published list floors · final fee set at scoping fixed fee, never hourly  ·  senior-only bench
§ Security pricing·Assess · Run · Private AI·v2026.09

Security services pricing, published.

DSE security services start at $1,250 for a scored Security Readiness Check, run from $3,500 a month for retained vCISO leadership, and start at $40,000 fixed for a Private AI Pilot deployed inside your own cloud account. Every figure below is a published list floor. The final fee is set at a scoping call and confirmed in writing before any work starts.

Three lanes, one ladder. Assess tells you where you stand. Run gives you a senior security leader on a fraction of a hire. Private AI puts a governed AI workspace inside your AWS account and keeps it operated. Most clients start on the left and move right only when the findings warrant it.

§ Read this first

What is fixed. vCISO Essentials is a flat monthly fee. Every other line carries a "from" price: the published floor for the smallest honest version of that engagement, one entity, one site, one environment. The floor is real; we do not quote below it.

What moves the number. Additional sites or entities, more users or AI systems in scope, an examined regulatory profile, and multi-environment deployments move a fee above its floor. The scoping call sets the final fee, in writing, before work starts. Nothing here is billed hourly. Readiness and advisory work is not certification and not legal advice.

§A
Assess.
Point-in-time, fixed fee.

Know where you stand before you spend.

Each Assess engagement is scoped to one entity and one site at its floor. They are advisory reviews of the evidence you already have and the controls you already run. None of them is a penetration test, and none of them certifies anything.

Assess

door-opener → foundations → ongoing training
Assess · door-opener

Security Readiness Check

from$1,250

Fit: small and mid-sized firms, roughly 10 to 150 staff, taking a first structured look. Metro-Atlanta clients can have this done in person.

Included
  • Scored one-to-two-day read across identity and MFA, email security, endpoints, backup and restore, and SaaS exposure
  • 30-day quick-wins list, ranked by risk and effort
  • Cyber-insurance questionnaire readiness notes
  • Short leadership readout, plain English
  • A written recommendation on whether a Foundations Assessment is warranted
Not included
  • Technical testing, remediation work, physical security

Term: one-time, fixed fee. Estimate vs fixed: $1,250 is the floor for one entity and one site; the scoping call confirms the fee in writing.

Scope a Readiness Check
Assess · foundations

Security Foundations Assessment

from$3,500

Fit: 25 to 250 staff handling client financial data, PHI, or contract-sensitive data, usually under insurer, customer, or regulator questionnaire pressure.

Included
  • Full cyber assessment mapped to NIST CSF 2.0 and the CIS Controls
  • Evidence review of identity, Microsoft 365 or Workspace hardening, and endpoint posture
  • Backup and recovery test worksheet, completed with your team
  • Vendor and SaaS inventory with a first-pass risk rating
  • Severity-ranked findings and a prioritized remediation roadmap
  • Leadership readout with the evidence register
Not included
  • Penetration testing, remediation execution
  • Physical security: delivered only through a licensed Georgia partner on a referral basis, contracted separately

Term: one-time, fixed fee, typically two to four weeks. Estimate vs fixed: $3,500 is the floor for the cyber component at one site; additional sites and any physical component are scoped separately.

Scope a Foundations Assessment
Assess · ongoing

Security Awareness Training

from$600 / mo

Fit: any firm that needs a documented, evidenced training program for insurers, clients, or a HIPAA or GLBA obligation. The floor covers up to 25 users.

Included
  • Monthly training modules with completion tracking
  • Simulated phishing on a set cadence, with results by group
  • Policy-acknowledgement tracking and exportable evidence
  • Onboarding path for new hires
  • Quarterly summary for leadership and insurers
Not included
  • Role-specific technical training, incident response

Term: monthly subscription; the term and the user band above 25 are set at scoping. Estimate vs fixed: $600 a month is the floor for up to 25 users.

Scope awareness training

Physical security is never delivered by DSE. Where a client needs it, we refer to a licensed Georgia security firm and coordinate the cyber and physical findings into one roadmap; the physical work is contracted with the partner directly.

§B
Run.
Retained vCISO leadership.

A senior security leader, on a fraction of a hire.

