Cybersecurity Consulting Services: What Each Costs and Who Provides Them
Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

Nobody wakes up wanting cybersecurity consulting. They buy it because a customer sent a security questionnaire, an insurer asked a question they could not answer, a regulator named a date, or something already went wrong. That matters, because the trigger decides which service you need, and most of the money wasted in this market is spent on the wrong service bought at the wrong moment.
This guide covers what cybersecurity consulting services actually are, what each one costs, which firms provide them, and how to tell a good engagement from an expensive one. It is written by a practice that sells these services, so treat the recommendations accordingly. Where we are the wrong choice, that is said plainly.
The short version. There are four jobs consulting does: find out what is exposed, build what is missing, prove it to somebody external, and respond when something happens. Every service on the market is one of those four. Fixed-scope projects suit the first three. Retainers suit the fourth and the ongoing accountability nobody internal wants to own.
The four jobs cybersecurity consulting actually does
Service catalogues are long because every firm names the same work differently. Underneath the branding there are four jobs, and knowing which one you are buying prevents most bad purchases.
The common failure is buying from category two when your trigger belongs in category three. A company told to produce a SOC 2 report does not need a hardening project first; it needs a readiness programme that produces evidence, with hardening inside it where the evidence demands it. Buying in the wrong order costs months.
What each of the four jobs looks like in practice
Assess: finding out what is actually exposed
An assessment is worth buying when nobody in the building can answer a simple question: if someone tried, how would they get in? The output should be a ranked list where each item names a system, the exposure, and the fix. A maturity score is not that. A score tells you how you compare to a model; it does not tell your engineer what to change on Tuesday.
The common mistake is buying a penetration test when you needed an audit. A penetration test answers "can this specific thing be broken into". An audit answers "what is the full set of things that could be". If you have never had either, start with the audit, because a pen test against an environment with no multi-factor authentication will simply confirm what you already suspected, at a higher price.
Expect two to four weeks for a small environment. Expect to grant read access to your cloud tenant and to spend two or three hours in interviews. A firm that can do it without either is not looking very hard.
Build: putting in the controls that were missing
Build work is where the money actually gets saved, and where most consulting relationships fail. The failure mode is predictable: a good assessment lands, the report is circulated, everyone agrees it is excellent, and eleven months later nothing has changed because nobody was resourced to act on it.
Guard against that in the contract. Ask whether the firm implements or only recommends. Both models are legitimate, but if they only recommend, you need someone internal with the time and authority to do the work, and that person should be named before the assessment starts rather than found afterwards.
Build work is also where vendor commissions distort advice most sharply. A firm that resells the product it just recommended is not necessarily wrong, but you should know, and you should ask what the second-best option was and why it lost.
Prove: producing evidence somebody external demands
This is the largest category by spend, because it has a deadline attached. A customer contract naming SOC 2, an insurer's renewal questionnaire, a regulator with a date. The work is only partly technical; much of it is assembling evidence that the controls you already have actually operate, and writing down the ones that live only in someone's head.
Two things reliably save money here. First, sequence from the deadline backwards rather than starting with whatever is most interesting. Second, reuse: SOC 2 and ISO 27001 share roughly two thirds of their control work, and DORA and NIS 2 overlap heavily on incident reporting and third-party risk. Running them as separate programmes because they were sold separately is the most common avoidable cost in compliance.
Be wary of anyone promising certification. Consultancies prepare you; accredited bodies certify you, and any firm implying it can do both should be asked to explain exactly how.
Respond: acting when something has already happened
Incident work is bought under pressure, which is precisely when buying goes badly. The time to agree terms with a response firm is before you need them. Many will hold a retainer at modest cost that guarantees a response window, and the difference between calling a firm you have a contract with and cold-calling three firms at 6pm on a Friday is measured in days.
The expensive part of a small-company incident is rarely the attack itself. It is the two days spent deciding who is in charge, whether to notify customers, what the insurer needs, and whether the backups work. Most of that can be decided in advance in a single afternoon.
Why the same scope gets quoted at wildly different prices
Buyers are often startled to receive quotes for the same work that differ by a factor of five. The spread is usually explained by four things, none of which is quality.
