Who this is for
- Growing organisations with customer-facing systems or recurring remediation work.
- Teams that need scheduled security testing built into the year.
- Businesses that need both technical and executive reporting.
Growth plan
Growth combines regular advisory time, vulnerability and remediation support, scheduled testing allowance, and clearer reporting for leadership and technical teams.
Monthly allocation
A stronger retainer for organisations that need recurring security improvement and practical delivery support.
First 90 days
The first month focuses heavily on onboarding and understanding your environment. Work is then planned around priorities and the monthly time allocation.
Month 1
Month 2
Month 3
Monthly time
Actual allocation varies based on your priorities, access, risk, and the work already completed. The plan defines capacity, not an unlimited list of deliverables.
Included services
Services are delivered within the available consultant time and agreed priorities for the month.
Related services
These service pages explain the underlying work that can be delivered inside this plan, depending on monthly priorities and available consultant time.
Remediation tracking, validation, risk tagging and recurring exposure reduction.
Learn more →
Scheduled penetration or application security testing allowance for infrastructure, cloud, web, API, or mobile scope.
Learn more →
Cloud and on-prem review work for recurring security improvement needs.
Learn more →
Ongoing security delivery support with technical and executive reporting.
Learn more →
Response time
Email support within 1 business day.
Commercial terms
Review the commitment, onboarding, billing, capacity, tools, and plan-change terms before you proceed.
Yes. Service plans have an initial three-month minimum term and continue monthly after that. During the first 15 days, you may end the agreement in writing; time already used and any approved third-party costs will be deducted before the remaining first payment is refunded.
Give at least 30 days’ written notice before your next billing date. The plan will end on the billing date that follows the full 30-day notice period. For example, if your billing date is the 1st, notice given on 10 March ends the plan on 1 May.
No. Monthly hours are reserved delivery capacity and do not roll over. Wherever practical, we proactively use available capacity against the priorities agreed with you.
Additional work is £150 per hour, excluding VAT, billed in 30-minute increments and only undertaken with prior written approval. Emergency or out-of-hours work is scoped separately. Regular overuse normally indicates that a larger plan would be more suitable.
Hacker Academy’s standard internal delivery and assessment tools, such as the tools used to perform vulnerability assessment and reporting, are included. Licences deployed into or retained in your environment, including Microsoft Defender, EDR, SIEM, cloud, or other third-party products, are charged separately with prior approval.
Upgrades can begin immediately on a pro-rata basis or from the next billing period. Downgrades begin from the next billing period and are subject to the initial minimum term.
No. Onboarding is included within the first month’s service capacity and covers the initial review, information and access gathering, priority setting, and first action plan. If the work required exceeds the available capacity, we agree the scope, timeline, or additional cost before proceeding.
The allowance is available after six continuous months or provided pro rata according to the subscription term. Testing scope and scheduling are agreed in advance, and unused allowance is not converted into cash or additional monthly hours.
We can review your environment, priorities, and constraints and confirm whether this is the right starting point.