Six entry offers from $750 to $1,950. Designed for organizations that want a focused look at one specific question without committing to a larger engagement.
The flagship Defensible Risk Assessment and Governance Implementation Sprint. For organizations ready to do the substantive work of putting a real program in place.
The Security Leadership (vCISO) Retainer. Steady oversight and monthly tracking, with a written report to your board every quarter. For organizations that want sustained progress between formal engagements.
Most engagements with Northline start here. Each entry offer answers one specific question and gives you something tangible to act on, a written deliverable you can take to your board, your insurer, or your next leadership meeting. They’re priced under $2,000 so you can say yes without a procurement conversation, and they’re scoped tightly so you’re not buying a generalist’s wandering opinion.
A 90-minute structured conversation plus a scan of your top security gaps and immediate next steps.
Best for: An organization that is just starting its security journey or a nonprofit that just got a data question from a funder, a bank, or an insurer and had no good answer.
Time Commitment: 90 minute conversation and 30 minutes for review.
What you get: Written Security Snapshot Memo (2–3 pages): top gaps identified, risk level (High / Medium / Low), and 3–5 prioritized next steps.
Natural next step: Defensible Risk Assessment
You pay them every month. Do you know what you are actually getting?
An independent review of your current IT provider contract and practices, so you know where you are covered and where you are not. I ran an IT company for 24 years, so I know what a good contract looks like and what gets left out of a bad one.
Best for: A nonprofit whose IT is one contractor, one volunteer, or one staff person who handles the computers on top of their real job.
Time Commitment: About two hours, plus copy of your contract.
What you get: IT Provider Scorecard (summary with ratings across 8–10 critical areas) plus a written narrative memo highlighting gaps, missing protections, and follow-up questions to bring to your IT provider.
Natural next step: Defensible Risk Assessment
Prepare for your renewal. Know what you’ll be asked and whether your current controls support your answers.
Best for: A nonprofit facing renewal or rising premiums, or one where a board member asked whether the policy would actually pay out.
Time Commitment: About two hours, plus the application and your current policy.
What you get: Cyber Insurance Application Review Summary: current posture vs. insurer expectations, flagged gaps that could affect coverage or claims, and a short list of quick wins to improve position before renewal.
Natural next step: Defensible Risk Assessment
Every one of these ends with a document you own. Where you go next is your call, not mine.
A facilitated 2-hour walk-through of how your team would actually respond to a real scenario. For a nonprofit it is usually a fake wire request that looks like it came from the director. So the first time isn’t the real thing.
Best for: A nonprofit that wants to see what happens in the room when a fake wire request lands in the wrong inbox.
Time Commitment: Two hours for leadership
What you get: Post-Tabletop Summary Memo: scenario overview, key gaps surfaced, roles and decisions that broke down, and 3–5 prioritized recommendations. Suitable for board review.
Natural next step: Security Leadership (vCISO) Retainer or full Risk Assessment
A 60-minute staff training session built around how your organization actually operates, covering donor records, wire fraud, and the emails that target small teams.
Best for: A nonprofit that has never done formal security awareness training, is onboarding new staff, or needs training documentation for an insurer, or a funder.
Time Commitment: 60 minutes of staff time.
What you get: Customized 60-minute staff briefing (on-site or virtual) covering phishing, device handling, password hygiene, and breach reporting. Includes attendance log template, a 1-page staff reference card, and a facilitator summary memo.
Natural next step: IT Provider Review, Snapshot, or Governance Sprint
A focused conversation about how you take card payments and where that data goes. For a nonprofit it means donors, event card readers, and your online donation page.
Best for: A nonprofit taking donations online and at events, with donor records sitting in the middle of it.
Time Commitment: About 90 minutes.
What you get: Payment Security Process Review Memo (2–3 pages): how card data currently flows, observed process gaps, risk observations (especially system / network adjacency), and 3–5 practical recommendations. Includes clarifying questions for your payment processor and IT provider.
Natural next step: Security Snapshot or full Risk Assessment
When you are ready to move beyond a single conversation and put a real program in place, these are the engagements that do the work. Both produce defensible documentation, ranked priorities, and clear ownership, not a stack of generic templates with your name pasted on.
Your assessment runs on SecurityStudio S2Org, an established risk assessment framework used by thousands of organizations. It looks at four areas: your policies and your people, your physical space, the technology inside your walls, and what an outsider can see about you from the internet.
Every assessment produces a gap report against the NIST Cybersecurity Framework. That is the standard most funders, banks, and insurers recognize. So when someone asks how you protect donor and client information, you have a document that answers it against a public standard instead of one consultant’s opinion. That is most of what makes an assessment defensible.
You also get an S2Score, a single number between 300 and 850 that works like a credit score. Your board gets one figure they can understand, track year over year, and put in a grant report.
That fourth area is the one most directors have never seen. It looks at your organization the way an outsider would, without touching anything inside. What shows up in a search, what is reachable from the internet, what your public records give away.
I do not sell SecurityStudio and I earn nothing on it. It is what I measure with.
An independent Risk Assessment that shows where your risks are and what to fix first, with a remediation roadmap you can work from.
This is the core engagement most organizations come to Northline for. You get decision-ready priorities, owners, timelines, and evidence expectations. So leadership can prove safeguards, reduce downtime risk, and move forward confidently without vendor pressure shaping the answer.
Your policies and your evidence live in files you own, in a folder you control. No subscription to keep paying, nothing that disappears if budgets get tight, nothing to migrate if you and I stop working together.
What it costs
Price depends on two things: how many locations you have, and how many people can log in. Find yourself below.
