Plans
Three plans for three stages of security maturity. Every plan includes an annual IT security audit and security training. Request a written quote and we will price it to your firm.
Platinum
For firms pursuing SOC 2 or recovering from an incident.
- Everything in Gold and Standard
- SOC 2 compliance program (Type I or Type II)
- Penetration test coordination
- Post-breach recovery
- 50-plus policy framework aligned to SOC 2
- SOC 2-aligned annual IT security audit
- IT security training
Gold
For firms with no formal security program yet.
- Everything in Standard
- Complete security program development
- Network infrastructure redesign
- 30 to 50 policy framework
- Hands-on security engineering
- Annual IT security audit with technical testing
- IT security training
Standard
For firms that already have a program and need it kept healthy.
- Strategic security leadership
- Policy maintenance
- Compliance monitoring
- Quarterly reviews
- Annual IT security audit
- IT security training
A full-time CISO is a major hire once benefits and overhead are counted. A MiTech plan gives you the same leadership for a fixed annual fee, with the engineering work included on Gold and Platinum.
Side by side
| Platinum | Gold | Standard | |
|---|---|---|---|
| Best for | SOC 2 and post-incident | Building a program from scratch | Maintaining an existing program |
| Program development | Included | Included | Maintenance only |
| Network redesign | Included | Included | Not included |
| Policy framework | 50 or more | 30 to 50 | Maintained |
| SOC 2 program | Included | Not included | Not included |
| Penetration test coordination | Included | Not included | Not included |
| Post-breach recovery | Included | Not included | Not included |
| Annual IT security audit | SOC 2-aligned | With technical testing | Included |
| IT security training | Included | Included | Included |
Good to know
Fees are fixed and quoted in writing. You can pay annually or quarterly, and work outside your plan is agreed in advance. Final scope for your firm is confirmed in a written proposal before anything starts.
Which plan fits?
You have no formal program
Start with Gold. It builds the whole program, then Standard keeps it running in later years.
You have a program and want it maintained
Standard gives you leadership, quarterly reviews and an annual audit.
A client or regulator wants SOC 2, or you were breached
Platinum covers the certification path and the recovery work.
Find out where your firm stands.
A 30-minute call covers your current controls, the rules that apply to you, and what a first 90 days would look like. No cost, no sales deck.