How We Work

Two Ways to Engage ALC

Every ALC engagement starts with a clear picture of where your organization stands. From there, the path depends on what you need — a one-time assessment or ongoing security leadership.

Which engagement is right for you?

Most clients start with the Sprint. The Retainer is for organizations that have completed the Sprint and need sustained security leadership over time.

Start Here

Choose the Sprint if…

  • You don't have a clear picture of your current security posture
  • You've never had a formal security assessment
  • You want a written roadmap before committing to ongoing engagement
  • You're evaluating whether ALC is the right fit
  • You need to demonstrate security due diligence to a client, insurer, or board
Next Step

Choose the Retainer if…

  • You've completed the Sprint and have a roadmap to implement
  • You operate in a regulated industry with ongoing compliance obligations
  • You handle sensitive customer, financial, or health data continuously
  • Your board or investors expect documented, ongoing security governance
  • You need a security executive on-call without the cost of a full-time hire

The engagements

Both services are practitioner-led. You work directly with Adam — no junior staff, no handoffs.

Entry Point

SMB Security Sprint

A fixed-fee, 60-day assessment that tells you where your organization stands and gives you a written roadmap for what to do next.

  • Duration 60 days
  • Pricing $2,500 remote • $4,500–$5,000 onsite
  • Deliverables Risk assessment, NIST CSF gap analysis, written security roadmap, executive debrief
  • Commitment No retainer required — one engagement, defined scope
  • Best for First-time clients, one-time assessments, compliance prep
Learn About the Sprint →
Ongoing Engagement

Fractional CISO Retainer

Ongoing executive security leadership — monthly advisory, risk monitoring, policy development, and incident response support.

  • Cadence Monthly sessions + as-needed advisory
  • Pricing Starting at $1,500/mo — scope-based
  • Includes Risk monitoring, policy review, vendor advisory, compliance guidance, incident response support
  • Prerequisite SMB Security Sprint (recommended)
  • Best for Sprint graduates, regulated industries, ongoing compliance needs
Learn About the Retainer →

The natural progression

ALC engagements are designed to build on each other. The Sprint creates the foundation. The Retainer implements and maintains it.

Step 1

SMB Security Sprint

Establish your baseline. Understand your risks. Get a written roadmap tailored to your organization.

Step 2 (optional)

Fractional CISO Retainer

Execute the roadmap with ongoing executive security leadership. Built on the Sprint foundation — no redundant discovery work.

Not sure where to start?

Most clients begin with the Sprint. If you're not sure which engagement fits your situation, reach out — Adam will give you a direct answer.

Start with the Sprint → Ask a Question

No obligation. No sales process. Direct conversation with Adam.

For IT Providers & Advisors

ALC complements your work — it doesn't compete with it.

If you're an MSP, IT provider, fractional CFO, insurance broker, or business advisor, your clients ask you about security. ALC provides the security leadership layer — program design, risk prioritization, policy development, executive reporting, and compliance guidance — that you're not resourced to deliver and weren't hired to own.

ALC does not sell or manage IT infrastructure, endpoints, or day-to-day technical services. Engagements are scoped to security leadership and advisory only. Clients who work with ALC keep their existing IT providers — and typically find that a clearer security posture makes the IT team's work more focused and defensible.

Referral relationships are straightforward and handled with discretion. Reach out directly if you'd like to discuss.