WHAT OUR CLIENTS ASK US

Frequently Asked Questions.

These are some of the key questions we get asked by startup founders. If your question isn't covered here, please get in touch.

General

Do you work with UK digital startups specifically?

Yes, that is who we build our services for. Pre-revenue to around £1m, pre-seed to Series A, SaaS, fintech, healthtech, marketplace, or AI-led. We give proportionate advice scoped to your stage and runway, not an enterprise framework applied at a quarter of the scale.


We're a small business, not a venture-backed startup. Can you still help us?

Yes. Our core focus is digital startups, but the fundamentals, like Secure Foundations, apply just as well to any small business that needs the basics properly in place, whether or not you are raising investment. Some of our services, such as Commercial Readiness, are built around investor and enterprise-procurement scrutiny specifically, and may be less relevant if that is not your situation, but we will tell you honestly which of our services actually fit.


What is the difference between SOC 2 and ISO 27001, and which do we need?

They are not direct equivalents, they work differently. SOC 2 is a US-style attestation report against a set of trust criteria, assessed annually. ISO 27001 is an internationally recognised, certifiable management-system standard. In practice, UK investors and UK enterprise clients typically ask for ISO 27001 rather than SOC 2, so that is usually the more useful one to hold if you are selling or raising in the UK. If you are selling into the US or raising from US investors, SOC 2 may still come up. Commercial Readiness maps out which one actually applies to you before you spend money on either.


Our developers already handle security. Isn't that enough?

Your development team keeping the product running and your business being able to demonstrate, with evidence, that it can be trusted at scale are two different things. Investors, enterprise clients, and regulators ask about the second one. That is usually the gap we get called in to close.


We already use Vanta or Drata. Do we still need you?

A compliance platform automates evidence collection, it does not tell you what controls you actually need, whether your architecture is sound, or what an investor will find when they look closely. We do not resell these platforms, and we will tell you honestly whether one fits your stage. Advisory and a platform work well together; a platform alone is not the same as being investor-ready.


When should we start preparing for investor due diligence?

Ideally 60 to 90 days before the round starts, not three weeks into it. Most founders discover the security gap partway through a six-week round, when it is too late and too expensive to fix properly. Commercial Readiness can still help if a questionnaire has already landed, but the options narrow considerably.


What is a Fractional CISO, and do we need one instead of hiring?

A Fractional CISO gives you senior, CISO-level oversight, investor meeting attendance, and board-level reporting, without the cost or hiring timeline of a full-time senior hire. At Series A, investors increasingly expect a CISO-level function; your CTO is not your CISO. Our Security Leadership service fills that gap until the business is ready to hire one directly.


Can you help with Cyber Essentials or ISO 27001?

Yes. Secure Foundations builds the Cyber Essentials-aligned technical controls into your business directly, and Commercial Readiness prepares you for the formal audit itself, gap assessment, evidence and all. We do not carry out the certification ourselves, that is done by an accredited body, so our assessment of your gap stays honest.


What do you not do?

We do not formally audit, certify, or assess against any standard ourselves. We do not run penetration tests directly, but we can refer you to trusted technical partners and will help you interpret the results. We do not manage operational incident response, we advise on what to do. And we do not resell compliance platforms.


How do you price your services?

We publish clear pricing on our services page rather than a "talk to us" default. Secure Foundations is a fixed, one-off price by tier (Essentials, Standard or Advanced). Cyber Security Coaching is a fixed-term programme, typically 3-6 months, priced as a total rather than a monthly fee. Security Leadership is a monthly retainer. Project-based services like Commercial Readiness, Product & AI Security and the Strategy Workshop are fixed scope. You can see roughly what something will cost before you book a call.


Can you help us understand whether the EU AI Act, EU Cyber Resilience Act or NIS-2 apply to us?

Yes. Most founders do not know these apply to them until an investor or customer raises it. If you have EU customers or EU users, the EU AI Act and Cyber Resilience Act can apply regardless of Brexit, with fines up to €35M or 7% of global turnover for the EU AI Act. NIS-2 mainly affects essential and important-sector operators and their suppliers, so it is less common at early stage but worth checking if you sell into those supply chains. Commercial Readiness includes a plain-English regulatory map specific to your product and market.


Secure Foundations

How long does Secure Foundations take, start to finish?

