Hacker AcademyHacker Academy

Growth plan

Ongoing security delivery for growing organisations with recurring needs.

Growth combines regular advisory time, vulnerability and remediation support, scheduled testing allowance, and clearer reporting for leadership and technical teams.

Monthly allocation

32 hours / month consultant time

£3,250 / month, excluding VAT
Everything in Starter
Testing allowance
Quarterly strategy review
1 business day email support

A stronger retainer for organisations that need recurring security improvement and practical delivery support.

Who this is for

  • Growing organisations with customer-facing systems or recurring remediation work.
  • Teams that need scheduled security testing built into the year.
  • Businesses that need both technical and executive reporting.

Who this is not for

  • Small teams needing only light advisory support.
  • Organisations expecting unlimited testing or major project delivery.
  • Teams requiring same-day phone support or weekly executive cadence.

First 90 days

A phased start that keeps expectations clear.

The first month focuses heavily on onboarding and understanding your environment. Work is then planned around priorities and the monthly time allocation.

Month 1

Onboarding and risk inventory

  • Understand systems, assets, cloud services, and existing security work.
  • Create an initial risk and remediation view.
  • Agree the testing allowance approach and priority roadmap.

Month 2

Remediation and validation rhythm

  • Review vulnerability and exposure priorities.
  • Track remediation ownership and validate progress.
  • Prepare leadership and technical reporting views.

Month 3

Strategy review and testing plan

  • Run a quarterly strategy review.
  • Confirm annual testing targets and timing.
  • Adjust roadmap priorities based on current risk.

Monthly time

How your consultant time is typically used.

Actual allocation varies based on your priorities, access, risk, and the work already completed. The plan defines capacity, not an unlimited list of deliverables.

ActivityTypical hours
Advisory and strategy meetings4
Vulnerability and exposure review8
Remediation tracking and validation8
Cloud / on-prem security review6
Executive and technical reporting6

Included services

What can be covered inside the monthly allocation.

Services are delivered within the available consultant time and agreed priorities for the month.

Testing and validation

  • Scheduled penetration testing allowance
  • Remediation validation
  • Risk-based retest planning

Risk management

  • Asset inventory and risk tagging
  • Cloud and on-prem security review
  • Priority advisory support

Leadership reporting

  • Quarterly strategy review
  • Executive reporting
  • Technical reporting

Deliverables

  • Quarterly 90 minute strategy review
  • Executive and technical reports
  • Remediation tracking view
  • Scheduled penetration testing allowance up to 3 days per year, available after 6 continuous months or pro rata

Customer responsibilities

  • Provide access to relevant assets, vulnerability data, and technical owners.
  • Support scheduling and scoping of testing activities.
  • Assign remediation owners and participate in review meetings.

Response time

Email support within 1 business day.

Not included

  • Unlimited penetration testing
  • Full-time embedded delivery
  • 24x7 monitoring
  • Incident response retainer

Commercial terms

Clear terms for every service plan.

Review the commitment, onboarding, billing, capacity, tools, and plan-change terms before you proceed.

Is there a minimum commitment?+

Yes. Service plans have an initial three-month minimum term and continue monthly after that. During the first 15 days, you may end the agreement in writing; time already used and any approved third-party costs will be deducted before the remaining first payment is refunded.

How does cancellation work after the minimum term?+

Give at least 30 days’ written notice before your next billing date. The plan will end on the billing date that follows the full 30-day notice period. For example, if your billing date is the 1st, notice given on 10 March ends the plan on 1 May.

Do unused hours roll over?+

No. Monthly hours are reserved delivery capacity and do not roll over. Wherever practical, we proactively use available capacity against the priorities agreed with you.

What happens if we need more time?+

Additional work is £150 per hour, excluding VAT, billed in 30-minute increments and only undertaken with prior written approval. Emergency or out-of-hours work is scoped separately. Regular overuse normally indicates that a larger plan would be more suitable.

Are tools and software licences included?+

Hacker Academy’s standard internal delivery and assessment tools, such as the tools used to perform vulnerability assessment and reporting, are included. Licences deployed into or retained in your environment, including Microsoft Defender, EDR, SIEM, cloud, or other third-party products, are charged separately with prior approval.

Can we change plan?+

Upgrades can begin immediately on a pro-rata basis or from the next billing period. Downgrades begin from the next billing period and are subject to the initial minimum term.

Is onboarding charged separately?+

No. Onboarding is included within the first month’s service capacity and covers the initial review, information and access gathering, priority setting, and first action plan. If the work required exceeds the available capacity, we agree the scope, timeline, or additional cost before proceeding.

How does the Growth penetration testing allowance work?+

The allowance is available after six continuous months or provided pro rata according to the subscription term. Testing scope and scheduling are agreed in advance, and unused allowance is not converted into cash or additional monthly hours.

Want to confirm whether Growth fits?

We can review your environment, priorities, and constraints and confirm whether this is the right starting point.