A security engagement should end with less risk, not a longer report.
Every Binary2 engagement follows the same five stages. Durations are typical for a mid-sized organisation and are fixed in writing before work starts.
Scope
One to two weeksWe agree the question before we agree the price. You get a written scope stating what is in, what is out, what we need from you, and what you will hold at the end.
Assess
Two to six weeksInterviews, evidence review and hands-on testing. We look at how things work in practice, which is rarely how the policy says they work.
Prioritise
One weekFindings are ranked by what they would cost the business, not by a scanner's severity score. We walk your team through each one before anything is final.
Fix
As agreedWe stay for remediation if you want us to: designing controls, reviewing changes, and working alongside your engineers or your vendors.
Verify
On completionWe retest what was fixed and report what changed. Closed means demonstrated, with evidence you can hand to an auditor.
What you can hold us to
Fixed scope, fixed fee
Where the work can be scoped, we price it as a fixed fee. Changes are agreed in writing before they are billed.
No surprises in the final report
Critical findings are raised the day we confirm them. The report records conversations you have already had.
Your data stays yours
We work under NDA, keep client data in the region where required, and delete engagement data on a schedule you approve.
Written for two audiences
Each deliverable has a short executive summary a board can read and a technical section an engineer can act on.
Standards, named
We map our work to the framework you are measured against, and say which control each finding relates to.
We say when we are not the right firm
If a problem sits outside our competence, we will tell you in the first conversation.
Frameworks we work to
- NIST Cybersecurity Framework 2.0 and NIST AI Risk Management Framework
- ISO/IEC 27001 and ISO/IEC 42001
- CIS Critical Security Controls
- SOC 2 and PCI DSS v4
- OWASP ASVS and the OWASP Top 10 for LLM applications
- MITRE ATT&CK and MITRE ATLAS
Tell us what you are trying to secure.
A first conversation is thirty minutes, with a practitioner, and costs nothing. You will leave it knowing whether we are the right firm for the problem.