Ready to scope an engagement?
Book a Discovery CallBoutique Cyber Advisory · London
Fixed-fee assessments, TPRM, threat modelling, and fractional vCISO leadership for regulated firms, boutique London team, no generalist fluff.
How It Works
No lengthy procurement. No retainer surprises. A straight path from where you are to where you need to be.
A free 30-minute call. We listen first, understand your situation, and tell you honestly whether and how we can help.
A fixed-fee proposal with clear deliverables, timelines, and outcomes. You know exactly what you're getting before signing anything.
We get to work. Regular updates, no surprises. Practical outputs your team can actually use, not 200-page reports that sit on a shelf.
Most clients move to a retainer after their first engagement. Fractional vCISO, quarterly reviews, ongoing vendor oversight, on your terms.
Advisory Disciplines
From baseline assessment through to active threat operations, we cover the full security lifecycle for regulated firms.
Understand where you stand before you build. Honest, expert-led visibility into your gaps and risk exposure.
Turn findings into working programmes. We design the processes, policies, and controls your business actually needs.
Ongoing strategic security leadership without the cost of a full-time hire. Protected, compliant, and ahead.
Active security operations, from attack surface management to red team coordination. We test your defences before your adversaries do.
Structured, methodology-driven threat analysis. We map what attackers would target, how they'd reach it, and the business impact of each scenario.
Continuous surveillance of criminal forums, paste sites, and breach markets. Know when your data, credentials, or brand appear, before the damage is done.
About Us
Penthropic Security is a boutique cyber consultancy focused on one thing: helping regulated and fast-growing businesses build security programmes that actually work under scrutiny.
We work with fintechs, SaaS companies, media firms, and PE-backed businesses that need expert security leadership, without the overhead of a full in-house team.
Our approach is outcome-driven. We don't sell days, we sell results: audit-ready programmes, functioning risk processes, and security strategies your board can get behind.
Project pricing
Project work is scoped and priced upfront. The vCISO retainer below is monthly. Bespoke programmes available, get in touch.
A rapid review of your current third-party risk posture with actionable findings and prioritised recommendations.
A comprehensive assessment of your security programme against the NIST Cybersecurity Framework with a full remediation plan.
An intensive 1-week structured threat modelling exercise using STRIDE and MITRE ATT&CK, producing actionable attack path documentation.
Scoped offensive and defensive operations, attack surface review, pen test management, threat hunting, and purple team exercises.
Ongoing strategic security leadership. Your dedicated vCISO attends meetings, advises your team, and keeps you audit-ready.
Continuous monitoring of criminal markets, breach databases, and paste sites for your domains, credentials, and executive profiles.
All engagements are fixed-fee and scoped upfront. Operational tooling lives on the platform page, bespoke programmes available, get in touch.
Advisory FAQ
Still unsure? Drop us a message, we reply fast.
Probably not yet. Most mid-sized firms can't justify a full-time CISO at £120k, £180k all-in. A fractional vCISO gives you the same strategic expertise, board reporting, vendor oversight, incident response advisory, at typically 10–20% of the cost of a hire. We'll be honest with you on the discovery call about whether you've grown past needing fractional and into needing a permanent hire.
Our sweet spot is 30–300 employees, precisely because firms this size face real regulatory and customer scrutiny but can't absorb a full security function. If you're smaller, a one-off assessment might be all you need. We'll tell you honestly what's proportionate; we'd rather lose a sale than push you into a programme you don't yet need.
A standard audit looks at your own internal controls. Third-party risk management (TPRM) is about the risk your suppliers and partners introduce to your business. Under DORA, FCA guidelines, and most enterprise procurement requirements, both matter, but TPRM is the gap most firms have. We design TPRM operating models that are actually run, not the questionnaire-and-shelf model.
Typically within 1–2 weeks of a signed engagement. If you have an urgent audit or deadline, FCA, DORA, customer security review, or insurer demand, contact us directly; we've mobilised in under a week for clients with pressing timelines.
Kick-off call, document review and stakeholder interviews, findings analysis, then a structured output, report, risk register, or programme design depending on the engagement. We work remotely with occasional on-site visits and give weekly status updates throughout. You'll have a named lead, a Slack channel (or Teams if you prefer), and a fixed end date.
Yes, always. We operate under mutual NDA and provide a DPA as standard. We carry Professional Indemnity insurance, follow our own information security policies on every engagement, and can sign your supplier security questionnaire ahead of kickoff if your procurement requires it.
Yes. Advisory engagements (NIST, TPRM, vCISO, threat modelling) stand on their own, you can take the report and walk away. The platform is there if you want continuous operations after the project, but it's never a condition of working with us.
Get in Touch
Whether you're preparing for an audit, designing a TPRM programme, or looking for ongoing security leadership, we'd love to help.