- Who delivers. A partner-led firm staffing with junior consultants carries overhead a solo practitioner does not. You are paying for the bench, the brand and the offices.
- How the scope was read. One firm assumed a single cloud tenant; another assumed three subsidiaries and an on-premise domain. The difference is not price, it is what was priced.
- Whether retesting is included. Excluding it makes the headline number smaller and the eventual total larger.
- Risk appetite on fixed pricing. A firm that fixes the price carries the risk of underestimating and pads accordingly. A firm quoting day rates moves that risk to you.
The way to compare quotes fairly is to make every firm price the same written scope, including retesting, and to ask each to name the individual who will deliver it. Quotes usually converge sharply once those two things are fixed.
What good looks like six months later
The test of a consulting engagement is not the report. It is what is different half a year on.
- Someone internal can name the top five risks without opening a document.
- The findings that mattered are closed, and the ones that are not closed have an owner and a date.
- The next customer questionnaire took an afternoon because the evidence was already assembled.
- Your engineers can explain why a control exists, not just that an auditor wanted it.
- You know who to call at 6pm on a Friday, and they already have your environment documented.
If none of that is true six months after an engagement, the money bought a document rather than a change, and the fault is usually shared between a firm that did not push and a buyer who did not resource the follow-through.
The twelve services, what they cost and when you need them
This is the full catalogue as it is actually sold. Durations assume a single legal entity of roughly 20 to 300 staff. Prices are indicative market ranges for a competent independent firm, not quotes, and Big 4 pricing typically runs two to four times higher for the same scope.
| Service | What you get | Typical duration | Indicative range |
|---|---|---|---|
| IT security audit | A ranked list of what is exposed across every domain, with a fix plan | 2 to 4 weeks | $5,000 to $25,000 |
| Risk assessment | Risks scored against your appetite, mapped to a framework | 2 to 4 weeks | $6,000 to $20,000 |
| Penetration test | Proof of what an attacker can reach, with attack paths | 1 to 3 weeks | $4,000 to $30,000 |
| Vulnerability assessment | Known weaknesses found, ranked and tracked over time | 1 to 2 weeks | $3,000 to $15,000 |
| Cloud security review | AWS, Azure, GCP or M365 configuration against a benchmark | 2 to 3 weeks | $4,000 to $20,000 |
| SOC 2 readiness | Controls, evidence and auditor coordination to pass first time | 8 to 16 weeks | $12,000 to $60,000 |
| ISO 27001 readiness | An ISMS that survives the certification audit | 10 to 20 weeks | $15,000 to $70,000 |
| Virtual CISO | A named accountable person, on retainer | Monthly, ongoing | $3,000 to $15,000/mo |
| Incident response | Containment, forensics, and the regulatory clocks handled | Days to weeks | $15,000 upward |
| Security architecture | A design that does not need redoing in eighteen months | 3 to 8 weeks | $10,000 to $50,000 |
| Awareness training | Role-specific training plus phishing simulation | Ongoing | $2,000 to $15,000/yr |
| Third-party risk | Your suppliers assessed and monitored, not just listed | 3 to 6 weeks | $8,000 to $40,000 |
Ranges reflect what independent firms and mid-size specialists charge for single-entity scopes. Multi-entity, multi-country, regulated or software-producing companies sit above these. Anyone quoting a firm number before asking what you run is guessing.
Start from the trigger, not the catalogue
The fastest way to pick the right service is to name what actually happened. Almost nobody buys consulting because they decided to be more secure in the abstract.
If two rows apply, sequence them. A customer questionnaire plus a SOC 2 clause in the same contract is one programme, not two engagements, and buying them separately is how companies pay twice for the same evidence.
Two shapes of engagement, and how to tell which you are being sold
Beneath every proposal is one of two commercial models. The model tells you more about how a firm works than any capability deck.
Be suspicious of a fixed-scope price quoted before anyone has asked what you run. Either it is padded to cover the unknown, or the scope will be renegotiated once work starts. A firm confident in fixed pricing asks a lot of questions first, and that conversation is free.
The four types of firm, and what each is genuinely good at
The market divides into four groups. Each is the right answer for somebody, and the expensive mistake is buying from the wrong group for your size.
