Skip to main content
Good Security

Pricing

Good Security isn't expensive. Bad security is

Choose the level of structure, reporting, and evidence the business needs now. Start where it fits and step up when the demands change.

Choose your level

Pick the tier that fits the business today.

Most businesses start with Baseline, then step up only when scrutiny, reporting load, or board expectations get heavier.

Baseline

Foundation

Security baseline

$1,750 /mo


The first credible answer when the business needs structure, named owners, and usable evidence fast.

Best when the business wants a practical baseline in place without jumping straight to the heavier tiers.

See inclusions
  • Baseline review, roadmap, and first priorities in the opening month
  • Core policies, response plans, and a reporting rhythm leadership can use

Assurance

Evidence & Compliance

Evidence and compliance

$3,500 /mo


The tier for buyers, insurers, privacy questions, and audit pressure that is already real.

Best when the business needs faster evidence and broader delivery support under live scrutiny.

See inclusions
  • Questionnaire, audit, insurer, privacy, and supplier pressure support
  • Broader monthly delivery once the business is already being tested

Leadership

Fractional CISO

Fractional CISO

$8,500 /mo


The higher-touch tier for leadership teams that need stronger ownership, reporting, and pace.

Best when the business needs board-ready governance, a steadier operating rhythm, and a faster decision path.

See inclusions
  • Board and executive rhythm with deeper strategic guidance
  • Priority delivery, continuous review, and ongoing security leadership

Funding help

The NZTE Capability Development Voucher can cover up to $2,500 of your first security assessment.

See the Foundations Pack

Compare the tiers in full

See exactly what expands between Baseline, Assurance, and Leadership.

Open this when you want the line-by-line scope before you choose how much structure the business needs now.

Open comparison

Security Baseline Assessment

Baseline Full assessment at onboarding plus annual refresh
Assurance Full assessment at onboarding plus annual refresh
Leadership Full assessment at onboarding plus annual refresh

Cyber Insurance Readiness Assessment

Baseline Basic readiness assessment
Assurance Full assessment plus pre-completed insurer questionnaires
Leadership Full assessment plus pre-completed insurer questionnaires

Monthly Security Posture Report

Baseline Standard monthly report
Assurance Standard monthly report
Leadership Enhanced monthly report with trend analysis

Quarterly Security Scorecard

Baseline Standard quarterly scorecard
Assurance Enhanced scorecard with compliance tracking
Leadership Full scorecard with compliance tracking and benchmarking

Annual Security Report

Baseline Standard annual report
Assurance Enhanced report with board narrative
Leadership Board-ready report with narrative and strategic roadmap

Information Asset Register

Baseline Basic register with annual review
Assurance Living register with quarterly reviews
Leadership Living register with continuous updates and quarterly reviews

Personal Data Inventory

Baseline Basic inventory for IPP 3A compliance
Assurance Full inventory with data flow mapping
Leadership Complete inventory with data flow mapping and continuous updates

Privacy Breach Readiness Report

Baseline Basic readiness report with templates
Assurance Full readiness report plus tabletop exercise
Leadership Full readiness report plus tabletop exercise with enhanced scenarios

Incident Response Plan Suite

Baseline Core 5 response plans
Assurance Full 10-plan suite
Leadership Full 10+ plan suite with custom scenarios

Policy Suite & Lifecycle Management

Baseline Core 8-policy suite with annual review
Assurance Full 12+ policy suite with lifecycle management
Leadership Full 12+ policy suite with continuous lifecycle management

Annual Security Posture Review

Baseline 60-minute annual review call
Assurance 60-minute annual review call
Leadership 60-minute annual review call

Government Standards Gap Assessment

Baseline
Assurance Single framework gap assessment
Leadership Multi-framework gap assessment

Third-Party / Vendor Risk Register

Baseline
Assurance Standard register with annual assessments
Leadership Full register with continuous monitoring

Privacy Impact Assessment

Baseline
Assurance Up to 6 assessments per year with 3-business-day turnaround
Leadership Unlimited assessments with 3-business-day turnaround

Security Questionnaire Response Engine

Baseline
Assurance Up to 8 questionnaire responses per year with 3-business-day turnaround
Leadership Unlimited questionnaire responses with 3-business-day turnaround

Audit Readiness Score & Evidence Compiler

Baseline
Assurance Primary framework audit readiness
Leadership Multi-framework audit readiness

Customer Requirements Register

Baseline
Assurance Requirements tracking plus annual impact assessments
Leadership Full tracking with continuous impact assessments

Multi-Standard Compliance Mapping

Baseline
Assurance Dual-framework control mapping
Leadership Multi-framework control mapping

Incident Management Assistant

Baseline
Assurance 2 hours per month with quarterly rollover (max 8 banked)
Leadership 8 hours per month with quarterly rollover (max 24 banked)

Security Awareness Programme Design

Baseline
Assurance Annual programme design plus quarterly review
Leadership Annual programme design with quarterly reviews and ongoing refinement

Risk Management Framework

Baseline
Assurance Full framework plus annual review
Leadership Full framework with continuous review and enhancement

Audit Finding & Corrective Action Tracking

Baseline
Assurance
Leadership Full finding tracking and corrective action management

Board Advisory & Governance Reporting

Baseline
Assurance
Leadership Full board advisory and governance reporting included

AI Governance Programme

Baseline
Assurance
Leadership Full AI governance programme included

See what the first 90 days look like

Know how the work lands once you say yes.

