CHARITY PRACTICE · TIER SELECTOR

Find your practice tier.

Five questions. About 90 seconds. No email required.

Our charity practice runs five tiers — from a one-week posture snapshot to an embedded vCISO programme. Answer five questions; we recommend where to start.

FIVE QUESTIONS

Data sensitivity

What kind of personal data does your charity hold?

Headcount

How many staff have email accounts or system access?

Incident history

Have you had a security incident in the last 24 months?

Governance pressure

Are your board or funders asking about cybersecurity?

Provincial scope

Where do you operate?

RECOMMENDED — TIER 0

Posture Snapshot.

A one-week, fixed-fee assessment. The right place to start.

  • Format. Fixed-fee, ≈1 week.
  • Output. A board-ready posture document and remediation roadmap.
  • Best for. Charities formalizing cybersecurity for the first time.

RECOMMENDED — TIER 1

Stabilisation.

Specific high-risk gaps need closing now.

  • Format. Project-based, typically 30 days.
  • Output. Closed gaps and a 30-day stabilisation report.
  • Best for. Charities with known issues or a recent incident.
  • Next step. A Posture Snapshot first, to scope the work.

RECOMMENDED — TIER 2

Essentials.

Foundational managed controls and quarterly reporting.

  • Format. Monthly retainer.
  • Includes. EDR, email controls, quarterly reviews, an annual tabletop, and direct senior contact.
  • Best for. Charities with established operations and growing oversight.

RECOMMENDED — TIER 3

Secure.

A mature programme with active monitoring.

  • Format. Monthly retainer, broader scope.
  • Includes. Continuous monitoring (Sentinel Watch™), exposure management, a full policy library, vendor risk, and compliance documentation.
  • Best for. Mid-to-large charities with complex or regulated operations.

RECOMMENDED — TIER 4

Guardian.

Continuous protection at scale.

  • Format. Monthly retainer, full programme scope.
  • Includes. An embedded vCISO, 24/7 monitoring, annual exposure validation, board reporting, and insurance & audit liaison.
  • Best for. National charities, regulated programmes, or organizations with material cybersecurity risk.

CHARITY PRACTICE TIERS

  1. TIER 0: Posture Snapshot

    A one-week, fixed-fee assessment. The right place to start. Best for charities formalizing cybersecurity for the first time.

    Fixed-fee · ≈1 week · board-ready posture document and remediation roadmap

  2. TIER 1: Stabilisation

    Specific high-risk gaps need closing now. Best for charities with known issues or a recent incident; a Posture Snapshot comes first, to scope the work.

    Project-based · typically 30 days · closed gaps and a 30-day stabilisation report

  3. TIER 2: Essentials

    Foundational managed controls and quarterly reporting. Best for charities with established operations and growing oversight.

    Monthly retainer · EDR · email controls · quarterly reviews · annual tabletop · direct senior contact

  4. TIER 3: Secure

    A mature programme with active monitoring. Best for mid-to-large charities with complex or regulated operations.

    Monthly retainer · broader scope · Sentinel Watch™ (continuous monitoring) · exposure management · full policy library · vendor risk · compliance documentation

  5. TIER 4: Guardian

    Continuous protection at scale. Best for national charities, regulated programmes, or organizations with material cybersecurity risk.

    Monthly retainer · full programme scope · embedded vCISO · 24/7 monitoring · annual exposure validation · board reporting · insurance & audit liaison