Big 4 and global consultancies
Deloitte, PwC, KPMG, EY and Accenture. Enormous benches, global coverage, and the name on the report carries weight with boards, regulators and acquirers. That is what you are paying for, and in some situations it is worth it: a contested acquisition, a regulator who expects a recognised name, or a programme spanning fifteen countries.
The trade is cost and staffing. Partners sell, managers scope, and delivery lands with consultants who may be early in their careers. Day rates reflect the brand and the overhead. For a 40-person SaaS company needing SOC 2, this is usually the wrong shape of firm.




Large security-specialist firms
Optiv, NCC Group, Kroll and similar. Security is the whole business rather than one practice inside a consultancy, so the technical depth is usually better than the Big 4 at comparable or lower cost. They carry real incident response capability, which matters if you want one firm on retainer for both advice and emergencies.
The trade is that you are still a mid-size account inside a large organisation. Continuity of people varies, and the person who impressed you in the pitch may not be the person on your engagement.



Technical boutiques
Bishop Fox, Coalfire and firms of that shape. Narrower catalogues, deeper expertise in what they do, and usually the best choice when the work is genuinely hard: complex application testing, cloud-native architecture, or an assessment that has to stand up to scrutiny.
The trade is coverage. A boutique that is excellent at offensive testing may not want to run your ISO 27001 programme, and should say so.


Independent and founder-led practices
One senior practitioner, or a very small team, doing the work personally. The person who scopes the engagement is the person who delivers it, so nothing is lost in translation and there is no junior bench. Pricing is usually well below the large firms for the same scope because there is no overhead to carry.
The trade is capacity and continuity. An independent cannot field ten people next Monday, cannot cover every framework, and if they are unavailable there is no bench behind them. Ask directly what happens when they are busy, and treat "we will find someone" as a bad answer.
Atlant Security sits in this group, so read the next paragraph with that in mind.

Alexander Sverdlov runs every engagement personally: former Microsoft Security Consulting team, CISSP, 200+ security assessments across 14 countries since 2013, including banks, payment institutions, government bodies and critical infrastructure. Scope and price are agreed in writing first, and for assessments you read the full report before an invoice is issued. There are no reseller agreements with any security vendor, so a recommendation to buy something is never about margin. The honest limitation is capacity: when the calendar is full the answer is a date, not a junior.
How a good engagement actually runs
Five steps. If a firm cannot describe all five on the first call, that is information.
Step five is where proposals quietly differ. Some firms include verification of the fixes they recommended; others treat it as a fresh engagement. Neither is dishonest, but the second doubles your cost to reach the same place, and you should know which you are buying.
Seven things that should end the call
The vendor-commission question is the one buyers most often forget to ask. A firm earning reseller margin on the tools it recommends has an interest in your problem having a product-shaped solution. That does not make the advice wrong, but you are entitled to know before you weigh it.
Questions worth asking before you sign
- Who does the work, by name? Then ask what happens if that person is unavailable.
- What standard are you testing against? A firm that cannot name one is improvising.
- Is retesting included? See above.
- Do you hold any reseller or partner agreements? Ask for a yes or no.
- What does the deliverable look like? Ask to see a redacted sample. Good firms have one ready.
- Will my engineers be in the debrief? If the readout is board-only, the fixes will not land.
- What is out of scope? The answer reveals how carefully they scoped.
- What happens if you find something critical on day two? You want "we call you", not "it is in the report".
Choosing by company size
| Company size | Usually the right firm | Start with |
|---|---|---|
| Under 50 staff | Independent or small specialist | A scoped audit, then fix the top five findings |
| 50 to 200 | Independent or technical boutique | Audit plus a virtual CISO retainer |
| 200 to 1,000 | Security specialist firm | Framework readiness with testing inside it |
| 1,000+ | Specialist firm, Big 4 where the name matters | Programme-level engagement with named workstreams |
| Regulated, any size | Whoever knows your specific regulator | The control catalogue your supervisor assesses against |
Regional and regulator-specific consulting
Gulf and Asian regulators publish prescriptive control catalogues, and the supervisor assesses against the catalogue rather than a generic framework. Mapping an existing ISO 27001 programme across usually covers half to two thirds of the work. The rest is local: data residency, named officers, in-country reporting lines and the specific evidence formats expected.