Every vCISO tier carries a six-month minimum and a one-time setup fee that covers the first-30-day baseline: risk register, policy inventory, and the evidence calendar. DSE directs the program; DSE does not operate a 24/7 SOC or MDR, and continuous monitoring, where required, runs through a vetted partner you contract.

Run: vCISO tiers

6-month minimum + one-time setup fee on every tier
Run · essentials

vCISO Essentials

$3,500 / mo

Fit: 25 to 150 staff, no in-house security lead, building a first security program that a client or insurer will ask to see.

Included
  • Monthly leadership cadence and a named escalation point
  • Risk register ownership and a maintained policy set
  • Light-touch vendor review for new tools
  • Quarterly leadership report
  • Cyber-insurance and customer questionnaire support
  • Advisory incident escalation during business hours
Not included
  • 24/7 monitoring, hands-on remediation engineering, tooling licences

Term: flat $3,500 a month, six-month minimum, plus a one-time setup fee. Estimate vs fixed: the monthly fee is fixed; only the setup fee is set at scoping.

Scope vCISO Essentials
Run · core

vCISO Core

from$5,500 / mo

Fit: 100 to 500 staff under GLBA, HIPAA, or state privacy obligations, with AI already in use and a board or owner that wants reporting.

Included
  • Everything in Essentials
  • AI risk register and AI vendor reviews alongside the conventional register
  • Board or owner reporting on a quarterly cadence
  • Compliance evidence calendar mapped to your framework
  • One tabletop exercise a year, facilitated
  • Remediation oversight and MDR or MSP partner orchestration
Not included
  • Operating the SOC or MDR itself, examination representation

Term: six-month minimum plus a one-time setup fee. Estimate vs fixed: $5,500 a month is the floor for one entity; system count and regulatory surface set the final fee at scoping.

Scope vCISO Core
Run · regulated

vCISO Regulated

from$9,000 / mo

Fit: examined entities: banks, credit unions, RIAs and broker-dealers, insurers, healthcare systems, and defense suppliers, often multi-entity, usually 250+ staff.

Included
  • Everything in Core
  • Examination and audit support: evidence assembly and reviewer walkthroughs
  • Regulatory crosswalk kept current as guidance changes
  • Third-party risk program, not just point reviews
  • Model and AI governance liaison with your risk function
  • Advisory incident leadership across multiple business units
Not included
  • Legal advice, examination outcomes, certification of any kind

Term: six-month minimum plus a one-time setup fee. Estimate vs fixed: $9,000 a month is the floor for one examined entity; entity count and examination cadence set the final fee at scoping.

Scope vCISO Regulated

Looking for AI-program-only leadership? The narrower vCISO for AI retainer is scoped separately from $6,000 a month. The tiers above run the whole security program, with AI risk inside it.

§C
Private AI.
Deployed in your cloud account.

A governed AI workspace, inside your AWS account.

Private AI engagements deploy PrivateStack, DSE's governed AI workspace built on open-weight models, or an equivalent reference stack, inside a customer-owned AWS account and VPC under customer-managed keys. Under that Enterprise BYOC deployment, prompts, completions, retrieval documents, and audit logs remain in your VPC; control-plane metadata is the documented exception. The BYOC boundary map spells out every data path.

Private AI

pilot → foundation → managed operations
Private AI · pilot

Private AI Pilot

from$40,000

Fit: one high-value workflow on sensitive data, one team, one environment. The right first buy when the hosting boundary is the blocker.

Included
  • Architecture brief: data flows, hosting pattern, access and logging design
  • Single-environment deployment inside your AWS account through a least-privilege assumed role
  • IAM, KMS, network egress, and audit-logging baseline
  • One workflow and one document corpus wired for retrieval
  • Security testing against AI-specific failure modes before launch
  • Evidence package and a handoff runbook
Not included
  • Multi-environment builds, model training or fine-tuning, ongoing operations

Term: fixed fee, typically six to ten weeks. Estimate vs fixed: $40,000 is the floor for one environment and one workflow; the architecture review sets the final fee in writing.

Scope a Private AI Pilot
Private AI · foundation

Private AI Foundation

from$75,000

Fit: several workflows across several teams, regulated data, and a reviewer, auditor, or examiner who will ask for the control path.

