Security & Compliance

Cybersecurity Consulting: What It Covers and What It Costs

13 min read

A cybersecurity consultant tells you where you’re exposed, ranks the gaps by how much they’d actually cost you, and hands you a plan to close them in priority order. That’s the whole job, stripped of jargon. In practice it shows up as a handful of engagement types: a risk assessment, a gap analysis against a framework like NIST CSF or the CIS Controls, a security architecture review, fractional security leadership (a vCISO), and incident-response planning. The money sorts into three shapes: a one-off project, a monthly retainer, or vCISO leadership. A small-company risk assessment runs about $15K to $25K; a vCISO retainer runs $3,000 to $20,000 a month.

We’re gmware, a custom software development firm headquartered in Austin, TX with engineering centers in Bangalore and Mohali, India. We run production data systems ourselves, including Shield Suite, our retail-intelligence platform tracking 60,000+ beverage-alcohol storefronts, so security architecture and access control aren’t theory to us. This post covers what each engagement type delivers, what each one costs with sourced ranges, an original matrix for matching the engagement to your situation, and the honest fork most buyers miss: when you actually need a managed security provider or just baseline hygiene instead of a consultant.

What a cybersecurity consultant actually delivers

Most of the confusion about cybersecurity consulting comes from treating it as one product. It isn’t. It’s a small set of engagements that answer different questions, and a good consultant tells you which one you need rather than selling you all of them.

A risk assessment is the usual front door. The consultant interviews your people, reviews your systems and policies, looks at how data flows and who can touch it, and produces a ranked list of where you’re exposed plus a roadmap to close it. A gap analysis is that same exercise pointed at a specific framework: here’s what NIST CSF or CIS expects, here’s what you’ve got, here’s the delta. Framework alignment is the longer program of actually closing that delta and being able to prove you did. A security architecture review looks at how one system is built, where the trust boundaries sit, and where an attacker would pivot once they’re inside. Incident-response planning writes the runbook for the bad day. Who declares an incident, who calls the lawyer, who talks to customers, in what order. And a vCISO, a virtual or fractional Chief Information Security Officer, is part-time senior leadership that owns the whole program, reports to your board, and herds the auditors and vendors.

Notice what isn’t on that list: running your firewalls, watching your alerts at 2am, patching servers. That’s operations, and it’s usually somebody else’s job. A consultant points; an operator does. Keeping that line clear is the single biggest favor you can do your budget.

What cybersecurity consulting costs in 2026

Pricing tracks the engagement shape, not a single rate card. Here are the three shapes with sourced ranges.

EngagementWhat you getTypical costBest for
One-off risk assessment / gap analysisRanked exposure list, framework gap map, remediation roadmap$15K to $25K small co.; $20K to $35K mid-marketA starting point, a renewal, or a buyer/insurer asking
Monthly vCISO retainerPart-time security leadership: strategy, framework work, board reporting, audit coordination$3K to $20K a monthOngoing need, no full-time CISO budget
On-demand / hourlyTargeted advice, a policy rebuild, a single review$200 to $400 an hourA specific question, not a program

The retainer band is wide for a reason. Advisory-only engagements start around $3K to $5K a month for a few hours of strategy and a quarterly review. A standard retainer with real hands-on hours sits in the middle, roughly $5K to $9K. Compliance-heavy work, where the vCISO is also driving a SOC 2 or HIPAA effort and managing an auditor, pushes toward the top of the range. The lever is hours and how much execution you want, not some fixed seniority premium.

The math behind the vCISO model is straightforward. A full-time CISO costs $250K to $700K a year in total compensation, and most mid-market companies don’t have a full-time CISO’s worth of decisions to make. A fractional one gives you the title, the strategy, and the buyer-facing credibility for a fraction of that, which is the entire pitch.

One line that lives outside all of these: remediation. The assessment tells you what’s broken; fixing it (rolling out MFA, cleaning up identity, building logging, hardening cloud) is separate work and usually the larger spend. Any consultant who quotes an assessment without flagging that the remediation bill comes next is setting up an unpleasant month two. We say it on the first call because we’d rather lose the work than surprise you.

How cybersecurity consulting differs from a penetration test

This is the most common mix-up, and it costs people money. A penetration test is a single technical assessment: ethical hackers try to break into a defined target, an app, a network, a cloud account, and report exactly what worked and how. It’s narrow, deep, and point-in-time. It answers one question well: can someone get in through this thing, right now?

Cybersecurity consulting is the advisory layer around that. It’s wider and shallower per item, covering risk across the whole organization, governance, framework alignment, and what to prioritize. A pen test finds the unlocked window. Consulting tells you that you’ve been spending on alarm sensors while leaving the back door unlocked, and which to fix first given a finite budget.