If a framework below applies to you, the firm you pick should be able to name the document and its current version without looking it up:
- SAMA CSF and NCA ECC in Saudi Arabia
- NESA / UAE IA, ADHICS and Dubai ISR in the UAE
- Qatar NIA, MAS TRM in Singapore and HKMA C-RAF in Hong Kong
- DORA and threat-led penetration testing for EU financial entities
Five situations, and what to actually buy
Generic advice is hard to act on. These are the five situations that account for most enquiries, with the engagement that fits each and the one people wrongly buy instead.
1. A 60-person SaaS company has a deal blocked by a security questionnaire
Buy: a short gap engagement against the questionnaire itself, two to four weeks. Map every question to evidence you already hold, close the three or four gaps that would force a "no", and keep the answers so the next one takes an afternoon.
Do not buy: a full SOC 2 programme, yet. SOC 2 takes months and the deal will not wait. Many enterprise buyers accept documented readiness plus a dated plan. Start the programme afterwards if the pattern repeats, which it usually does.
Watch for: firms that answer the questionnaire for you without closing anything. That gets the deal through and leaves the exposure in place, which is fine until the first audit.
2. A 25-person firm just had an invoice paid to a fraudulent account
Buy: a short incident review to establish whether a mailbox was accessed and for how long, then email hardening. Business email compromise usually involves no malware at all, so antivirus tells you nothing.
Do not buy: a penetration test. Nothing was hacked in the sense a pen test measures. The control that failed was a payment verification process, not a firewall.
Watch for: the second-channel rule being treated as optional. Any request to move money or change bank details gets verified by phone on a number you already had. That single policy prevents most recurrences and costs nothing.
3. A 300-person fintech has a regulator deadline in nine months
Buy: a programme scoped backwards from the deadline, against the specific control catalogue the supervisor assesses. The firm should name the document and its version without looking it up.
Do not buy: a generic ISO 27001 programme on the assumption it will satisfy the regulator. It will cover a large share of the work, but the residual is exactly the part the supervisor examines: local reporting lines, named officers, data residency, evidence formats.
Watch for: a firm without direct experience of that regulator. Enthusiasm is not the same as having sat opposite them.
4. A 120-person manufacturer has no one accountable for security
Buy: a fractional or virtual CISO retainer, plus one scoped audit at the start so the retainer begins with facts rather than opinions.
Do not buy: a full-time hire, at least not yet. At this size the role is perhaps two days a month of decisions and a few days a quarter of programme work. A full-time senior hire will be expensive, under-used, and difficult to recruit against companies that can offer a bigger remit.
Watch for: retainers that are really support contracts. You want decisions, board reporting and customer-facing answers, not a ticket queue.
5. A 15-person startup whose largest customer is about to audit them
Buy: very little. Do the free work first: multi-factor authentication on every account, admin rights cut to two people, a tested restore, and control of what is exposed to the internet. Then a short assessment to confirm and document it.
Do not buy: a retainer. At this size the fixed costs of an ongoing relationship rarely earn out, and most of the risk is closed by configuration rather than advice.
Watch for: anyone selling a fifteen-person company an enterprise programme. It happens, and it is the clearest signal to walk.
The honest limits of consulting
Consulting cannot make a company secure that will not change anything. It cannot replace tooling you genuinely need, and it cannot substitute for someone internal owning the outcome. The most common disappointment in this market is not bad advice; it is good advice that nobody was resourced to act on.
It also cannot give you certainty. Security work reduces the probability and the blast radius of a bad day. Any firm promising that you will not be breached is either misunderstanding the problem or misrepresenting it, and both are reasons to keep looking.
Cybersecurity consulting services: frequently asked questions
What are cybersecurity consulting services?
Cybersecurity consulting services are engagements where an external specialist assesses, builds, proves or defends your security posture. In practice that means security audits and risk assessments, penetration testing, control implementation and hardening, framework readiness for SOC 2 or ISO 27001, fractional security leadership, and incident response. They are bought as fixed-scope projects or as ongoing retainers.
How much do cybersecurity consulting services cost?