Included
  • Everything in the Pilot
  • Separate development and production environments
  • SSO integration and role design across teams
  • Retrieval over multiple corpora with per-corpus access control
  • Change control on models and prompts, monitoring design, backup and restore
  • Controls mapped to your framework with a reviewer-facing evidence package
Not included
  • Ongoing operations, examination representation, model training

Term: fixed fee, scoped to the estate. Estimate vs fixed: $75,000 is the floor for two environments and a handful of workflows; larger estates route to custom pricing.

Scope a Private AI Foundation
Private AI · operations

Private AI Managed Ops

from$8,000 / mo

Fit: a private AI system already in production that needs to stay patched, tested, and evidenced without a dedicated internal team.

Included
  • Monitoring of the deployment and its control paths
  • Upgrades through the documented mechanism, version-pinned, with rollback
  • Model and vendor change review before anything ships
  • Re-testing cadence against AI-specific failure modes
  • Evidence upkeep and a quarterly operations report
  • Break-glass support access, requested per incident and logged in your account
Not included
  • 24/7 SOC or MDR, cloud infrastructure costs, new feature builds

Term: 12-month minimum. Estimate vs fixed: $8,000 a month is the floor for one production environment; environment and workflow count set the final fee at scoping.

Scope managed operations

The product path: PrivateStack is the governed AI workspace these engagements deploy. Its Hosted and Solo tiers run on DSE-managed infrastructure and do not inherit the BYOC residency posture described here.

§D
Custom pricing.
When a floor is the wrong frame.

When to ask for custom pricing.

The floors above are honest for the smallest version of each engagement. Some work is simply bigger than the ladder, and pretending otherwise wastes a call.

Ask for a custom scope if any of these is true.

  • More than one legal entity, regulator, or examination cycle is in scope
  • You need a private AI estate beyond two environments, or across more than one AWS account
  • Retained leadership has to cover more than one business unit with its own risk register
  • A federal or defense program needs a NIST RMF, ATO, or CMMC-aware delivery path
  • You want a bundled Assess, Run, and Private AI program on one engagement letter
  • Procurement requires a fixed multi-year price or a specific contract vehicle

What happens next

A principal reads the request, replies within 24 hours with fit or not-fit, and, if it is a fit, sends a fixed-fee scope document within 48 hours of the scoping call. Enterprise work is priced to the estate, in writing, before anything starts.

Request custom pricing
§F
Common questions.
Before you book a call.

Pricing questions, answered.

Straight answers on why the numbers read "from", what moves them, and how an engagement actually gets signed.

Why do most prices say "from"?

Because the floor is the only number we can publish honestly without seeing your environment. Each "from" price is the fee for the smallest complete version of that engagement: one entity, one site, one environment. We do not quote below it, and we do not pad above it without a reason we can show you.

What changes the price?

Four things, in roughly this order: scope units (sites, entities, environments, AI systems), regulatory profile (an examined entity needs more evidence than an unregulated one), user or workflow count for the per-month lines, and delivery constraints such as in-person requirements or a procurement vehicle. None of them is headcount for its own sake.

Is the fee fixed once we scope it?

Yes. The scoping call produces a written scope with one fixed fee. Nothing is billed hourly. If the scope changes mid-engagement, the change is priced and agreed in writing before the work continues.

How does the engagement letter work?

Engagement letters are issued only after our counsel-reviewed terms and errors-and-omissions coverage are in force for the scope. That is a standing gate on signing and delivery, not on scoping: you can scope, receive a fixed-fee proposal, and reserve a start window before it clears. We will tell you plainly where a given scope stands.

How does this page relate to the engagement-models page?

The engagement models page carries non-binding market-estimate ranges for the AI governance, implementation, and data catalogue. This page carries published list floors for the security service line. Where both mention private AI, this page's floors are the ones we quote from.

Do you deliver physical security or run a SOC?

No to both. Physical security is referred to a licensed Georgia partner and contracted with them directly. Continuous monitoring runs through a vetted MDR or MSP partner you contract; DSE directs the program and reviews the evidence but does not operate a 24/7 SOC.

§ What this is, and is not·readiness and advisory work

Prepared for review. Not a certification.