forumNew topic

We are a 4-person cybersecurity consultancy — is our service packaging and pricing model wrong?

SSerapNew member
Job title
Private tutoring
Joined
Nov 2024
Message
30
#1

We are a core team of 4 running a cybersecurity consultancy in the UK (London). Everyone on the team is technically very strong; we handle penetration testing cloud security configuration, and compliance audits. anyway however we're hitting a serious bottleneck on the business operations and pricing side.

Under our current model we usually bill at an hourly rate of 120-150 GBP or we give small companies a flat fee of 3,000 - 5,000 GBP for a one-off pentest. I mean the problem is that one month we're slammed, and the next we have zero work. On top of that fixed-price projects keep suffering from scope creep, and clients continue asking questions for weeks after we deliver the report without paying extra.

How should we package our services to generate recurring monthly revenue? like for a small consultancy, is hourly, fixed-project or a monthly subscription model more sustainable?

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
Most Helpful#2

Short answer: Drop hourly billing altogether and transition to a monthly retainer model centered on vCISO services and continuous vulnerability management. One-off pentests cause your cash flow to fluctuate wildly; sustainable profitability isn't about finding a client's vulnerabilities once a year, it's about keeping their systems secure every month.

To keep your 4-person team's capacity manageable, I'd suggest structuring your services into three core tiers. Tier one should cater to small businesses, covering monthly automated vulnerability scans, external asset monitoring, and a quarterly assessment report; you can price this around 1,500 - 2,500 GBP per month. Tier two should be a full retainer at 3,500 - 5,000 GBP aimed at more regulated industries, including ongoing compliance tracking, staff training, and 10 hours of monthly advisory. Use one-off penetration tests strictly as an entry point to upsell these packages.

To prevent scope creep, put strict boundaries in your contracts. Cap the post-report Q&A window at a maximum of 10 business days and allow up to 2 remediation verification checks. Any request beyond that should trigger an additional work order fee.

Once you lock down 8-10 recurring corporate clients, you'll have a predictable base revenue of around 25,000 GBP per month. That eliminates the stress of bench time and lets you scale capacity by selling outcomes rather than selling hours.

UUğur S***Member
Job title
Marketing manager
Sector
Agriculture
Organization type
cooperative
Joined
Nov 2025
Message
284

Doki · Infrastructure migration · 2024

#3

We were stuck in the exact same spot with our 3-person team. We walked away from one-off tests and signed local mid-sized finance and logistics firms on 2,000 GBP/month monitoring and audit retainers. We're currently sitting at 12 clients, bringing in 24,000 GBP a month in steady income, so we can focus on the work instead of stressing about next month.

SSerkan Ç***MemberCommunity member
Joined
Jul 2022
Message
373
#4

You need to phase this in gradually. 1) First, call every client you did a pentest for over the past year. 2) Pitch a quick follow-up review: "You patched the issues we found, but have new risks emerged in the last 6 months?" 3) Attach a monthly retainer proposal to the end of that review that includes 4 scans a year.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#5

Be careful when moving to a retainer model. SMBs hate paying recurring security fees; they usually only find budget when there's an active breach or an impending compliance audit. Unless you can offer compliance documentation that lowers their insurance premiums or helps them close deals rather than just handing them technical reports, selling retainers is going to be an uphill battle.

NNeslihan T***Expert
Job title
Purchasing manager
Sector
Machinery manufacturing
Organization type
workshop
Joined
Dec 2024
Message
229
#6

To prevent scope creep, make sure you strictly require these 3 clauses in your contracts: 1) The list of IPs and domain names included in the project scope is frozen; any new assets are subject to additional billing. 2) Post-report re-validation testing is limited to a maximum of 1 round. 3) Any revision requests not closed within 14 days following the delivery of the report are deemed complete.