You usually want both, in order: consulting to figure out where to look and what matters, then a pen test to prove the specific defenses hold. Buying a pen test with no program around it is like getting one window checked while the rest of the house is uninspected. For what that single test costs, a small-company pen test runs about $3K to $15K, and it’s a line inside a larger program, not a substitute for one.

How it differs from a SOC 2 or cyber-insurance certification

A compliance certification is a buyer-facing or insurer-facing attestation: proof, verified by a third party, that you run the controls you claim to. A SOC 2 report exists so your enterprise customers can skip interrogating you one questionnaire at a time. A cyber-insurance application exists so a carrier will write you a policy. Both are about producing a document somebody else demands.

Consulting is the work that gets you to a passable state in the first place. The relationship is sequential: a consultant runs the gap analysis, drives the remediation, and prepares the evidence; then a licensed auditor (for SOC 2) or the carrier’s underwriter (for insurance) renders the verdict. The consultant doesn’t issue the report. We’re explicit about this because it’s a line companies blur and then get burned by, the same way they assume one vendor can both build a system and independently audit it.

The controls overlap heavily, which is the good news. The MFA, logging, access reviews, and endpoint protection a consultant helps you stand up are the same controls a SOC 2 scope expects and the same ones a cyber insurer checks. Do the security work well and the paperwork gets easier; chase the paperwork without the work and you’ve built a facade that fails the first real test.

Which engagement fits your company: a decision matrix

The right first engagement depends on what’s pushing you and how big you are, not on what’s most expensive. Here’s the mapping we actually use on scoping calls. Find the trigger that matches your situation.

Your triggerCompany sizeStart withWhy
”An enterprise customer sent a security questionnaire”AnyGap analysis against their ask, then remediationThe deal is the deadline; scope tightly to what they require
”We have no security strategy and no one owns it”50 to 500 staffvCISO retainerYou need ongoing direction, not a one-time document
”We just want to know how exposed we are”AnyOne-off risk assessmentA ranked exposure list and roadmap is the cheapest clarity you can buy
”We’re shipping a new product or major system”AnySecurity architecture reviewCheaper to fix trust-boundary problems in design than after launch
”We need to pass a SOC 2 to close deals”Startup to midGap analysis plus compliance-focused vCISODrive the controls, then hand a clean state to the auditor
”Our cyber-insurance renewal is asking hard questions”SMBTargeted assessment of insurer-required controlsCarriers check MFA, EDR, backups; close those specifically
”We just had a breach or a close call”AnyIncident-response planning plus assessmentFirst contain and learn, then fix the program that let it happen
”MFA isn’t even on everywhere yet”SmallBaseline hygiene first (see the next section)A consultant will mostly tell you to do this; do it cheaper first

NIST CSF or CIS Controls: what a consultant aligns you to

Framework alignment sounds bureaucratic until you realize it’s just a shared checklist of what “secure enough” means, so you and your buyers and your insurer can stop arguing about it.

The two that matter for most companies are NIST CSF and the CIS Controls. NIST CSF is the broad, flexible one: five functions (Govern, Identify, Protect, Detect, Respond, Recover) spanning 98 practices, adaptable to any size. It’s become the common language. Small-business adoption climbed from 29% in 2023 to 42% in 2025, and enterprise adoption now exceeds 90%, per an ACSMI industry survey. When a buyer says “are you NIST-aligned?” this is what they mean.

CIS Controls are the more prescriptive cousin, and for a small business they’re often the better place to start. The entry tier, Implementation Group 1, is 56 specific safeguards that CIS calls “essential cyber hygiene,” explicitly designed for organizations “with limited IT and cybersecurity expertise.” It’s a do-this-list, not a maturity philosophy. We point a lot of small clients at IG1 first because it’s concrete and it covers the attack techniques behind most breaches.

A consultant’s job here isn’t to evangelize a framework. It’s to map you to whichever one your buyers, your insurer, or your regulator actually require, and to ignore the ones nobody’s asking for. Aligning to a framework no customer recognizes is effort with no payoff.

When you need an MSSP, a consultant, or just hygiene first

Here’s the honest fork, and it’s the part most consulting pages skip because two of the three answers send you elsewhere.

If the basics aren’t done, do them before you hire anyone. Roughly 1 in 4 SMBs were breached in the past year, despite 92% having security tools in place, which tells you tools aren’t the gap, hygiene is. If MFA isn’t enforced everywhere, backups aren’t tested, laptops aren’t encrypted, and patching is whenever-someone-remembers, a $20K assessment will mostly hand you back that list. Spend the first dollars closing the CIS IG1 hygiene gaps. It’s cheaper, and it’s most of the risk. Come back for an assessment once the obvious holes are shut.

