
How We Engage
Every engagement starts with a clear scope and a price agreed before any work begins — no open-ended billing, no surprises. Most clients begin with a focused piece of work and grow into a long-term partnership where we run, secure and continuously improve their entire IT and security estate — in effect becoming their IT and security department. Start with a free, no-obligation consultation and find out exactly what is worth doing.
Priced to your risk — not a rate card
We deliberately do not publish a fixed price list. Enterprise security and IT are not commodities: a penetration test for a single application is a completely different engagement from hardening a 50-server regulated banking estate, and pricing either one from a web page would mean charging you for work you may not need — or under-scoping work you do. Instead, we scope precisely, then give you a fixed price or a clear monthly retainer before you commit to anything.
That means the first conversation costs you nothing and carries no obligation. We listen, we tell you honestly what is worth doing (and what is not), and only when the scope is clear do we put a number in front of you. You always know what you are paying for, and why, before any work begins.
Four ways to work with us
Most clients start with one model and combine others as the relationship grows. Every model is vendor-independent and delivered by senior, certified consultants.
Fixed-Scope Project
For defined deliverables — security assessments, penetration tests, cloud migrations, hardening or compliance readiness. You get a documented scope, timeline and a fixed fee agreed upfront, so the budget is predictable from day one. Best for organisations with a specific outcome in mind and a need for budget certainty.
Advisory Retainer (vCISO)
Ongoing senior security leadership without the cost of a full-time hire — strategy, board and regulator reporting, architecture review and roadmap ownership. Billed as a monthly retainer scaled to how much of our time you need. Best for organisations that need CISO-level expertise on tap but not a permanent executive.
Managed Services
The heart of a long-term partnership: we take care of your entire IT and security estate — 24/7 monitoring, detection and response, patching, backup/DR and support — running and defending your environment against agreed SLAs. Billed monthly and scaled to the size of your estate, this is how most clients settle into an ongoing relationship where Aydahwa is, in effect, their IT and security department. Best for organisations that would rather we operate their technology than build and retain a large in-house team.
Staff Augmentation
Embed vetted specialists directly into your team when you need capacity or a specific skill — cloud, security engineering, SOC or infrastructure. Billed for the time you use, month to month. Best for organisations scaling a programme or covering a skills gap without long-term headcount.
How an engagement works
A clear, low-risk path from first conversation to delivered outcome.
1. Free consultation (~30 min)
A no-obligation call to understand your situation, your risks and your goals. No hard sell — if there is a simpler or cheaper way to solve your problem, we will tell you.
2. Discovery & risk review
We look closer at your environment, priorities and constraints to pinpoint what truly matters, so the work targets real risk rather than a generic checklist.
3. Scoping & proposal
We define the deliverables, timeline and the right engagement model, then put a fixed price or clear monthly retainer in writing. You see exactly what is included before committing.
4. Agreement & NDA
A clear statement of work with no hidden costs. We provide an NDA on request before any sensitive detail is shared, so you can speak freely from the start.
5. Kick-off & planning
We agree points of contact, access, milestones and reporting cadence up front, so everyone knows what happens, when — and delivery starts without friction.
6. Delivery
Senior, certified consultants do the work — never juniors learning on your systems — with regular updates, evidence-based reporting and clear progress against the plan.
7. Reporting & knowledge transfer
You receive clear, actionable reporting and full handover documentation, so your own team understands what was done and owns the outcome with confidence.
8. Ongoing partnership
This is where most engagements are heading: we continue as your long-term retainer or managed-services partner, taking day-to-day responsibility for your IT and security so your own team can focus on the business. You stay because the relationship delivers real value year after year — and because a partner who knows your estate inside out is far more effective than starting again with someone new.
What every engagement includes
Trusted on mission-critical systems
A sample of engagements across regulated banking, telecom and critical infrastructure. Client names are shared with permission; others are kept confidential.
Al Khaliji Bank · Banking · Qatar
A regulated GCC bank under Qatar Central Bank oversight needed its core banking, payments and internet-banking platforms hardened and kept continuously compliant.
A 50+ server high-availability estate hardened to PCI-DSS, ISO 27001, CIS and STIG, encryption across core systems, a clustered internet-banking architecture and a custom WAF-protected banking tier — delivered in partnership with regulators and internal audit.
A materially reduced audit and breach-impact surface, demonstrable regulatory compliance and a monitoring and KPI baseline the bank’s own teams adopted.
