Pricing

Commercial models designed to fit security operating needs — published in GBP and USD.

Cyberzonic publishes indicative entry points so enterprise buyers can shortlist without a sales call. Final pricing is always shaped to the real environment during scoping — these numbers are starting points, not menu prices.

GBP rates apply to UK and EU clients. USD rates apply to US, Canadian, and international clients invoiced in dollars. All pricing is exclusive of VAT where applicable.

Retained Engagement

Monthly retained models for organisations with continuous security pressure.

Foundation

Scoped after discovery

Confirmed in proposal

For organisations establishing better visibility, baseline governance, and senior advisory access without standing up a large internal security function.

Best for

Smaller or earlier-stage operating models, pre-Series B SaaS, regulated start-ups, single-region SMEs.

What is included

  • Senior security advisory hours each month
  • Baseline Microsoft Sentinel / Defender posture monitoring
  • Quarterly posture review with written report
  • Incident triage support during business hours (Europe/London)
  • Direct line to a named senior practitioner — not a ticket queue

Not included

  • Extended-hours monitoring unless explicitly scoped
  • Bespoke detection engineering programmes

Operational

Most common

Scoped after discovery

Confirmed in proposal

For organisations needing recurring depth around monitoring, detection engineering, assurance, and structured security delivery — where security pressure is persistent rather than occasional.

Best for

Mid-market and regulated environments, fintech and healthtech, multi-region SaaS, organisations preparing for ISO 27001 or SOC 2.

What is included

  • Active Sentinel detection engineering and tuning sprints
  • Defender suite (MDE / MDI / MDO / MDC) posture management
  • Entra ID and Conditional Access hardening cycles
  • Monthly executive readout with metrics that drive decisions
  • Incident response support with a defined service response model and escalation path
  • Runbook and evidence-pack maintenance for assurance reviews

Enterprise

Tailored to the operating model

Confirmed in proposal

For larger or more complex organisations needing a blended programme across architecture, governance, assurance, response, and capability design — shaped to the estate, not the price list.

Best for

Regulated, distributed, or high-change environments. Financial services, healthcare groups, public sector, and global SaaS.

What is included

  • Embedded senior security leadership (vCISO / Head of Security cover)
  • Multi-workstream programme delivery against a written charter
  • Architecture, detection, governance, and response in one engagement
  • Board-level reporting cadence with regulator-grade evidence
  • Defined transformation milestones and exit criteria
  • Optional extended-hours incident response model, defined in scope

Fixed-Scope Engagements

One-off engagements with a defined scope, timeline, and outcome.

Indicative entry points for the most common standalone engagements. Larger or more complex scopes are priced after a scoping call.

Cloud Security Posture Review

Scope-dependent

Scoped

Confirmed in proposal

Microsoft cloud posture assessment with prioritised gap backlog, evidence pack, and remediation roadmap aligned to MCSB and CIS.

Microsoft Sentinel Deployment

Scope-dependent

Scoped

Confirmed in proposal

Production-ready Sentinel workspace with data connectors, tuned analytics, SOAR playbooks, runbooks, and operator handover.

ISO 27001 Readiness Programme

Scope-dependent

Scoped

Confirmed in proposal

Gap analysis, control implementation plan, evidence pack, and audit-readiness review against ISO/IEC 27001:2022.

Identity & Conditional Access Hardening

Scope-dependent

Scoped

Confirmed in proposal

Entra ID hardening, Conditional Access redesign, PIM rollout, and identity governance baselines with documented decisions.

Incident Response Readiness + Tabletop

Scope-dependent

Scoped

Confirmed in proposal

IR plan review, runbook refresh, and a leadership tabletop exercise with written lessons and follow-up actions.

Penetration Test (Web / Cloud / Internal)

Scope-dependent

Scoped

Confirmed in proposal

Scoped offensive assessment with prioritised findings, remediation guidance, and a retest window.

Commercial Principles

How CYBERZONIC LIMITED shapes the commercial model — every engagement, every tier.

Scope before delivery

Every engagement starts with a written scope brief and exit criteria. We will not commit to delivery against a vague ask.

Outcomes over hours

Pricing is shaped around the outcome the client needs, not a daily rate sheet. Where time-and-materials is the right shape, we say so.

No hidden mark-ups

Third-party costs (Microsoft licensing, scanning tools, threat intel feeds) are passed through at cost. We do not stack hidden margin.

Honest pacing

If the ask is unrealistic for the window, we say so before contracts are signed — not three months in.

Shape the commercial model

A short scoping call is the fastest way to confirm which model fits your environment.

Bring us the pressure point. We will come back with a shaped proposal — not a template.