Everything I deliver is scoped precisely, documented clearly, and explained in terms your leadership can act on.

All engagements include a kickoff call, scoped testing window, written report (technical + executive summary), and a 30-minute debrief call. Pricing reflects scope and environment complexity — contact me for a specific quote.

HIPAA Security Risk Analysis

Formal HIPAA-required Security Risk Analysis (SRA) for covered entities and business associates. Identifies ePHI assets, threat/vulnerability pairs, and likelihood/impact ratings per HHS guidance. Delivers a written, audit-ready SRA report.

Includes

  • ePHI asset identification
  • Threat + vulnerability pair analysis
  • Likelihood + impact ratings
  • HHS-compliant written SRA report
  • Debrief call

Ideal For

Healthcare covered entities (medical practices, dental offices, clinics) and business associates who need a documented, defensible SRA that satisfies HHS OCR requirements.

Price Range

$1,500 – $3,500

Typical Duration

3–4 days

Get a Quote

NIST RMF Security Controls Assessment

Assessment support for organizations adopting the NIST Risk Management Framework — system characterization, control gap analysis against NIST SP 800-53, and a written findings report with a prioritized remediation roadmap.

Includes

  • System characterization
  • Control gap analysis (SP 800-53)
  • Risk rating per control family
  • Written findings report
  • Prioritized remediation roadmap

Ideal For

Healthcare organizations, financial services firms, and compliance-driven businesses that want a structured, NIST-aligned approach to evaluating and improving their security controls.

Price Range

$2,500 – $6,000

Typical Duration

1–2 weeks

Get a Quote

Vulnerability Assessment

Automated and manual scanning with expert analysis — no active exploitation. Produces a prioritized, CVSS-scored remediation roadmap. The right entry point for first-time clients and compliance pre-checks.

Includes

  • Automated + manual scanning
  • CVSS-scored findings
  • Prioritized remediation roadmap
  • Executive summary
  • 30-minute debrief call

Ideal For

Organizations new to security assessments, those under time or budget constraints, or companies preparing for a full penetration test.

Price Range

$500 – $1,500

Typical Duration

1–2 days

Get a Quote

Phishing Simulation

Simulated phishing campaign targeting employees. Measures click rates and credential submission, then provides awareness training guidance. Includes an executive summary your leadership can act on.

Includes

  • Custom phishing templates
  • Click + credential capture metrics
  • Awareness training guidance
  • Executive summary
  • Debrief call

Ideal For

Organizations looking to measure and improve employee security awareness, especially those in regulated industries or those that have experienced phishing incidents.

Price Range

$400 – $900

Typical Duration

1 day setup + 1–2 week campaign

Get a Quote

Security Program Review

Review of existing security policies, incident response plans, and controls against NIST CSF, CIS Controls, or NIST SP 800-53. Written gap analysis with a prioritized remediation roadmap.

Includes

  • Policy + procedure review
  • Control gap analysis
  • NIST CSF / CIS Controls / SP 800-53 mapping
  • Written gap analysis
  • Prioritized remediation roadmap

Ideal For

Organizations that have existing security programs but want an independent review, or those building out their program for the first time.

Price Range

$800 – $2,000

Typical Duration

2–3 days

Get a Quote

Transparent ranges, honest scoping.

Entry-level pricing is designed to lower the barrier for first-time clients. The upper range applies to larger scope, more complex environments, or tighter timelines.

I'll give you a specific number after a 30-minute discovery call — no obligation. If my pricing doesn't fit your budget, I'll tell you that directly.

Schedule a Free Discovery Call

30 minutes · No pitch · No obligation