Hacker AcademyHacker Academy

Starter plan

Regular visibility and guidance for teams ready to move beyond ad-hoc security.

Starter adds more monthly capacity for vulnerability review, risk-based prioritisation, exposure monitoring, and remediation guidance.

Monthly allocation

16 hours / month consultant time

£1,750 / month, excluding VAT
Everything in Essentials
Monthly vulnerability review
Action-focused report
2 business day email support

A practical monthly rhythm for teams that need recurring visibility, decisions, and follow-up support.

Who this is for

  • Small organisations with recurring security questions or customer assurance pressure.
  • Teams that need monthly vulnerability visibility and prioritisation.
  • Businesses that want regular advisory support without a dedicated security hire.

Who this is not for

  • Teams needing scheduled penetration testing included in the plan.
  • Organisations that require same-day support or phone response.
  • Large environments requiring broad delivery oversight.

First 90 days

A phased start that keeps expectations clear.

The first month focuses heavily on onboarding and understanding your environment. Work is then planned around priorities and the monthly time allocation.

Month 1

Onboarding and priority baseline

  • Understand the environment, tools, access, and current security work.
  • Review immediate identity, workspace, and exposure priorities.
  • Agree the monthly review and reporting cadence.

Month 2

Vulnerability and exposure review

  • Review internal vulnerability signals and external exposure.
  • Prioritise findings based on risk and practical remediation effort.
  • Support the first remediation action plan.

Month 3

Recurring security rhythm

  • Track remediation progress and blockers.
  • Review security advisory topics and best-practice decisions.
  • Produce an action-focused monthly report.

Monthly time

How your consultant time is typically used.

Actual allocation varies based on your priorities, access, risk, and the work already completed. The plan defines capacity, not an unlimited list of deliverables.

ActivityTypical hours
Monthly advisory call1
Vulnerability and exposure review4
Risk-based prioritisation3
Remediation guidance4
Monthly report and follow-up4

Included services

What can be covered inside the monthly allocation.

Services are delivered within the available consultant time and agreed priorities for the month.

Vulnerability visibility

  • Monthly internal vulnerability review
  • External exposure monitoring
  • Risk-based prioritisation

Advisory support

  • Monthly advisory call
  • Security best-practice guidance
  • Action plan and remediation support

Reporting

  • Action-focused monthly report
  • Prioritised recommendations
  • Progress and blocker tracking

Deliverables

  • Monthly 60 minute advisory call
  • Monthly vulnerability review summary
  • Action-focused monthly report
  • Email support within the stated response time

Customer responsibilities

  • Provide access to vulnerability data, security tools, and relevant system owners.
  • Review priorities and confirm remediation ownership.
  • Implement agreed changes or separately scope delivery support.

Response time

Email support within 2 business days.

Not included

  • Scheduled penetration testing
  • Same-day support
  • 24x7 monitoring
  • Incident response

Commercial terms

Clear terms for every service plan.

Review the commitment, onboarding, billing, capacity, tools, and plan-change terms before you proceed.

Is there a minimum commitment?+

Yes. Service plans have an initial three-month minimum term and continue monthly after that. During the first 15 days, you may end the agreement in writing; time already used and any approved third-party costs will be deducted before the remaining first payment is refunded.

How does cancellation work after the minimum term?+

Give at least 30 days’ written notice before your next billing date. The plan will end on the billing date that follows the full 30-day notice period. For example, if your billing date is the 1st, notice given on 10 March ends the plan on 1 May.

Do unused hours roll over?+

No. Monthly hours are reserved delivery capacity and do not roll over. Wherever practical, we proactively use available capacity against the priorities agreed with you.

What happens if we need more time?+

Additional work is £150 per hour, excluding VAT, billed in 30-minute increments and only undertaken with prior written approval. Emergency or out-of-hours work is scoped separately. Regular overuse normally indicates that a larger plan would be more suitable.

Are tools and software licences included?+

Hacker Academy’s standard internal delivery and assessment tools, such as the tools used to perform vulnerability assessment and reporting, are included. Licences deployed into or retained in your environment, including Microsoft Defender, EDR, SIEM, cloud, or other third-party products, are charged separately with prior approval.

Can we change plan?+

Upgrades can begin immediately on a pro-rata basis or from the next billing period. Downgrades begin from the next billing period and are subject to the initial minimum term.

Is onboarding charged separately?+

No. Onboarding is included within the first month’s service capacity and covers the initial review, information and access gathering, priority setting, and first action plan. If the work required exceeds the available capacity, we agree the scope, timeline, or additional cost before proceeding.

How does the Growth penetration testing allowance work?+

The allowance is available after six continuous months or provided pro rata according to the subscription term. Testing scope and scheduling are agreed in advance, and unused allowance is not converted into cash or additional monthly hours.

Want to confirm whether Starter fits?

We can review your environment, priorities, and constraints and confirm whether this is the right starting point.