Ready to scope an engagement?
Book a Discovery CallAdvisory · London
Fixed-fee assessments, third-party risk design, threat modelling sprints and fractional vCISO. A consultant writes a report and leaves. Here the work can land in a platform that carries on testing it, so a control that regresses raises a finding instead of waiting for next year's review.
The handover
Every advisory engagement here stands on its own. You can take the report and walk away, and plenty of clients should. If you run the Penthropic platform as well, the findings go into the same Risk Register the platform works from, and the checks behind them keep running.
A finding written in March is a claim about March. A finding the platform re-tests is a claim about today.
How an engagement runs
No lengthy procurement and no retainer surprises. A straight path from where you are to where you need to be, with a named lead and a fixed end date.
Thirty minutes. We listen first, work out what you are actually being asked to prove, and say honestly whether we are the right people for it.
Free · No obligationA fixed-fee proposal with the deliverables, the dates and the outputs written down. Nothing starts, and nothing is billed, until you approve the scope and the fee.
Your approval · The gateWeekly status, a named lead and a shared channel. Practical outputs your team can work from, not a 200 page report that sits on a shelf.
Fixed scope · Fixed end dateOptional in every direction. Fractional vCISO, quarterly reviews, vendor oversight, or the platform carrying the findings forward. None of it is a condition of the first engagement.
Optional · FlexibleAdvisory disciplines
From a baseline assessment through to active threat operations. Each one is scoped and priced on its own, and each one produces something the platform can keep checking if you want it to.
Understand where you stand before you build. Expert-led visibility into the gaps and the exposure, written so an auditor and a board can both read it.
Turn findings into working programmes. We design the processes, policies and controls the business will actually run, not the ones that read well in a binder.
Strategic security leadership without the cost of a full-time hire. A named person who turns up, owns the roadmap and answers to your board.
Active security operations, from attack surface management to red team coordination. We test your defences before somebody else does.
Structured, methodology-driven threat analysis. We map what an attacker would target, how they would reach it, and what each scenario costs the business.
Continuous watch on criminal forums, paste sites and breach markets. Know when your data, your credentials or your brand appear, and what to do about it.
The practice
Penthropic Security is a boutique London practice with one job: helping regulated and fast-growing businesses build security programmes that hold up when somebody checks them.
We work with fintechs, SaaS companies, media firms and PE-backed businesses that need expert security leadership without the overhead of a full in-house team.
We do not sell days. We sell the outputs: an audit-ready programme, a risk process people actually run, and a strategy written in the terms a board reads. Then, if you want it, a platform that keeps testing all three.
Project pricing
Project work is scoped and priced upfront. The vCISO retainer below is monthly. Bespoke programmes available, get in touch.
£5,000
A rapid review of your current third-party risk posture with actionable findings and prioritised recommendations.
£12,000
A comprehensive assessment of your security programme against the NIST Cybersecurity Framework with a full remediation plan.
£6,500
An intensive 1-week structured threat modelling exercise using STRIDE and MITRE ATT&CK, producing actionable attack path documentation.
From £8,500
Scoped offensive and defensive operations, attack surface review, pen test management, threat hunting, and purple team exercises.
From £3,000/mo
Ongoing strategic security leadership. Your dedicated vCISO attends meetings, advises your team, and keeps you audit-ready.
From £750/mo
Continuous monitoring of criminal markets, breach databases, and paste sites for your domains, credentials, and executive profiles.
All engagements are fixed-fee and scoped upfront. Operational tooling lives on the platform page, bespoke programmes available, get in touch.
Advisory FAQ
Still unsure? Drop us a message, we reply fast.
Probably not yet. Most mid-sized firms can't justify a full-time CISO at £120k, £180k all-in. A fractional vCISO gives you the same strategic expertise, board reporting, vendor oversight, incident response advisory, at typically 10–20% of the cost of a hire. We'll be honest with you on the discovery call about whether you've grown past needing fractional and into needing a permanent hire.
Our sweet spot is 30–300 employees, precisely because firms this size face real regulatory and customer scrutiny but can't absorb a full security function. If you're smaller, a one-off assessment might be all you need. We'll tell you honestly what's proportionate; we'd rather lose a sale than push you into a programme you don't yet need.
A standard audit looks at your own internal controls. Third-party risk management (TPRM) is about the risk your suppliers and partners introduce to your business. Under DORA, FCA guidelines, and most enterprise procurement requirements, both matter, but TPRM is the gap most firms have. We design TPRM operating models that are actually run, not the questionnaire-and-shelf model.
Typically within 1–2 weeks of a signed engagement. If you have an urgent audit or deadline, FCA, DORA, customer security review, or insurer demand, contact us directly; we've mobilised in under a week for clients with pressing timelines.
Kick-off call, document review and stakeholder interviews, findings analysis, then a structured output, report, risk register, or programme design depending on the engagement. We work remotely with occasional on-site visits and give weekly status updates throughout. You'll have a named lead, a Slack channel (or Teams if you prefer), and a fixed end date.
Yes, always. We operate under mutual NDA and provide a DPA as standard. We follow our own information security policies on every engagement, and can sign your supplier security questionnaire ahead of kickoff if your procurement requires it.
Yes. Advisory engagements (NIST, TPRM, vCISO, threat modelling) stand on their own, you can take the report and walk away. The platform is there if you want continuous operations after the project, but it's never a condition of working with us.
Get in touch
Whether you are preparing for an audit, designing a TPRM programme, or looking for ongoing security leadership, tell us what you are being asked to prove.