
How We Engage
Every engagement starts with a clear scope and a price agreed before any work begins — no open-ended billing, no surprises. Whether you need a one-off assessment, ongoing security leadership, a fully managed estate or extra specialist hands, we shape the engagement around your risk and your budget. Start with a free, no-obligation consultation and find out exactly what is worth doing.
Priced to your risk — not a rate card
We deliberately do not publish a fixed price list. Enterprise security and IT are not commodities: a penetration test for a single application is a completely different engagement from hardening a 50-server regulated banking estate, and pricing either one from a web page would mean charging you for work you may not need — or under-scoping work you do. Instead, we scope precisely, then give you a fixed price or a clear monthly retainer before you commit to anything.
That means the first conversation costs you nothing and carries no obligation. We listen, we tell you honestly what is worth doing (and what is not), and only when the scope is clear do we put a number in front of you. You always know what you are paying for, and why, before any work begins.
Four ways to work with us
Most clients start with one model and combine others as the relationship grows. Every model is vendor-independent and delivered by senior, certified consultants.
Fixed-Scope Project
For defined deliverables — security assessments, penetration tests, cloud migrations, hardening or compliance readiness. You get a documented scope, timeline and a fixed fee agreed upfront, so the budget is predictable from day one. Best for organisations with a specific outcome in mind and a need for budget certainty.
Advisory Retainer (vCISO)
Ongoing senior security leadership without the cost of a full-time hire — strategy, board and regulator reporting, architecture review and roadmap ownership. Billed as a monthly retainer scaled to how much of our time you need. Best for organisations that need CISO-level expertise on tap but not a permanent executive.
Managed Services
24/7 monitoring, detection and response, patching, backup/DR and support — we run and defend your environment against agreed SLAs. Billed monthly, scaled to the size of your estate. Best for organisations that would rather we operate the security and IT than build a large in-house team.
Staff Augmentation
Embed vetted specialists directly into your team when you need capacity or a specific skill — cloud, security engineering, SOC or infrastructure. Billed for the time you use, month to month. Best for organisations scaling a programme or covering a skills gap without long-term headcount.
How an engagement works
A clear, low-risk path from first conversation to delivered outcome.
1. Free consultation (~30 min)
A no-obligation call to understand your situation, your risks and your goals. No hard sell — if there is a simpler or cheaper way to solve your problem, we will tell you.
2. Discovery & risk review
We look closer at your environment, priorities and constraints to pinpoint what truly matters, so the work targets real risk rather than a generic checklist.
3. Scoping & proposal
We define the deliverables, timeline and the right engagement model, then put a fixed price or clear monthly retainer in writing. You see exactly what is included before committing.
4. Agreement & NDA
A clear statement of work with no hidden costs. We provide an NDA on request before any sensitive detail is shared, so you can speak freely from the start.
5. Kick-off & planning
We agree points of contact, access, milestones and reporting cadence up front, so everyone knows what happens, when — and delivery starts without friction.
6. Delivery
Senior, certified consultants do the work — never juniors learning on your systems — with regular updates, evidence-based reporting and clear progress against the plan.
7. Reporting & knowledge transfer
You receive clear, actionable reporting and full handover documentation, so your own team understands what was done and owns the outcome with confidence.
8. Ongoing partnership
When it makes sense, we continue as a retainer or managed-services partner. There is no long lock-in — you stay because the relationship delivers, not because a contract traps you.
What every engagement includes
Trusted on mission-critical systems
A sample of engagements across regulated banking, telecom and critical infrastructure. Client names are shared with permission; others are kept confidential.
Al Khaliji Bank · Banking · Qatar
A regulated GCC bank under Qatar Central Bank oversight needed its core banking, payments and internet-banking platforms hardened and kept continuously compliant.
A 50+ server high-availability estate hardened to PCI-DSS, ISO 27001, CIS and STIG, encryption across core systems, a clustered internet-banking architecture and a custom WAF-protected banking tier — delivered in partnership with regulators and internal audit.
A materially reduced audit and breach-impact surface, demonstrable regulatory compliance and a monitoring and KPI baseline the bank’s own teams adopted.
Optiva · Telecom SaaS · Global
A global multi-tenant telecom SaaS had to scale rapidly across AWS, Google Cloud and Azure without compromising security or service continuity.
Security, network and reliability architecture governed across all three clouds — segmentation, IAM, encryption, ISO 27001/CIS hardening and Terraform/Ansible automation — plus a proprietary approach to run the client’s Solaris/SPARC application on Google Cloud, avoiding a costly re-platform.
The platform scaled 10× in customer base with no material service regression, and the containerisation saved substantial funds versus rewriting the application.
Knabu · Regulated fintech / blockchain · UK
A regulated blockchain and crypto-wallet platform needed a high-assurance cloud posture protecting signing infrastructure and customer assets.
Aydahwa built the platform on AWS aligned to ISO 27001 and AWS security best practices — centralised AAA, audit logging, continuous configuration monitoring, a custom VPN and segmentation model isolating the signing environment, Terraform/Ansible IaC guardrails in an AWS CodePipeline CI/CD flow, and tested disaster-recovery runbooks.
Every deployment policy-compliant by construction (no configuration drift), a contained blast radius around signing infrastructure, and measurably lower MTTD/MTTR through automation-first operations.
National critical-infrastructure programme
Client confidentialA national critical-infrastructure programme required a specialist virtual team directed across mission-critical systems where availability and security are non-negotiable.
Aydahwa directed a 20+ strong specialist virtual team across the programme, providing security and infrastructure leadership on systems where downtime is not an option.
A coordinated, security-led delivery across mission-critical infrastructure, with expertise directed exactly where the programme needed it.
Engagement & pricing FAQ
Why don’t you publish fixed prices?+
Because every environment is different, a published rate card would either overcharge you for work you do not need or under-scope work you do. We scope precisely first, then give you a fixed price or a clear monthly retainer in writing before you commit to anything — so you always know what you are paying for, and why.
How do you charge?+
Four ways, matched to your need: a fixed fee for defined projects, a monthly retainer for advisory (vCISO) work, a monthly fee scaled to your estate for managed services, or time-based billing for staff augmentation. Many clients combine models over time.
Is there a minimum engagement?+
You can start small — a short, well-defined project or a free self-assessment — with no obligation to continue. We would rather earn a long-term relationship by delivering value than lock you into a large upfront commitment.
What if we are not sure what we need?+
That is exactly what the free consultation and our free self-assessment are for. We will help you understand where you stand and tell you honestly what is worth doing — including if the answer is “less than you think”.
Do you sign NDAs?+
Yes. We provide an NDA on request before any sensitive detail is shared, so you can speak freely about your environment from the very first conversation.
Are we locked into a long contract?+
No. We avoid long lock-ins and offer month-to-month options on retainers and managed services. We also transfer full knowledge to your team, so you always own the outcome and stay because the partnership delivers.
Cybersecurity Readiness Checklist
A practical, vendor-neutral self-check mapped to ISO/IEC 27001, the NIST Cybersecurity Framework, and CIS Controls — find your gaps before an attacker or an auditor does.
Prefer to score it online? Take the interactive checklistBook a free, no-obligation consultation
Tell us where you are and what is keeping you up at night. In about 30 minutes we will give you an honest view of your risk and the most sensible way to address it — with a clear scope and price before any work begins.
No obligation, no hard sell. NDA provided on request. Vendor-independent advice.