ENG-01
Security Audits
From $4,500
A structured posture review of information-security controls for one defined environment—not a certification or SOC 2 attestation.
- Control checklist across people, process, and tech in scope
- Gap notes vs. a stated baseline (e.g. CIS-aligned expectations)
- Written findings summary and prioritized recommendations
Starting scope: 1 environment · ~3–5 analyst days · excludes continuous monitoring and formal certification
ENG-02
Vulnerability Assessment
From $3,500
Discovery and ranking of known weaknesses across an agreed host or URL set, with manual triage of scanner noise.
- Up to 25 hosts or URLs
- Authenticated scanning where credentials are provided
- Severity-ranked findings and remediation guidance
Starting scope: non-destructive assessment · no exploitation · not a penetration test
ENG-03
Authorized Penetration Testing
From $6,800
Human-led, permissioned testing against one target class under written rules of engagement—web app or external perimeter at the starting price.
- Written RoE required before work
- Typically up to 5 tester-days for the starting scope
- Evidence-backed report plus remediation priorities
Starting scope: 1 target class · quotes below ~$4,000 in this market are usually scans, not manual tests
ENG-04
Security Configuration
From $2,800
Hardening pass focused on protective mechanisms for one agreed stack, with a clear before/after map.
- Baseline vs. desired configuration map
- Hardening changes within the agreed stack
- Operator handoff notes for your team
Starting scope: 1 stack (perimeter, IAM, or endpoints) · ~2 analyst days · excludes ongoing admin or MDR
ENG-05
Recommendations & Reports
From $1,800
A standalone recommendations package and security report for technical and business readers. Included at no extra charge when bundled with ENG-01 to ENG-04.
- Executive-readable summary
- Technical finding detail
- Remediation priority order
Starting scope: rewrite from findings you supply or from prior work · no new testing
ENG-06
Remediation Planning Session
From $2,400
A working session that turns existing findings into an ordered, owner-assigned fix plan your team can execute.
- One half-day remote workshop
- 30-day written remediation plan
- Owner and priority assignments
Starting scope: planning only · excludes implementation of fixes
ENG-07
Re-test / Validation Pass
From $2,800
Post-fix verification that previously reported issues were addressed, under renewed or still-valid written authorization.
- One target class re-checked
- Per-finding status: closed, partial, or open
- Short validation addendum
Starting scope: 1 target class · often ~35–40% of the original test when booked after our ENG-03 · no new discovery
ENG-08
Security Awareness Briefing
From $1,800
A readout for leadership and technical staff on current exposure, risk language, and sensible next steps.
- Executive readout
- Technical readout
- Slide deck and discussion notes
Starting scope: 2 sessions · no testing · no phishing simulation campaign