Skip to main content
Good Security

Pricing

Good Security isn't expensive. Bad security is

Choose the level of structure, reporting, and evidence the business needs now. Start where it fits and step up when the demands change.

Choose your level

Choose the level of support the business actually needs now

Most businesses start with Baseline, then step up only when scrutiny, reporting load, or board expectations get heavier.

Foundation

Baseline

$1,750 /mo


The first credible answer when the business needs structure, named owners, and usable evidence fast.

Best when the business wants a practical baseline in place without jumping straight to the heavier tiers.

  • Baseline review, roadmap, and first priorities in the opening month
  • Core policies, response plans, and a reporting rhythm leadership can use

Evidence & Compliance

Assurance

$3,500 /mo


The tier for buyers, insurers, privacy questions, and audit pressure that is already real.

Best when the business needs faster evidence and broader delivery support under live scrutiny.

  • Questionnaire, audit, insurer, privacy, and supplier pressure support
  • Broader monthly delivery once the business is already being tested

Compare the tiers in full

See exactly what expands between Baseline and Assurance.

Open this when you want the line-by-line scope before you choose how much structure the business needs now.

Open comparison

Security Baseline Assessment

Baseline Full assessment at onboarding plus annual refresh
Assurance Full assessment at onboarding plus annual refresh

Cyber Insurance Readiness Assessment

Baseline Basic readiness assessment
Assurance Full assessment plus pre-completed insurer questionnaires

Monthly Security Review

Baseline Standard monthly review and report
Assurance Standard monthly report

Quarterly Security Scorecard

Baseline Standard quarterly scorecard
Assurance Enhanced scorecard with compliance tracking

Annual Security Report

Baseline Standard annual report
Assurance Enhanced report with board narrative

Information Asset Register

Baseline Basic register with annual review
Assurance Living register with quarterly reviews

Personal Data Inventory

Baseline Basic inventory for IPP 3A compliance
Assurance Full inventory with data flow mapping

Privacy Breach Readiness Report

Baseline Basic readiness report with templates
Assurance Full readiness report plus a practice run of the response

Incident Response Plan Suite

Baseline Core 5 response plans
Assurance Full 10-plan suite

Policy Suite & Lifecycle Management

Baseline Core 8-policy suite with annual review
Assurance Full 12+ policy suite with lifecycle management

Annual Security Review

Baseline 60-minute annual review call
Assurance 60-minute annual review call

Government Standards Gap Assessment

Baseline
Assurance Gap assessment for one named standard

Third-Party / Vendor Risk Register

Baseline
Assurance Standard register with annual assessments

Privacy Impact Assessment

Baseline
Assurance Up to 6 assessments per year with 3-business-day turnaround

Security Questionnaire Response Engine

Baseline
Assurance Up to 8 questionnaire responses per year with 3-business-day turnaround

Audit Readiness Score & Evidence Compiler

Baseline
Assurance Main audit-readiness view

Customer Requirements Register

Baseline
Assurance Requirements tracking plus annual impact assessments

Multi-Standard Compliance Mapping

Baseline
Assurance Control mapping across two standards

Incident Management Assistant

Baseline
Assurance 2 hours per month with quarterly rollover (max 8 banked)

Security Awareness Plan

Baseline
Assurance Annual awareness plan plus quarterly review

Security Risk Register & Review

Baseline
Assurance Working risk register plus annual review

See what the first 90 days look like

Know how the work lands once you say yes.

Open this when you want the month-by-month view instead of wondering how quickly the business gets usable output.

Open rollout

What changes first

The early work is about reducing drag quickly, not creating another long setup project.

The first few months get the business organised, put evidence in one place, and establish a reporting rhythm leadership can actually use.

1

Week 1-2

Onboarding and discovery

Scoping call, team introductions, current-state review, and document collection.

2

Week 2-4

Baseline assessment

Review of where your security stands, gap analysis, prioritised risks, and the first written report.

3

Month 2

Core setup

Priority policies, incident structure, evidence register, and the first working controls.

4

Month 3+

Operating rhythm

Monthly reporting, ongoing oversight, and leadership review at a predictable cadence.

Need a smaller starting option?

Use one-off work when one urgent pressure needs answering first.

Open this when you need one urgent fix, one extra layer, or a smaller entry point before a broader monthly cadence.

Open options

Smaller starting options

Use these when the business needs one clear answer before committing to a broader cadence.

These options work when you need one urgent answer, one extra layer, or one visible gap fixed before stepping into broader monthly support.

How to use this section

Start with one-off work when a single buyer, insurer, privacy, or audit question needs an immediate answer. Add-ons are there when Baseline or Assurance already fits and you only need one extra layer without a full tier jump.

Entry-point work

One-time engagement

Privacy Notification Sprint

Focused on IPP 3A indirect collection notification obligations before May 2026 deadline. Maps personal data, assesses privacy impacts, delivers compliance roadmap.

$3,500 to $5,500

  • Personal data inventory with data flow mapping
  • Privacy impact assessment for key processing activities
  • Gap analysis against IPP 3A notification requirements
  • Prioritised improvement roadmap
  • Transition pathway to ongoing Baseline or Assurance engagement

One-time engagement

Cross-Border Sprint

Focused on IPP 12 cross-border disclosure obligations. Audits international data flows, evaluates the Section 11 agent exception for cloud services, and lands the business on a compliant disclosure footing.

$3,000 to $5,000

  • Cross-border data flow audit and disclosure inventory
  • Section 11 agent exception assessment for cloud services
  • Gap analysis against IPP 12 cross-border disclosure requirements
  • Privacy breach notification process template
  • Transition pathway to ongoing Baseline or Assurance engagement

Add-ons

Add-on

Enhanced Incident Response Retainer

$1,000/mo

Additional incident management hours and priority response for organisations that need more capacity beyond their tier allocation.

Available with

Baseline Assurance

Add-on

NZ-Only Processing

$500/mo

For organisations with strict data residency obligations. Every analysis, report, and deliverable runs entirely on private New Zealand infrastructure, with no ambiguity about where client data is processed.

Available with

Baseline Assurance

Add-on

Additional Expert Hours

$350/hr

On-demand access to senior security expertise for ad-hoc projects, workshops, or advisory sessions beyond your tier inclusions.

Available with

Baseline Assurance

Add-on

Annual Pen Test Coordination

$2,000/yr

Annual coordination for one penetration testing engagement, including vendor selection, scoping, scheduling, and findings review.

Available with

Baseline Assurance

FAQ

The questions owners usually ask before they commit.

Open the answers when you need the detail.

FAQ
How do I choose the right tier?

Choose based on the scrutiny the business is under. Baseline is the usual starting point when the business needs a credible first layer of structure. Assurance fits customer, insurer, or privacy obligations that are already active.

Can we start small and move up later?

Yes. Most businesses start at the level that fits now and step up only when the scrutiny, customer base, or reporting expectations change.

Do we need an MSP as well?

Usually yes. A managed IT provider (MSP) runs systems. Good Security gives the business governance, reporting, evidence, privacy, and security leadership that most MSPs do not own.

How do we size your support?

We start by understanding your current exposure — whether that's customer questionnaires, insurance renewals, leadership expectations, or all three. The tier you start on reflects the breadth and depth of work needed, not a rigid package. Most businesses start at Baseline and step up only when the scrutiny, reporting load, or governance expectations justify it.

Ready to work out which level fits?

Book a free consultation and leave with a clear starting point, likely first steps, and the right level of support.