Security leadership that moves at the speed of your business.
Purple Squirrel Cyber Security gives startups, SMBs and mission-driven organisations genuine, evidenced security leadership, built from twenty years running programs inside banking, retail, energy and government, without the cost or the wait of a full-time hire.
Most businesses need a CISO for about a day a month. Not a $250,000 hire.
A board is asking questions. An investor wants SOC 2 before the deal closes. A customer's security questionnaire just landed in your inbox with a Friday deadline. Whatever brought you here, you're likely comparing more than one provider, and you want a straight answer about what it costs and what you actually get.
The deadline is real
An audit, a tender, or an enterprise deal that won't close without evidence of a working security program.
The budget isn't there yet
A full-time CISO runs $250,000 to $400,000 a year before recruitment costs. Most businesses this size don't need that much, that often.
You're comparing options
Plenty of consultants can talk frameworks. Fewer have actually built and run them, on the inside, under real pressure.
Two ways in, one clear path to ongoing coverage.
Start with a fixed-fee diagnostic, or step straight into a monthly retainer if the need is already clear.
Security Baseline Build
From AUD 7,500 ex GST
A multi-framework posture assessment and maturity score, run against Essential Eight, VPDSS, NIST CSF and CIS Controls at once, with a prioritised remediation roadmap and policy gap register.
- Current-state review across four frameworks in one engagement
- Board-ready maturity scoring and remediation roadmap
- The natural bridge into whichever compliance track comes next
On-Demand Security Leadership Retainer
AUD 2,500–3,000 / month ex GST
One day a month of board-ready risk reporting, security roadmap ownership, and policy and governance oversight, the same calibre of judgement a full-time hire would bring, drawn from twenty years actually running these programs, not just advising on them.
- Governance oversight, incident escalation point of contact
- Vendor and MSSP management included
- Scales to 2–4 days a month, quoted case by case
Audit & Compliance Readiness
Walk into an audit with evidence already assembled, so certification takes weeks off the calendar instead of months.
Security Program Build
The right tooling, chosen once and integrated properly, so spend goes toward controls that actually reduce risk.
Penetration Testing
A vetted specialist runs the test, findings arrive as a plan your team can act on, not a report that sits on a shelf.
Third-Party Risk
Know which vendors can actually hurt you, before one of them does, and monitor it without the ongoing headcount.
Incident Response Advisory
A plan and a rehearsed team, so an incident costs hours of disruption instead of days.
Cyber Insurance Readiness
Walk into a renewal with the evidence insurers ask for already in hand, and negotiate from a position of proof.
Board & Executive Briefings
Give your board or leadership team a clear, confident answer on security, without needing a security background to follow it.
Security Assessment Support
Turn a customer's security questionnaire into a signal of trust instead of a deal-stalling scramble.
Built on the frameworks you already have to answer to.
Every engagement is mapped back to a recognised standard, not a private methodology no one else can audit.
Melbourne and Victoria, four kinds of client.
Wherever you sit, the engagement is shaped around what your business actually needs, not a fixed package.
Tech Startups
No security leader on staff, and SOC 2 standing between them and the next enterprise deal.
SMBs
Currently covered by an IT generalist, or by nobody, and ready for a proper security program.
Mid-Market & Regulated
Deep, evidenced experience across VPDSS, PCI DSS, ISO 27001 and SOC 2.
Not-for-Profits
A dedicated quarterly advisory that gives the board genuine oversight, sized to a mission-driven organisation's real rhythm and resources.
Plenty of consultants can talk about frameworks. Fewer have shipped them.
Built, not just advised
Multiple compliance frameworks, including SOC 2, ISO 27001, PCI DSS, VPDSS and Essential Eight, implemented personally, so certification timelines shrink and rework gets avoided.
Tested under real pressure
Led a major security integration through a large-scale merger, across hundreds of retail locations and thousands of endpoints, proof of handling operational complexity at speed.
Outcomes that show up on the balance sheet
Negotiated a multi-fold increase in a client's cyber insurance coverage, a concrete figure that shows security work reducing financial exposure.
Cross-industry range
Career spanning banking, retail, energy and government, so nobody's regulatory quirks are being learned on your dime.
From first call to ongoing coverage.
A short, deliberately low-friction path. Most clients know their next step by the end of the first call.
Discovery call
Thirty minutes, no cost, to understand what's driving the need right now.
Baseline or scope
A Security Baseline Build for a full picture, or a scoped project if the need is already narrow.
Engage
Sign on for ongoing monthly support, or a one-off project. Either way, you get a simple written agreement upfront that spells out exactly what's included, what it costs, and what happens next.
Report & govern
Board-ready reporting on a set cadence, with a named point of contact for anything urgent.
Ready to see where you actually stand?
Book a free discovery call. Melbourne based, working with clients across Victoria.