Hacker AcademyHacker Academy

Essentials plan

Security foundations for small teams that need a clear starting point.

Essentials gives small organisations a predictable monthly security advisor retainer focused on onboarding, hygiene, safer access, and practical next steps.

Monthly allocation

8 hours / month consultant time

£995 / month, excluding VAT
Onboarding included in month one
Monthly advisory call
Security hygiene review
Summary reporting

Use the monthly allocation for the security priorities that matter most. Work is planned and delivered within the available consultant time.

Who this is for

  • Small teams without dedicated security ownership.
  • Organisations that need safer access, basic hygiene, and a practical roadmap.
  • Teams that want regular guidance without a large monthly commitment.

Who this is not for

  • Teams that need weekly security leadership.
  • Organisations expecting major project delivery within the monthly allocation.
  • Environments that require 24x7 monitoring or incident response cover.

First 90 days

A phased start that keeps expectations clear.

The first month focuses heavily on onboarding and understanding your environment. Work is then planned around priorities and the monthly time allocation.

Month 1

Onboarding and environment review

  • Understand users, systems, cloud services, and key risks.
  • Review immediate security hygiene and access priorities.
  • Agree the first action list and monthly working rhythm.

Month 2

Identity and workspace quick wins

  • Review MFA, admin accounts, password manager use, and access hygiene.
  • Check Microsoft 365 or Google Workspace security basics.
  • Prioritise practical fixes for the team.

Month 3

Roadmap and recurring improvement

  • Refine the security roadmap based on what has been learned.
  • Review external exposure and basic vulnerability signals.
  • Agree the next improvement priorities.

Monthly time

How your consultant time is typically used.

Actual allocation varies based on your priorities, access, risk, and the work already completed. The plan defines capacity, not an unlimited list of deliverables.

ActivityTypical hours
Monthly advisory call0.5
Security hygiene or access review2
M365 / Google Workspace review1.5
Action plan and guidance2
Summary reporting and follow-up2

Included services

What can be covered inside the monthly allocation.

Services are delivered within the available consultant time and agreed priorities for the month.

Identity and access

  • MFA review
  • Password manager guidance
  • Admin account review

Workspace security

  • Microsoft 365 / Google Workspace review
  • Email security checks
  • Basic configuration guidance

Security hygiene

  • Backup and patching review
  • Endpoint protection review
  • Basic external vulnerability review

Deliverables

  • Monthly advisory call
  • Monthly summary report
  • Prioritised action list
  • Email support within the stated response time

Customer responsibilities

  • Provide timely access to systems and security settings needed for review.
  • Nominate a primary contact for priorities, approvals, and follow-up.
  • Own implementation of agreed actions unless separately scoped.

Response time

Email support within 3 business days.

Not included

  • Incident response
  • 24x7 monitoring
  • Penetration testing
  • Major implementation projects

Commercial terms

Clear terms for every service plan.

Review the commitment, onboarding, billing, capacity, tools, and plan-change terms before you proceed.

Is there a minimum commitment?+

Yes. Service plans have an initial three-month minimum term and continue monthly after that. During the first 15 days, you may end the agreement in writing; time already used and any approved third-party costs will be deducted before the remaining first payment is refunded.

How does cancellation work after the minimum term?+

Give at least 30 days’ written notice before your next billing date. The plan will end on the billing date that follows the full 30-day notice period. For example, if your billing date is the 1st, notice given on 10 March ends the plan on 1 May.

Do unused hours roll over?+

No. Monthly hours are reserved delivery capacity and do not roll over. Wherever practical, we proactively use available capacity against the priorities agreed with you.

What happens if we need more time?+

Additional work is £150 per hour, excluding VAT, billed in 30-minute increments and only undertaken with prior written approval. Emergency or out-of-hours work is scoped separately. Regular overuse normally indicates that a larger plan would be more suitable.

Are tools and software licences included?+

Hacker Academy’s standard internal delivery and assessment tools, such as the tools used to perform vulnerability assessment and reporting, are included. Licences deployed into or retained in your environment, including Microsoft Defender, EDR, SIEM, cloud, or other third-party products, are charged separately with prior approval.

Can we change plan?+

Upgrades can begin immediately on a pro-rata basis or from the next billing period. Downgrades begin from the next billing period and are subject to the initial minimum term.

Is onboarding charged separately?+

No. Onboarding is included within the first month’s service capacity and covers the initial review, information and access gathering, priority setting, and first action plan. If the work required exceeds the available capacity, we agree the scope, timeline, or additional cost before proceeding.

How does the Growth penetration testing allowance work?+

The allowance is available after six continuous months or provided pro rata according to the subscription term. Testing scope and scheduling are agreed in advance, and unused allowance is not converted into cash or additional monthly hours.

Want to confirm whether Essentials fits?

We can review your environment, priorities, and constraints and confirm whether this is the right starting point.