Services

Three commercial shapes. Senior-led on every one. The partner who scoped the engagement runs every quarterly review.

01 · Practices

Five practices. Each designed around a specific buyer pain,
not a generic SOW template.

The five practices below are the intellectual scope of what Birchlogic delivers. The three commercial shapes that follow are how you actually buy it.

04 · The work

The work,
matched to the problem on your desk.

These are engagements we have run enough times to deliver on a clock. If one of them looks like the problem you are facing, the weeks column tells you how quickly it can be gone: fixed scope, fixed date, a senior partner in every meeting, and first-pass acceptance as the contracted outcome.

EngagementThe situation it fixesWeeks
The Security ReadWhere most engagements beginSomeone important is about to read your security. We read it first, the way they will, and tell you what they will find.3
Sales Deal RescueYour deal is stuck in the customer's security review right now. We write the answers, join the calls, and unstick it.2 to 3
Platform RescueYou bought Vanta, Drata or Sprinto and the audit is still stuck. The tool did its job; we do the part it cannot.2 to 4
Regulatory ResponseAn RBI order, a CSCRF deadline, a DPDP date, a MAS finding or a licence application. Evidence that survives the inspector.4 to 12
Certification ProgrammeSOC 2, ISO 27001, or both at once. Evidence collected once, certificate on the first pass.6 to 8
CERT-In empanelled VAPTThe pentest report that banks, regulators, tenders and enterprise reviews actually accept. Delivered with our CERT-In empanelled testing partners, scoped and signed by our senior partner, so you get the empanelled report and one accountable name.2 to 4
Breach ReadinessThe incident plan that exists only on paper, tested before it is needed: tabletop, runbook, and the DPDP and CERT-In notification clocks you would actually have to hit.3 to 4
Evidence Automation & Trust CentreOne-time build: evidence collects itself, your trust centre answers the questionnaires, and your engineers go back to shipping. A senior partner signs what the pipeline produces.3 to 6
AI Security & GovernanceCustomers and regulators started asking AI questions your SOC 2 was never built to answer, from system assessment to the board AI policy FREE-AI expects.4 to 6

Every Security Read ends in a working session with your team rather than a PDF, and if the plan is something your own people can execute without us, we will say so in the room.

Also available, scoped on request: Cloud Security Architecture Review · M&A Cyber Due Diligence Express. MAS-specific sprints live on the .

05 · vCISO retainer


A full-time CISO hire is six months and a board approval away. A vCISO retainer gives you the function in two weeks, with cross-industry pattern recognition that a first-time CISO has not yet built. Month-to-month commercial. Most engagements run multi-year because the program compounds and the partner who closed the engagement runs every quarterly review.

01 / 03

Solo vCISO.

A named senior practitioner who represents your security: in front of your customers' security reviews, your auditors, your investors and your board.

Fit: Firms whose engineering can execute and who need seniority, representation and a programme owner rather than extra hands.
02 / 03

vCISO + Engineer.

The same named practitioner, plus a forward-deployed engineer for the work that has to actually get built: the evidence pipeline, the cloud hardening, the control implementation, the findings that need closing rather than documenting.

Fit: Firms where the gap is in the doing.
03 / 03

vCISO Regulated.

The senior-most configuration, for RBI, SEBI, IRDAI and MAS-regulated environments: regulator response and representation, audit committee briefings, supervisor letters answered, and board reporting that puts a number on exposure. Boards see cyber risk in dollars: a quantified exposure model, delivered in 45 days, is part of every Regulated engagement.

Fit: RBI-regulated fintechs, SEBI mid-caps, IRDAI insurers and MAS-licensed entities.

Month-to-month, thirty days\u2019 notice. Most engagements begin with the Security Read.

06 · Fractional Security Office


We are building entire security departments for companies that were never going to hire one, and it works because of how it deploys: one forward-deployed engineer and one virtual CISO as the fixed core, specialised agents composed around them per task, and every tool, platform and OEM licence the department needs, packaged and run inside the same engagement. Everything a security department does, delivered as one line on your budget, scaled up when your quarter demands it and back down when it does not.

The department, mapped
Fixed coreForward-deployed engineerVirtual CISOPlus every tool, platform and OEM licence the department needs, packaged inside the engagement.
Governance & policyRisk & board reportingCompliance & auditIdentity & accessCloud & infrastructureApplication securityVulnerability managementDetection & responseThird-party risk

If you are a regulated entity or a mid-size firm, book the thirty minutes and we will tell you honestly whether this is the right fit or whether a retainer serves you better.

If you are a founder building a startup, we have a founding offer running for exactly ten companies, and it is priced for you.

07 · What we deliberately do not sell

These are all important.
They are separate disciplines.

  • Managed Detection and ResponseCoordinated, not owned
  • Live incident responseCoordinated, not owned
  • Penetration testingDelivered with empanelled partners, owned by us
  • Cybersecurity productsCoordinated, not owned
  • Managed IT helpdeskCoordinated, not owned

We do not run these in-house. We coordinate the best specialist for each. You get senior judgment on the program. You get top-tier delivery on each specialist line. You get one accountable partner across all of it.