- AI usage discovery (sanctioned + shadow AI)
- Data-exposure & access review
- AI governance review (ISO/IEC 42001-aligned)
- Governance framework + acceptable-use
Natural next step: AI governance retainer
Executive Security Review
$8,000ex GST1–2 weeks
A board-level posture review across people, process and technology.
- Posture review across people/process/tech
- Rated, owned risk register
- 12-month prioritised roadmap
- Executive summary the board can fund
Natural next step: Security Partnership
Cyber Insurance Readiness
$6,500ex GST1 week
Answer your insurer's questionnaire with evidence that supports your renewal.
- Insurer-questionnaire gap analysis
- Evidence pack for renewal
- Prioritised remediation shortlist
Natural next step: Essential Eight uplift, CIP
Penetration Test (Assured)
From $9,000ex GST2–3 weeks
Manual penetration testing with a board-ready report, completion statement and a retest.
- Scoped ext / int / web / API / AD test
- Board-ready report + completion statement
- Prioritised remediation guidance
- One retest included
Natural next step: Annual retest, MVM
02 · Engineer — fix it
We don't just find it — we fix it
Senior-led sprints that implement the fixes and verify them.
- Best first step
Microsoft Security Hardening Sprint
From $12,000ex GST2–4 weeks
Implement and verify the priority Microsoft 365 security improvements — Entra ID, Defender, Intune, Zero Trust.
- Entra ID / Conditional Access / PIM hardening
- Defender deployment & tuning
- Intune device hardening
- Zero Trust controls + verification re-test
Natural next step: Security Partnership, MVM
Security Remediation Sprint
From $8,000ex GST2–4 weeks
Senior-led fix of the priority findings from any assessment.
- Fixed-scope remediation of priority findings
- Senior-led implementation (no junior hours)
- Change documentation
- Verification re-test of the work
Natural next step: Security Partnership, managed
03 · Advise — sustain it
Keep the gains compounding
Recurring leadership and assurance that keeps the gains compounding.
CyberByte Security Partnership
From $2,500/mo · tieredTiered senior leadership — Essentials, Core and Premium.
- Quarterly roadmap & board reporting
- Vendor & Microsoft posture reviews
- Risk register & incident planning
- Tender assistance & annual testing (higher tiers)
Managed Vulnerability Management
From $1,500/moRecurring automated scanning with prioritised, human-triaged guidance. Priced by assets, not users.
- Recurring automated external and internal vulnerability scanning, subject to the agreed asset scope and scan schedule
- Monthly prioritised report
- Remediation guidance (a human in the loop)
- Risk-reduction trend line
Scoping
How we land on your price
The prices above are the starting point for a typical small organisation. Your number reflects the size and complexity of your environment — never an hourly rate. Here's exactly how we get there.
- Step 01
A 20-minute scoping call
A few quick questions: how many staff and sites, one Microsoft tenant or several, and — for testing — how many hosts or apps.
- Step 02
Sized to your environment
We scope to what we'll actually secure — users for Microsoft work, assets for scanning, attack surface for a test. Bigger or more complex means more scope.
- Step 03
One fixed price, in writing
A single number with a defined scope — priced on the outcome it delivers, never an open-ended hourly meter that creeps.
- Step 04
50% secures your start
A deposit books your slot; the balance is due on delivery. No unapproved variations — scope, price and timing changes are documented and approved before additional work begins.
Same rate, sized to you. Whether you're 30 staff or 300, a larger engagement reflects more scope — more users, sites or systems to secure — not a higher hourly rate. And once it's agreed, the price for that scope holds.
Bundles
Go further for less — the whole arc, one fixed price.
When you already know you need more than one engagement, a bundle fixes the price across the lot — including the signature Assess → Engineer → Advise path.
Secure Foundations
~$21,000
Cyber Risk Snapshot + Microsoft 365 Security Assessment + Essential Eight Fast Track — the flagship way to start.
Assess → Engineer → Advise
From $20,000 ex GST + Partnership
Assessment and remediation from $20,000 ex GST, plus the selected Security Partnership tier under a 12-month initial agreement. Find it, fix it, keep it secure.
Microsoft Secure
From $25,000
M365 Security Assessment + Microsoft Hardening Sprint + Copilot Readiness — the complete Microsoft environment, hardened.
FAQ
The pricing questions buyers ask
If something isn't covered here, a scoping call answers it in 20 minutes.
Every one-off package is fixed price: 50% on commencement, 50% on delivery, unless alternative procurement terms are agreed in writing. Security Partnership tiers run on a 12-month initial agreement, and Managed Vulnerability Management on a 6-month initial agreement — both billed monthly in advance, then month-to-month with 30 days' written notice. No hourly rates, no unapproved variations.
Assess finds what's exposed (fixed-scope assessments). Engineer fixes it (senior-led remediation sprints). Advise keeps it secure (the recurring Security Partnership). Most clients start with an assessment and follow the arc — and we'll always recommend the smallest credible first step.
Yes. The productised packages cover the most common shapes, but scope flexes to your environment. A 20-minute scoping call confirms the fit and, if needed, we'll quote a tailored fixed price before you commit.
They're the starting point for a typical small organisation. Your number depends on the size and complexity of your environment — more users, sites, tenants or systems mean more scope, so a larger organisation pays more for more work. It's never a different hourly rate, and we confirm the exact fixed price after a short scoping call, before you commit.
All prices are quoted ex GST. GST is added on invoice as required for an Australian Pty Ltd. You'll see the full inclusive figure before you pay anything.
Request a scoping call
Talk to a senior advisor — not a salesperson.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide