Five practices. Each designed around a specific buyer pain,
not a generic SOW template.
The five practices below are the intellectual scope of what Birchlogic delivers. The three commercial shapes that follow are how you actually buy it.
The work,
matched to the problem on your desk.
These are engagements we have run enough times to deliver on a clock. If one of them looks like the problem you are facing, the weeks column tells you how quickly it can be gone: fixed scope, fixed date, a senior partner in every meeting, and first-pass acceptance as the contracted outcome.
| Engagement | The situation it fixes | Weeks |
|---|---|---|
| The Security ReadWhere most engagements begin | Someone important is about to read your security. We read it first, the way they will, and tell you what they will find. | 3 |
| Sales Deal Rescue | Your deal is stuck in the customer's security review right now. We write the answers, join the calls, and unstick it. | 2 to 3 |
| Platform Rescue | You bought Vanta, Drata or Sprinto and the audit is still stuck. The tool did its job; we do the part it cannot. | 2 to 4 |
| Regulatory Response | An RBI order, a CSCRF deadline, a DPDP date, a MAS finding or a licence application. Evidence that survives the inspector. | 4 to 12 |
| Certification Programme | SOC 2, ISO 27001, or both at once. Evidence collected once, certificate on the first pass. | 6 to 8 |
| CERT-In empanelled VAPT | The pentest report that banks, regulators, tenders and enterprise reviews actually accept. Delivered with our CERT-In empanelled testing partners, scoped and signed by our senior partner, so you get the empanelled report and one accountable name. | 2 to 4 |
| Breach Readiness | The incident plan that exists only on paper, tested before it is needed: tabletop, runbook, and the DPDP and CERT-In notification clocks you would actually have to hit. | 3 to 4 |
| Evidence Automation & Trust Centre | One-time build: evidence collects itself, your trust centre answers the questionnaires, and your engineers go back to shipping. A senior partner signs what the pipeline produces. | 3 to 6 |
| AI Security & Governance | Customers and regulators started asking AI questions your SOC 2 was never built to answer, from system assessment to the board AI policy FREE-AI expects. | 4 to 6 |
Every Security Read ends in a working session with your team rather than a PDF, and if the plan is something your own people can execute without us, we will say so in the room.
Also available, scoped on request: Cloud Security Architecture Review · M&A Cyber Due Diligence Express. MAS-specific sprints live on the Singapore practice page.
A full-time CISO hire is six months and a board approval away. A vCISO retainer gives you the function in two weeks, with cross-industry pattern recognition that a first-time CISO has not yet built. Month-to-month commercial. Most engagements run multi-year because the program compounds and the partner who closed the engagement runs every quarterly review.
Solo vCISO.
A named senior practitioner who represents your security: in front of your customers' security reviews, your auditors, your investors and your board.
vCISO + Engineer.
The same named practitioner, plus a forward-deployed engineer for the work that has to actually get built: the evidence pipeline, the cloud hardening, the control implementation, the findings that need closing rather than documenting.
vCISO Regulated.
The senior-most configuration, for RBI, SEBI, IRDAI and MAS-regulated environments: regulator response and representation, audit committee briefings, supervisor letters answered, and board reporting that puts a number on exposure. Boards see cyber risk in dollars: a quantified exposure model, delivered in 45 days, is part of every Regulated engagement.
Month-to-month, thirty days\u2019 notice. Most engagements begin with the Security Read.
We are building entire security departments for companies that were never going to hire one, and it works because of how it deploys: one forward-deployed engineer and one virtual CISO as the fixed core, specialised agents composed around them per task, and every tool, platform and OEM licence the department needs, packaged and run inside the same engagement. Everything a security department does, delivered as one line on your budget, scaled up when your quarter demands it and back down when it does not.
If you are a regulated entity or a mid-size firm, book the thirty minutes and we will tell you honestly whether this is the right fit or whether a retainer serves you better.
If you are a founder building a startup, we have a founding offer running for exactly ten companies, and it is priced for you.
See the founding offer →These are all important.
They are separate disciplines.
- Managed Detection and ResponseCoordinated, not owned
- Live incident responseCoordinated, not owned
- Penetration testingDelivered with empanelled partners, owned by us
- Cybersecurity productsCoordinated, not owned
- Managed IT helpdeskCoordinated, not owned
We do not run these in-house. We coordinate the best specialist for each. You get senior judgment on the program. You get top-tier delivery on each specialist line. You get one accountable partner across all of it.