Packages & pricing

Transparent pricing. No surprises.

Most cyber consultancies hide their fees behind "contact us". We don't. Here is what our Virtual CISO retainers and fixed-fee engagements cost — so you can budget, compare and decide before you ever pick up the phone. Independent, senior-led, vendor-neutral — every price is for work delivered by a practitioner with 27 years hands-on, not a junior bench.

Virtual CISO — monthly retainer

Senior security leadership on demand. A named, accountable CISO owning your security program — at a fraction of a full-time hire (a full-time CISO in Australia costs $250,000–$400,000+ a year, before recruitment).

Foundation
$3,500/mo

Growing businesses, councils and SMEs putting security leadership in place for the first time.

Security strategy & roadmap
Risk register & quarterly review
Policy framework & uplift
Email & scheduled-call access
Book a scoping call
Most chosen
Standard
$6,500/mo

The core engagement — organisations with real obligations and a board that needs answers.

Everything in Foundation
Monthly board-ready reporting
Vendor & team oversight
Framework compliance program (Essential Eight / ISO 27001 / CPS 234)
Priority response
Book a scoping call
Enterprise
$9,500/mo

Listed, regulated and critical-infrastructure entities under active scrutiny.

Everything in Standard
Board & committee attendance
Continuous control testing & assurance
Incident-response leadership on call
Regulator & auditor representation
Book a scoping call

Retainers are month-to-month with no lock-in, scaled to your organisation and reviewed as your maturity grows. Most clients start with a fixed-fee assessment (below), then move to a retainer once they've seen what informed oversight looks like.

Fixed-fee engagements

Defined scope, defined deliverables, one fixed fee agreed before we start — confirmed after a short scoping call. No hourly billing, no scope surprises.

Engagement From What you get
Essential Eight assessment $8,500 Evidence-based maturity rating (ML1–ML3) + gap analysis, defensible to an auditor or tender panel.
Essential Eight assessment + uplift program $18,000 Assessment plus a prioritised, costed uplift roadmap and implementation oversight to your target level.
Cyber resilience audit $9,500 Independent, plain-English audit of your environment — systems, access, backups, staff exposure. Ideal for healthcare, NfP and mid-market.
ISO/IEC 27001:2022 readiness $12,500 An ISMS built to pass certification and be operated — scope, risk method, Statement of Applicability, audit support.
SOC 2 readiness $12,500 Trust Services Criteria scoping, control design and audit-period preparation for software companies.
Penetration test — web application $7,500 Authorised testing with verified, exploitable findings, retest and an attestation letter for customers and auditors.
Penetration test + social engineering $12,000 Technical testing plus a controlled phishing / pretexting campaign — your real human exposure, not your assumed one.
SOCI Act risk-management-program review $16,500 Independent review of your RMP and incident-reporting readiness, board-ready ahead of the annual attestation.
APRA CPS 234 / CPS 230 review $18,500 Independent information-security & operational-risk review with an evidence pack fit for APRA.
Technical due diligence (per deal) $25k–$45k Independent, read-only platform assessment for investors and acquirers.

All fees are in AUD and exclude GST. "From" reflects the typical starting point; the exact fixed fee depends on scope (number of systems, cloud accounts, repos, locations) and is confirmed in writing before any work begins.

Why we publish our prices

Because you deserve to know what something costs before you invest an hour in a sales call — and because we have nothing to hide. We sell no products, take no referral commissions, and quote fixed fees against defined deliverables. The number you see is the number you pay. That transparency is the same principle that makes our findings independent and defensible: no hidden margin, no incentive to inflate scope, no surprise on the invoice.

No products sold
No referral commissions
Fixed fee, no hourly billing
Quoted before work begins
Pricing questions

How much does a Virtual CISO cost in Australia?

CISO Advisory Australia offers Virtual CISO retainers from $3,500 per month (Foundation), $6,500 per month (Standard) and $9,500 per month (Enterprise), month-to-month with no lock-in. By comparison, a full-time CISO in Australia typically costs $250,000–$400,000+ a year before recruitment. Retainers are scaled to your organisation’s size and obligations.

How much does an Essential Eight assessment cost?

An Essential Eight maturity assessment starts from $8,500, and a combined assessment plus uplift program (with a prioritised, costed roadmap and implementation oversight) starts from $18,000. Both are fixed fee, with the exact price confirmed after a short scoping call.

How much does a penetration test cost in Australia?

A web-application penetration test starts from $7,500, including a retest and an attestation letter. A combined penetration test with social-engineering (phishing / pretexting) testing starts from $12,000. Pricing depends on the scope of the application and environment.

How much does ISO 27001 or SOC 2 readiness cost?

ISO/IEC 27001:2022 readiness and SOC 2 readiness each start from $12,500 — covering ISMS or control-environment design, gap closure and audit-period preparation. The certification audit itself is conducted by a separate accredited body.

How much does technical due diligence cost for a software acquisition?

Independent technical due diligence is a fixed fee per deal: from $25,000 (Express, smaller targets), $35,000 (Standard, full scope) and $45,000 (Comprehensive, larger or regulated targets with an investment-committee briefing). Investors with regular deal flow can join the DD Panel at panel pricing with no retainer.

Are your fees fixed or hourly?

Fixed. Every engagement is scoped and priced in writing before work begins — no hourly billing and no scope surprises. Because CISO Advisory sells no products and takes no commissions, the fee is its entire commercial interest in the engagement.

Take the first step

Know the cost. Book the call.

Tell us what you need to secure and we'll confirm the fixed fee — usually the same business day. Confidential, and no obligation.

Book a scoping call

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act