Optiva · Telecom SaaS · Global
A global multi-tenant telecom SaaS had to scale rapidly across AWS, Google Cloud and Azure without compromising security or service continuity.
Security, network and reliability architecture governed across all three clouds — segmentation, IAM, encryption, ISO 27001/CIS hardening and Terraform/Ansible automation — plus a proprietary approach to run the client’s Solaris/SPARC application on Google Cloud, avoiding a costly re-platform.
The platform scaled 10× in customer base with no material service regression, and the containerisation saved substantial funds versus rewriting the application.
Knabu · Regulated fintech / blockchain · UK
A regulated blockchain and crypto-wallet platform needed a high-assurance cloud posture protecting signing infrastructure and customer assets.
Aydahwa built the platform on AWS aligned to ISO 27001 and AWS security best practices — centralised AAA, audit logging, continuous configuration monitoring, a custom VPN and segmentation model isolating the signing environment, Terraform/Ansible IaC guardrails in an AWS CodePipeline CI/CD flow, and tested disaster-recovery runbooks.
Every deployment policy-compliant by construction (no configuration drift), a contained blast radius around signing infrastructure, and measurably lower MTTD/MTTR through automation-first operations.
National critical-infrastructure programme
Client confidentialA national critical-infrastructure programme required a specialist virtual team directed across mission-critical systems where availability and security are non-negotiable.
Aydahwa directed a 20+ strong specialist virtual team across the programme, providing security and infrastructure leadership on systems where downtime is not an option.
A coordinated, security-led delivery across mission-critical infrastructure, with expertise directed exactly where the programme needed it.
Engagement & pricing FAQ
Why don’t you publish fixed prices?+
Because every environment is different, a published rate card would either overcharge you for work you do not need or under-scope work you do. We scope precisely first, then give you a fixed price or a clear monthly retainer in writing before you commit to anything — so you always know what you are paying for, and why.
How do you charge?+
Four ways, matched to your need: a fixed fee for defined projects, a monthly retainer for advisory (vCISO) work, a monthly fee scaled to your estate for managed services, or time-based billing for staff augmentation. Many clients combine models over time.
Is there a minimum engagement?+
You can start small — a short, well-defined project or a free self-assessment — with no obligation to continue. We would rather earn a long-term relationship by delivering value than lock you into a large upfront commitment.
What if we are not sure what we need?+
That is exactly what the free consultation and our free self-assessment are for. We will help you understand where you stand and tell you honestly what is worth doing — including if the answer is “less than you think”.
Do you sign NDAs?+
Yes. We provide an NDA on request before any sensitive detail is shared, so you can speak freely about your environment from the very first conversation.
Do you offer long-term managed partnerships?+
Yes — and for most clients that is the goal. While you are free to start with a single project, the greatest value comes from a long-term engagement where we take care of your entire IT and security estate under an ongoing retainer or managed-services agreement. A longer commitment lets us plan properly, invest in your environment and deliver better value over time; we also transfer full knowledge to your team, so the relationship endures because it delivers, not because you are trapped.
Cybersecurity Readiness Checklist
A practical, vendor-neutral self-check mapped to ISO/IEC 27001, the NIST Cybersecurity Framework, and CIS Controls — find your gaps before an attacker or an auditor does.
Prefer to score it online? Take the interactive checklistLatest Insights
Recent articles from our team on IT consulting and cybersecurity.

Aligning IT Strategy with Business Goals: A CIO Framework
The most common complaint boards have about IT isn't the cost. It's that they can't see how technology spending connects to business outcomes. When IT operates as a cost centre detached from commercial strategy,…
Read more
Nine Service Architecture Anti-Patterns We Keep Fixing in Production
Architecture is where reliability and security get decided Most outages I have been called into over the last twenty-five years were not caused by a clever attacker or a freak hardware failure. They were caused by a…
Read more
The Failure Modes That Take Down Distributed Systems
A five-minute blip that cost a bank its morning A few years ago we were called into a retail bank whose core payment gateway had gone dark for forty minutes during the morning rush. The root cause was almost…
Read moreBook a free, no-obligation consultation
Tell us where you are and what is keeping you up at night. In about 30 minutes we will give you an honest view of your risk and the most sensible way to address it — with a clear scope and price before any work begins.
No obligation, no hard sell. NDA provided on request. Vendor-independent advice.