Typically 2-4 weeks. Essentials is usually 1.5-2.5 days of effort, Standard 4-5 days, and Advanced 6-8+ days, spread across scoping, review and roadmap delivery rather than one continuous block.


Is Secure Foundations enough on its own, or do I need something else too?

For most early-stage startups, yes, it covers the basics properly. If you want ongoing support to work through the roadmap yourselves, Cyber Security Coaching is a natural next step. If a customer or investor is already asking security questions, Commercial Readiness picks up from there.


Which package should we start with?

It depends on your stage. Essentials suits small businesses and beginning startups who need the Cyber Essentials-aligned basics in place. Standard fits a live product with employees, customers or upcoming commercial scrutiny. Advanced is for startups handling regulated, high-risk or commercially sensitive data. If you are not sure, a short scoping call is enough to identify the right starting point.


Cyber Security Coaching

How is this different from just hiring a consultant for one-off advice?

One-off advice answers a single question. Coaching is a structured programme, regular sessions, a roadmap you build together, and review of the documents and controls you actually produce, so the skills stick rather than the advice being forgotten after the call.


Do you write our policies and documents for us?

We review and give feedback on what you produce, we do not write it for you. That is a deliberate choice, policies you write and understand are ones you can actually follow and defend, not a template nobody on the team has read.


What happens after the programme ends?

Most founders come out able to run security decisions themselves, using the roadmap and habits built during the programme. If your needs grow beyond that, for example ongoing board reporting, Security Leadership is a natural next step.


Do you offer a monthly payment plan?

Yes. Packages are priced and scoped as a fixed total, but we're happy to split that into monthly instalments across the length of the programme rather than a single upfront payment. Let us know on the scoping call and we'll set it up.


Product & AI Security

Do you test the AI models themselves, or just how we use them?

We review how AI and agents are integrated into your product, permissions, data flows, prompts, third-party AI services, and where things could go wrong, rather than testing the underlying model itself, which is usually the responsibility of the model provider.


We're not using AI yet. Is this still relevant?

Yes. The Focused Review works just as well for a standard SaaS product, covering architecture, data flows and access model. AI-specific review is only included where it's relevant to what you're building.


How is this different from a penetration test?

A penetration test tries to break what you've built. This review happens earlier, at the architecture and design level, so you fix structural issues before they become expensive, and arrive at a penetration test with fewer, cheaper findings.


Strategy Workshop

What kind of challenges is this good for?

Anything specific enough to define in one sentence, for example choosing between SOC 2 and ISO 27001, setting an AI usage policy, deciding how to respond to a security question from a customer, or agreeing your security roadmap ahead of a board meeting.


Can we use this if we're not sure exactly what our challenge is yet?

Yes. The scoping call is designed to help pin that down. If it turns out the real issue is broader than one session can cover, we will tell you honestly and suggest a better-fitting service.


What happens if we need follow-up after the workshop?

Additional follow-up or advisory work after the workshop is available at an hourly rate, or you can move to Cyber Security Coaching or Security Leadership if you want ongoing support instead.


Commercial Readiness

How fast can you turn a questionnaire around?

It depends on length and how much evidence already exists, but most Focused Reviews are completed within one to two weeks. Tell us your deadline on the scoping call and we'll tell you honestly whether it's achievable.


Do you fill in the questionnaire for us?

We draft and review answers with you and help you gather the evidence behind them, rather than guessing on your behalf. The answers need to be accurate and defensible, not just complete.


What if we get asked something we genuinely don't have in place yet?

We help you answer honestly, with a credible plan and timeline attached, which is usually far more reassuring to a customer or investor than a vague or evasive answer.


Security Leadership

What's the difference between Virtual CISO and Fractional CISO here?

Virtual CISO gives you regular access to senior security expertise, 1-2 days a month, for businesses that need direction and oversight but limited operational involvement. Fractional CISO embeds that expertise into your leadership team for around a day a week, with active ownership of the security programme.


Can we start with Virtual CISO and move to Fractional CISO later?

Yes. Many founders start with lighter-touch oversight and increase involvement as the business grows, an upcoming funding round approaches, or the board starts expecting more formal reporting.


Will you actually attend board or investor meetings?

Yes, that's part of the service, particularly at the Fractional CISO tier, where board-level reporting and investor meeting attendance are included.


Book a Discovery Call.

30 minutes, no obligation. We will talk through where you are, what is coming up, and what would actually help at your stage.

Book a discovery call