Open this when you want the month-by-month view instead of wondering how quickly the business gets usable output.

Open rollout

What changes first

The early work is about reducing drag quickly, not creating another long setup project.

The first few months get the business organised, put evidence in one place, and establish a reporting rhythm leadership can actually use.

1

Week 1-2

Onboarding and discovery

Scoping call, team introductions, current-state review, and document collection.

2

Week 2-4

Baseline assessment

Review of where your security stands, gap analysis, prioritised risks, and the first written report.

3

Month 2

Programme build

Priority policies, incident structure, evidence register, and the first working controls.

4

Month 3+

Operating rhythm

Monthly reporting, ongoing oversight, and leadership review at a predictable cadence.

Need a smaller starting option?

Use one-off work when one urgent pressure needs answering first.

Open this when you need one urgent fix, one extra layer, or a smaller entry point before a broader monthly programme.

Open options

Smaller starting options

Use these when the business needs one clear answer before committing to a broader cadence.

These options work when you need one urgent answer, one extra layer, or one visible gap fixed before stepping into a broader monthly programme.

Leadership already includes deeper governance, broader incident capacity, and AI-governance coverage. These add-ons mostly matter for Baseline or Assurance customers that need one extra layer without a full tier jump.

Entry-point work

One-time engagement

NZTE Security Foundations Pack

Government-funded security foundations for NZ businesses. NZTE Capability Development Voucher covers $2,500 of the $5,000 cost. Credit of $2,500 applies against first 2 months of Baseline if client converts — making the Foundations Pack effectively free.

$5,000 to $5,000

  • Security Baseline Assessment with domain scoring, gap analysis, and prioritised roadmap (SVC-01)
  • 7 Core Policies: Information Security, Acceptable Use, Access Management, Incident Response, Data Handling, Backup & Recovery, Patch Management (SVC-20)
  • Personal Data Inventory with data flow mapping (SVC-08)
  • 2 Incident Response Plans: Ransomware, Phishing and email fraud
  • 90-minute Capability Workshop — walk through deliverables, build understanding, transfer capability

One-time engagement

Privacy Notification Sprint

Focused on IPP 3A indirect collection notification obligations before May 2026 deadline. Maps personal data, assesses privacy impacts, delivers compliance roadmap.

$3,500 to $5,500

  • Personal data inventory with data flow mapping
  • Privacy impact assessment for key processing activities
  • Gap analysis against IPP 3A notification requirements
  • Prioritised improvement roadmap
  • Transition pathway to ongoing Baseline or Assurance engagement

One-time engagement

Cross-Border Sprint

Focused on IPP 12 cross-border disclosure obligations. Audits international data flows, evaluates Section 11 agent exception for cloud services, ensures compliant disclosure.

$3,000 to $5,000

  • Cross-border data flow audit and disclosure inventory
  • Section 11 agent exception assessment for cloud services
  • Gap analysis against IPP 12 cross-border disclosure requirements
  • Privacy breach notification process template
  • Transition pathway to ongoing Baseline or Assurance engagement

Add-ons

Add-on

Board Advisory & Governance Reporting

$1,000 /mo

Board-level security reporting and advisory sessions for organisations that need governance visibility without the full Leadership tier.

Available with

Assurance

Add-on

AI Governance Advisory (ISO 42001-aligned)

$1,500 /mo

Practical AI governance support for organisations deploying or procuring AI-enabled systems, aligned to ISO 42001.

Available with

Baseline, Assurance

Add-on

Enhanced Incident Response Retainer

$1,000 /mo

Additional incident management hours and priority response for organisations that need more capacity beyond their tier allocation.

Available with

Baseline, Assurance

Add-on

NZ-Only Processing

$500 /mo

For organisations with strict data residency obligations. Every analysis, report, and deliverable runs entirely on private New Zealand infrastructure, with no ambiguity about where client data is processed.

Available with

Baseline, Assurance, Leadership

Add-on

Additional Expert Hours

$350 /hr

On-demand access to senior security expertise for ad-hoc projects, workshops, or advisory sessions beyond your tier inclusions.

Available with

Baseline, Assurance, Leadership

Add-on

Annual Pen Test Coordination

$2,000 /yr

Annual coordination for one penetration testing engagement, including vendor selection, scoping, scheduling, and findings review.

Available with

Baseline, Assurance, Leadership

FAQ

Questions owners usually ask before they commit.

How do I choose the right tier?

Choose based on the scrutiny the business is under. Baseline is the usual starting point when the business needs a credible first programme. Assurance fits customer, insurer, or privacy obligations that are already active. Leadership is for organisations that need deeper ownership, board-ready governance, and a higher-touch advisory cadence.

Can we start small and move up later?

Yes. Most businesses start at the level that fits now and step up only when the scrutiny, customer base, or reporting expectations change.

Do we need an MSP as well?

Usually yes. A managed IT provider (MSP) runs systems. Good Security gives the business governance, reporting, evidence, privacy, and security leadership that most MSPs do not own.

How do we size your programme?

We start by understanding your current exposure — whether that's customer questionnaires, insurance renewals, leadership expectations, or all three. The tier you start on reflects the breadth and depth of work needed, not a rigid package. Most businesses start at Baseline and step up only when the scrutiny, reporting load, or governance expectations justify it.

Ready to work out which tier fits?

Book a free consultation and leave with a clear starting point, likely first steps, and the right level of programme.

"Delivers on his promises — completed to a high standard, within budget, and by the agreed deadline." — Marko Blagojevic, Information Services Manager