Services

We build security programs.

Three commercial shapes. Senior-led on every one. The partner who scoped the engagement runs every quarterly review.

01 · Practices

Five practices. Each designed around a specific buyer pain,
not a generic SOW template.

The five practices below are the intellectual scope of what Birchlogic delivers. The three commercial shapes that follow are how you actually buy it.

  1. I

    Strategic Advisory and vCISO.

    Embedded senior leadership inside the executive team, not next to it. Risk appetite renegotiated each fiscal cycle. Governance built through workflow. Board reporting in financial language.

  2. II

    CRQ and Strategic Assessment.

    Sixteen-domain CMMI maturity scoring. FAIR-CAM control efficacy quantification. Monte Carlo loss exceedance modelling. Quant work accelerated by our internal workbench, while interviews, scenario scoping, and board framing remain partner-led.

  3. III

    Compliance, Privacy and Regulatory.

    Multi-framework programme design where evidence is collected once and mapped across overlapping regimes. RBI, SEBI, MAS TRM, EU AI Act, NIS2, DPDP, UAE PDPL, DESC. Workflow-built evidence linkage so audit preparation stops being a sprint.

  4. IV

    Application, Cloud and AI Security.

    Engineering-led security where the security team ships code. Cloud architecture across AWS, Azure, and GCP. AI security architecture for AI-native systems: agentic threat modelling, MCP security, supply-chain governance for models, EU AI Act compliance design that engineering teams can actually execute.

  5. V

    Resilience, Incident Response and Recovery.

    Crisis-grade incident response with hours-not-days containment objectives. DFIR with forensic-grade evidence preservation. Business continuity that does not depend on the CISO being available at the moment of crisis.

02 · Proof · Practice II

CRQ delivered
in 45 days.
Not six months.

FAIR and FAIR-CAM methodology, identical to top firms. The traditional consultancy response is a heat map in three shades of amber. The CRQ response is a number, denominated in the same currency the CFO uses for credit, market, and operational risk. The methodology is identical to top firms. The speed is our internal workbench.

04 · The twelve quick sprints

Twelve quick sprints.
One specific thing, fixed in weeks.

A founder with a US enterprise deal stuck on AI questions does not need a year. A SEBI mid-cap CISO with an attestation due in 60 days does not need a one-off audit. They need one specific thing fixed in one month, by a senior practitioner, with a partner accountable for the outcome.

SprintWhat it fixesDuration
Multi-Framework Compliance ProgramSOC2, ISO 27001, DPDP, AI governance, all delivered as one program. Evidence collected once, mapped across regimes.6 to 8 weeks
SOC2 Type I in 2 WeeksYou are stalled mid-Vanta. Senior firm pushes you across the audit line.2 weeks
AI Security Posture SprintUS prospects asking AI questions. You have no answers.4 weeks
ISO 42001 Readiness SprintEU customer asked for ISO 42001. You have no AIMS.4 weeks
Cloud Security Architecture ReviewAWS, Azure, GCP grew reactively. Customer-defensible architecture in 4 weeks.4 weeks
SEBI CSCRF Attestation SprintAudit committee deadline. CRQ in rupees alongside controls evidence.4 weeks
DPDP Act Readiness SprintROPA, DPO, breach playbook, cross-border transfer framework.4 weeks
TPRM Audit RescueA deal is stuck. We unstick it in three weeks.3 to 4 weeks
AI Security Questionnaire Response EngineMultiple enterprise prospects asking AI questions. We build the answer library.3 weeks + monthly
MAS TRM Single-Domain SprintOne open TRM Domain finding. MAS-fluent partner.4 weeks
Post-Incident 30-Day HardeningAfter the breach: identity, backups, IR runbook, board recovery report.4 weeks
M&A Cyber DD ExpressPE-ready cyber DD. IC-grade output.3 to 4 weeks
05 · vCISO retainer

vCISO retainer.
Three intensities.

A full-time CISO hire is six months and a board approval away. A vCISO retainer gives you the function in two weeks, with cross-industry pattern recognition that a first-time CISO has not yet built. Month-to-month commercial. Most engagements run multi-year because the program compounds and the partner who closed the engagement runs every quarterly review.

01 / 03

Light.

Quarterly board pack, monthly steering, audit support, on-call Slack hours.

Fit: Series A SaaS post-SOC2 with US or EU enterprise pipeline.
02 / 03

Standard.

Light plus ongoing program management, vendor risk, AI governance reviews, custom policy authoring, Trust Center maintenance.

Fit: Series B SaaS and mid-size fintechs.
03 / 03

Regulated.

Standard plus regulator response, monthly board pack, audit committee briefings, custom policy aligned to RBI, SEBI, or MAS, supervisor letter response.

Fit: RBI-regulated fintechs, SEBI mid-caps, MAS-licensed entities.

We are month-to-month. We have no minimum commitment. Most of our clients stay multi-year because the partner who closed the engagement runs every quarterly review.

06 · Fractional Security Office

Fractional Security Office.
A complete security function.

vCISO retainers are advisory. Fractional Security Office is execution. The buyer here is not looking for an advisor; they are looking for the entire security function as an outsourced capability. Birchlogic owns the program. Runs the team. Reports to the board.

01 / 03

Core.

Partner plus one senior plus 0.5 junior FTE-equivalent dedicated.

Fit: Series B-plus B2B SaaS and mid-size fintechs.
02 / 03

Plus.

Partner plus two senior plus one junior FTE-equivalent dedicated.

Fit: SEBI mid-caps and fintechs with regulator attention.
03 / 03

Premium.

Partner plus two senior plus two junior plus on-call IR readiness, dedicated.

Fit: Tier-2 and Tier-3 banks, payment institutions, MAS-licensed mid-size, post-breach embedded.

Our model is single-tenant. We can hand the capability back to you when you are ready to bring it in-house. We are not designed to be sticky. We are designed to be necessary while we are there.

07 · What we deliberately do not sell

These are all important.
They are separate disciplines.

  • Managed Detection and ResponseCoordinated, not owned
  • Live incident responseCoordinated, not owned
  • Penetration testingCoordinated, not owned
  • Cybersecurity productsCoordinated, not owned
  • Managed IT helpdeskCoordinated, not owned

We do not run these in-house. We coordinate the best specialist for each. You get senior judgment on the program. You get top-tier delivery on each specialist line. You get one accountable partner across all of it.

Pricing is on the call,
not on the website.