Two Kinds of Client. Different Offers for Each.
TinBOX serves two genuinely different buyers, not one generic pitch stretched across both. Find the segment that matches where your organization actually stands.
Whether you call it a vCISO, fractional CIO, or virtual CTO, the model underneath is the same: named executive leadership, delivered as one coordinated retainer instead of four separate searches.
No Internal Security or IT Leadership Yet
You've outgrown ad hoc IT, but a full-time CISO, CPO, CTO, or CIO isn't justified yet. This is the core TinBOX client, coordinated leadership as one engagement, plus scoped projects for a specific outcome.
Advisory Retainer
Coordinated CISO, CIO, CTO, and privacy leadership as one standing team, in three tiers, plus the Incident Response Retainer add-on for existing clients.
- Tiers set by monthly hours, from 10 to 43
- Essentials, Growth, or Full Stack
Projects & Assessments
Point-in-time engagements for a defined outcome, security and compliance readiness, IT process design, privacy program builds, development, and AI governance.
- Technology Strategy, IT Operations, Security & Compliance, Engineering & Cloud, Proposal & Bid Support
- No ongoing commitment required
You Already Have Security or IT Leadership
A different buyer entirely, organizations with their own internal team, buying independent quarterly assurance rather than embedded leadership. TinBOX works alongside your team, not in place of it, with sole-authorship independence in the deliverable itself.
Board Cyber Risk Briefing
Independent quarterly security risk assessment presented directly to your board or leadership team, a second, outside opinion your internal team's own reporting can't fully provide.
- 13 hours/quarter, delivered personally
- Independent validation, not a rubber stamp on internal findings
Board IT & Digital Strategy Briefing
The same independent model, applied to IT and digital strategy, an outside check on technology direction and investment, reported directly to leadership.
- 13 hours/quarter, delivered personally
- Independent validation, not a rubber stamp on internal findings
Buying or Selling a Company
Technology risk doesn't surface at closing. It surfaces after. Independent technology, security, and privacy due diligence across the full deal lifecycle, for buyers evaluating targets and sellers preparing for scrutiny.
M&A Due Diligence
One team, one deliverable, no vendor coordination. From a fixed-fee pre-LOI screen to the Full Diligence Package, integration planning, and seller-side readiness.
- Buy-side: pre-LOI through post-close, 6 engagements
- Sell-side: technology and security readiness before the data room
- Full Diligence Package from $30,000, tech and security DD in one report
Not sure which segment fits?
Start with the Technology Strategy Assessment, a fixed-fee, no-pressure look at where things stand, with a clear recommendation on the right path forward.
Book the Technology Strategy Assessment →