GGizem E***ExpertCommunity member
Joined
Jun 2023
Message
48
#7

hourly billing kills consulting. the faster you solve it the less money you make, its literally a perverse incentive. put together fixed-scope packages and lock them into monthly retainers save yourself the headache.

edit: I wrote something wrong above, sorry about that.

HHakan K***Member
Job title
Content Editor
Sector
Glass
Organization type
40-person manufacturing company
Joined
Jun 2024
Message
120
#8

Supply chain regulations and enterprise audit standards are steadily tightening in the UK market. Instead of selling direct technical scans to your clients, you will have a much easier time getting monthly retainer fees approved if you sell the promise of ensuring the security posture they need to qualify for enterprise tenders.

HHavva G***MemberCommunity member
Joined
Feb 2023
Message
384
#9

In our first year we did a penetration test for an e-commerce client for 4,000 pounds. For the next 8 months, they called us every single time they moved a server asking "could you take a quick look?", we couldn't say no, and it almost ran us into the ground. Then we drew a hard line and offered either a 1,200 pound monthly retainer or hourly billing—they gladly took the retainer.

HHavva Ö***MemberCommunity member
Joined
Aug 2025
Message
25
#10

Sell the client the risk you eliminate and their peace of mind, not the hours you spend; the moment you tie your price to an hourly rate, your stopwatch becomes the subject of negotiation not your technical expertise.

edit: fixed a few typos.

KKader A***Member
Job title
Store Manager
Sector
Cosmetics
Organization type
two-branch business
Joined
Nov 2022
Message
183
#11

There's one point I'm curious about. Hasty decisions become decisions you have to fix six months later.

Changing habits is harder and more expensive than setting up a system.

ZZübeyde E***Member
Job title
Accounting clerk
Sector
Tourism
Organization type
8-person team
Joined
Jul 2023
Message
221
#12

I went through the same thing two years ago. The biggest time-waster for us was not knowing who had the final say.

Of course, it varies if your situation is different.

VVahide V***Member
Job title
General Manager
Sector
Cosmetics
Organization type
workshop
Joined
Jul 2022
Message
1
#13

Timely topic. Mistakes made on the cybersecurity consultancy side are usually reversible but expensive.

The harder it is to reverse a decision, the slower you should make it. If I were you, I'd go this route.

SSerkan Ç***MemberCommunity member
Joined
Sep 2024
Message
2
#14

I agree with this. Most time waste accumulates in tasks waiting for approval.

If it's your first time, start small; scaling comes later. Hope this helps.

NNazlı P***MemberCommunity member
Joined
Oct 2024
Message
9
#15

Let me speak from the other side; I'm on the supplier side. When making decisions, write down the worst-case scenario too, not just the best.

If I were you, I'd go this route.

NNurcanNew member
Job title
Cleaning services
Joined
Nov 2024
Message
26
#16

we need to make a distinction here then annyway when we decide without measuring we always end up in the same place.

this is my opinion, I'm not claiming it's absolute truth.

İİbrahim B***Member
Job title
Production planning
Sector
Livestock
Organization type
chain store
Joined
Feb 2024
Message
24

Doki · Log management setup · 2024

#17

I was thinking the same thing. If it's your first time, start small; scaling comes later.

This is my opinion, I'm not claiming it's absolute truth.

OOsman K***MemberCommunity member
Joined
Mar 2024
Message
117
#18

I'm writing this so you don't make the same mistake. People defend habits, not processes. Resistance comes from there.

Start with a small trial; don't commit to everything at once. Proven by experience.

CCem K***Member
Job title
QA Tester
Sector
IT services
Organization type
chain store
Joined
Sep 2023
Message
138
#19

Here's how it went for us. Look where the bucket leaks; pouring water on top doesn't solve it.

Hope this helps.

TTülay C***MemberCommunity member
Joined
Jun 2024
Message
48
#20

Just a heads-up. When making a decision, first look at what data you have on hand.

Everything goes well for the first three months; problems arise in the fourth. Of course it varies if your situation is different.

Reply