§ 05 — Pricing

Fixed fees.
No surprises.

Every engagement is quoted upfront with a flat hour band and a fixed rate. You know the number before we start — no open-ended billing, no scope creep invoices.

Show in
Detection
Blue team operations
Hands-on with your SIEM or EDR. Noisy rules tuned, missing detections written, playbooks your on-call can actually follow at 2am.
Rule tune-up recommended
6–8 hrs · up to 5 rules + findings note
R 7,500
flat fee
Playbook pack
8–10 hrs · 2 IR playbooks, your tooling
R 12,000
flat fee
Audit
Independent security audit
Clear, evidence-based read of your infrastructure, policy and access controls. Findings graded honestly — no inflated severity to justify the invoice.
Snapshot audit recommended
8–10 hrs · one cloud env · written report
R 14,500
flat fee
IAM deep-dive
6–8 hrs · access control review only
R 9,500
flat fee
Triage
Alert investigation
Drowning in alerts your team can't keep up with? Send me the queue. Signal sorted from noise, written up with enough context to action it.
Alert batch (30) recommended
4–6 hrs · async · findings doc delivered
R 5,500
per batch
Per incident
2–3 hrs · min 2 incidents per engagement
R 2,800
per incident
Forensics
Log review & hunting
Targeted hunts in endpoint, firewall and cloud audit logs. The kind of work that needs someone with time to sit with the data and follow a thread.
Targeted hunt recommended
8–10 hrs · single hypothesis · written summary
R 11,000
flat fee
Hourly
min 3 hrs · flexible scope
R 950
per hour
// Case study discount

Taking on your first engagement with ThreatBX? 20% off any fixed-fee scope in exchange for a written testimonial and permission to anonymise the findings for the portfolio. Mention it in your first email.

From first email to written findings.

i.

Conversation

A 30-minute call to understand what's actually on your plate. No NDA needed at this stage.

ii.

Scope & quote

A short written scope with a fixed hour band and a flat rate. You sign it, we start. No ambiguity.

iii.

The work

I work in your tooling where possible. Turnaround is typically 2–3 weeks from kick-off. Daily notes if you want them, silence if you don't.

iv.

Findings

A written report — severity, evidence, recommendation. One follow-up call included.

Got a backlog nobody has time to read? That's the conversation.

Admin@threatbx.com ↗