If you need someone watching the alerts, that’s an MSSP, not a consultant. A managed security services provider runs the operational side: monitoring, detection, and response on your tools, often 24/7. It’s a recurring operations contract, roughly $2,000 to $5,000 a month for a small business and $5,000 to $20,000 for mid-market. A consultant sets strategy and walks away with a plan; an MSSP shows up every day and runs the playbook. Hiring a vCISO to do alert triage is overpaying a strategist to do an operator’s job.

If you need direction and accountability, that’s the consultant. Strategy, framework alignment, board reporting, audit and insurer coordination, deciding what to fix first with a finite budget. Plenty of mid-market companies end up with both a vCISO setting direction and an MSSP doing the watching, and that pairing is correct, not redundant. They’re different jobs.

The stakes are why getting this order right matters. 40% of SMBs say a cyberattack costing $100,000 or less would put them out of business. At that fragility, spending your security budget on the wrong layer isn’t just inefficient. It’s the difference between surviving an incident and not.

How gmware approaches cybersecurity work

We’re engineers, not auditors, and we don’t sell certifications. What we do is the building-and-fixing half of security: the remediation and hardening engineering that turns an assessment’s gap list into closed gaps, the security architecture work on systems we build, and the access-control and logging foundations that compliance frameworks expect. We run our own production platforms, so when we talk about identity boundaries and audit trails, we’re describing how we operate Shield Suite, not reciting a slide.

When the work is really compliance with a deadline, we tell you so and scope to it, the same way we run a SOC 2 sprint as an engineering project rather than a paperwork exercise. When you’re handling sensitive data and need the controls built into the product from day one, that’s design work, and we’ve written about what that looks like in our HIPAA-compliant app architecture breakdown. And when the honest answer is “fix your MFA and tested backups first, then call us,” that’s the answer you’ll get. Our Austin leads run scoping and strategy on US hours while our Bangalore and Mohali engineers clear the remediation backlog, which keeps senior oversight close without US-only burn rates.

Tell us what’s pushing you, a buyer questionnaire, an insurance renewal, a near-miss, or just a nagging sense you’re exposed. Reach out and we’ll give you a straight answer on which engagement you actually need, scope, and cost, within 48 hours.

  • cybersecurity consulting
  • vciso
  • risk assessment
FAQ

Common questions, answered

What does a cybersecurity consultant actually do?
They figure out where your organization is exposed, rank those gaps by risk, and hand you a prioritized plan to close them. The work spans a risk assessment, alignment to a framework like NIST CSF or CIS Controls, security architecture review, vCISO leadership, and incident-response planning. A consultant advises and plans; they don't usually run your security tools day to day.
How much does cybersecurity consulting cost?
A one-off risk assessment or NIST CSF gap analysis runs about $15K to $25K for a small company and $20K to $35K for mid-market. Ongoing virtual-CISO retainers run $3K to $20K a month depending on hours and compliance load. On-demand hourly work is roughly $200 to $400 an hour. Remediation, the actual fixing, is a separate and usually larger line.
What is the difference between cybersecurity consulting and a penetration test?
A penetration test is one technical assessment: ethical hackers try to break in and report what worked. Consulting is the broader advisory layer around that, covering risk, governance, framework alignment, and strategy. A pen test answers 'can someone get in through this app?' Consulting answers 'where is our whole program weak, and what should we fix first?' Most programs need both, in that order.
Do I need a vCISO or an MSSP?
A vCISO is part-time security leadership: strategy, framework alignment, board reporting, vendor and audit coordination. An MSSP is an operations vendor that runs monitoring, detection, and response on your tools. They solve different problems. Many mid-market companies end up with both, a vCISO setting direction and an MSSP doing the 24/7 watching. Below a certain size, you may need neither yet.
What framework should a small business align to?
For most small and mid-sized companies, start with the CIS Controls Implementation Group 1, a 56-safeguard baseline of essential cyber hygiene built for teams with limited security staff. NIST CSF is the broader, more flexible standard buyers and insurers increasingly expect; small-business adoption climbed from 29% in 2023 to 42% in 2025. A consultant maps you to whichever your buyers, insurer, or regulator actually require.
When does an SMB not need a cybersecurity consultant yet?
When you haven't done the basics. If MFA isn't on everywhere, backups aren't tested, laptops aren't encrypted, and patching is ad hoc, a six-figure assessment will mostly tell you that. Spend the first dollars closing the CIS IG1 hygiene gaps, then bring in a consultant to validate the work and set strategy. Hygiene first, advice second, unless a deal or breach forces the order.

Where we can help

See it on your own data.

Book a 30-minute discovery call and we'll walk through your use case.