For a single-entity company of 20 to 300 staff, a scoped security audit typically runs $5,000 to $25,000, a penetration test $4,000 to $30,000, SOC 2 readiness $12,000 to $60,000, and a virtual CISO retainer $3,000 to $15,000 per month. Big 4 pricing is usually two to four times higher for the same scope. What moves the number is legal entities, self-hosted infrastructure, whether you build software, and whether a contract names a framework.
What is the difference between a cybersecurity consultant and an MSSP?
A consultant advises, assesses and builds, then leaves you with something you own. A managed security service provider runs something for you on an ongoing basis, usually monitoring and detection. You often need both, and they are not substitutes: an MSSP watching your alerts does not tell you whether your architecture is sound, and a consultant producing a report does not watch your alerts at 3am.
Do I need a consultant if I already have an IT provider?
Usually yes, because they are different disciplines. IT builds and maintains systems and is measured on uptime. Security work is adversarial and asks how those same systems would be attacked. Good IT providers welcome an independent review, and many engagements run alongside one rather than instead of it.
How long does a cybersecurity consulting engagement take?
A scoped audit of a small environment is two to four weeks from access to report. Penetration tests run one to three weeks. Framework readiness for SOC 2 or ISO 27001 runs two to five months and is usually driven by the deadline in a customer contract. Incident response starts immediately and is measured in days.
What should a cybersecurity consulting deliverable contain?
A report naming the system, the exposure and the fix, rather than a maturity score. A remediation plan with owners and dates. Evidence packaged the way a customer or auditor asks for it. And a debrief your engineers attend. If the deliverable is a heat map and a recommendation to consider implementing something, you have bought a document rather than a change.
Should I use a Big 4 firm for cybersecurity consulting?
Use one when the name on the report is doing work for you: a contested acquisition, a regulator that expects a recognised brand, or a programme spanning many countries. For a company under a few hundred staff needing SOC 2 or a security audit, you will generally get deeper technical work for less from an independent or specialist firm.
How do I know if a cybersecurity consultant is any good?
Ask who does the work by name, what standard they test against, whether retesting is included, and whether they hold reseller agreements with any vendor. Ask to see a redacted sample deliverable. A firm that answers all five without hesitation is usually competent; one that deflects on any of them is telling you something.
Is cybersecurity consulting worth it for a small business?
It is worth it when there is a trigger: a customer questionnaire, an insurance renewal, a contract naming a framework, or an incident. Without a trigger, a small company is usually better served by doing the basics itself first, which costs nothing: multi-factor authentication everywhere, fewer admin accounts, a tested backup, and control of what is exposed to the internet.
What is a virtual CISO and when does it make sense?
A virtual CISO is a named, accountable security leader on a part-time retainer rather than a full-time hire. It makes sense between roughly 50 and 500 staff, where a full-time hire is not proportionate but having nobody accountable is exactly what customer questionnaires and insurers ask about. Below 50 staff, a fixed-scope engagement is usually better value.
Can cybersecurity consulting help with cyber insurance?
Yes, and it is one of the more common triggers. Insurers now ask specific control questions, particularly about multi-factor authentication, endpoint protection, backup and privileged access. A short engagement that closes those gaps and documents them tends to pay for itself in premium terms, quite apart from the risk reduction.
What does cybersecurity consulting not cover?
Consulting does not run your security operations day to day, does not replace tooling you genuinely need, and cannot make a company secure that will not change anything after the report. The most common failure is not bad advice; it is a good report that nobody was resourced to act on.
Where to go next
If you know the trigger, go straight to the service that answers it:
- Nobody can say what is exposed: IT security audit
- A customer questionnaire is blocking a deal: risk assessment and evidence
- A contract names SOC 2 or ISO 27001: SOC 2 readiness or ISO 27001 readiness
- You need proof an attacker cannot get in: penetration testing
- Nobody owns security internally: virtual CISO services
- You are under 200 staff and unsure where to start: cybersecurity for small business
- You want the whole picture first: how our consultancy engagements work
Or book a thirty-minute scoping call. You will leave it knowing the three things most likely to be exposed in your environment and whether you need an outside firm at all, which is sometimes no.

Alexander Sverdlov
Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
Connect on LinkedIn