What is a cybersecurity consultancy?
A cybersecurity consultancy is a professional-services firm that assesses and improves an organisation's security through paid engagements. The typical services list includes:
- penetration testing and red-team exercises
- compliance assessments against frameworks like ISO 27001, the Essential Eight or APRA CPS 234
- incident response and digital forensics
- security architecture, strategy and board reporting
Australian examples include CyberCX, Deloitte Cyber and the cyber practices of the big accounting firms. The work is genuinely expert and genuinely necessary — for organisations with regulatory obligations, internal IT estates and security budgets to match. Engagements are scoped and priced like legal work: tens of thousands of dollars and up. A business under about 30 staff almost never needs an engagement letter; it needs its website, email, backups and staff awareness checked, which is a different and much cheaper tier of the market.