ONE LOCATION
Up to 20 logins
$4,950 · 3-4 weeks
ONE OR TWO LOCATIONS
Up to 50 logins
$6,950 · 4-5 weeks
LARGER OR MULTI-SITE
Three or more locations, or more than 50 logins
$8,950 to $12,950 · 5 to 6 weeks
The rule behind the table: start at $4,950, add about $1,000 for each additional location, and about $1,000 for every thirty people with a login.
Count logins, not staff. Volunteers, board members, contractors, and part-time people all have accounts, and every account takes time to review. Most organizations guess low on this. If you are not sure, that is fine. Fifteen minutes on the phone gets you a firm number.
What else can move the price
• More than one IT vendor, because each one is a separate conversation
• No existing documentation, because the picture gets built from nothing
• Money movement, like wires, grants going out, or payment processing
• Desire for additional 3rd party vendor assessment
WHAT’S INCLUDED
Standards-aligned Risk Assessment covering Administrative, Physical and Technical controls
Ranked Risk Register
90-day Remediation Roadmap
Executive Summary
Board Briefing
Evidence Request and Gap Log
All platform and tool access needed to do the work, included in the price
HOW IT RUNS
Engagement runs three to six weeks, depending on which band you land in. Discovery and system mapping come first. Then the core assessment against requirements. Interviews, the risk register, the remediation roadmap, and evidence documentation come together after that. The last stretch is review, executive summary, and a live briefing with your leadership or your board.
Time Commitment: 10 to 15 hours across your team over the course of the engagement. 90 minutes for the final presentation.
Natural next step: Governance Implementation Sprint or Security Leadership Retainer.
A governance-first build-out of policies, controls, vendor practices, and the evidence binder that proves your safeguards are actually operating.
A Risk Assessment tells you what’s wrong. The Governance Sprint puts the structure in place to keep it right. The outcome is plain-English findings and a practical governance cadence covering metrics, responsibilities, and a prioritized roadmap, so your organization stops relying on assumptions and starts managing security as an ongoing program. Designed to work even with lean internal IT or an outside provider doing it all.
WHAT’S INCLUDED
Customized policy set (written to how your organization actually operates, not dropped in from a template)
Evidence binder structure and roadmap
Assigned ownership across roles
Governance cadence setup (meeting and review rhythms)
Quarterly metric dashboard template
HOW IT RUNS
Engagement runs 8–12 weeks after you have completed the Risk Assessment. The bulk of the time is the customized policy set. Not boilerplate. Policies tailored to your IT arrangement, your donor systems, grant obligations, program tools, your vendor mix, and your actual workflows. Throughout, you’re building the muscle to run governance as an ongoing practice, not a one-time deliverable.
Time Commitment: About 20 to 30 hours across the team.
Natural next step: Security Leadership Retainer for ongoing oversight
A Risk Assessment and Governance Sprint produce documentation. Ongoing support produces results. The Security Leadership (vCISO) Retainer is for organizations that want continued forward motion and someone in their corner between formal engagements.
Price depends on how many people can log in. Locations do not change it, because the monthly work follows accounts and vendors, not buildings.
Up to 20 logins: $1,950 per month, up to 8 hours included
21 to 50 logins: $2,950 per month, up to 12 hours included
51 or more logins: from $3,950 per month, up to 18 hours included
Pragmatic cybersecurity and technology strategy support for organizations that need steady progress, not a one-time report.
Through a light monthly cadence and quarterly executive reporting, we track remediation, refresh the risk register, strengthen vendor and incident readiness, and turn security work into measurable outcomes and board decisions. This is independent leadership and accountability that complements your IT provider, keeping priorities aligned to the work you actually do, uptime, and what’s actually achievable in an organization.
WHAT’S INCLUDED EACH MONTH
Monthly remediation tracking with status updates and owner follow-through
Roadmap/Risk register refresh: new vendors, staff changes, system changes flagged and scored
Vendor review/oversight (3rd Party Vendors, new tools, IT provider spot-checks)
Incident readiness (tabletop prep, response plan review, backup verification)
Routine vulnerability scanning, external and internal, with findings added to your risk register
Quarterly executive reporting in board-ready language
Async advisory: email questions, quick calls, ad hoc guidance as needed
Time Commitment: About an hour per month, plus two hours every quarter for review.
| Engagement | Price | Delivery | Best For |
|---|---|---|---|
| Security Snapshot | $1,500 | 5 business days | First look at security posture; no formal program yet |
| IT Provider Review | $1,500 | 5 business days | Independent check on what your IT provider is actually doing |
| Cyber Insurance Application Review | $1,950 | 5 business days | Renewal prep; ensuring controls match application answers |
| Incident Response Tabletop | $900 | 3 business days | Stress-testing your response before a real incident |
| Security Awareness Briefing | $750 | Scheduled | Staff training tailored to how your organization operates |
| Payment Security Review | $750 | 5 business days | How card data flows; risk where payment terminals meet other systems |
| Defensible Risk Assessment | From $4,950 | 3–4 wks | Defensible assessment with ranked register and 90-day plan |
| Governance Implementation Sprint | $9,950 | 8–12 wks | Policies, evidence binder, governance cadence, ownership |
| Security Leadership (vCISO) Retainer | $1,950 to $3,950/mo | 12-mo min | Ongoing oversight; quarterly executive reporting |
Because hiding prices forces every visitor into a sales call to find out if they can afford a conversation. That’s not how I want to work, and it’s not how the people I respect want to buy. The prices on this page are the prices.
Two questions settle it most of the time. How many locations do you have, counting anywhere staff regularly work? And how many people have a login of any kind, counting part-timers, contractors, and anyone else with an account? Tell me those two numbers and I will give you a firm price on the call, not a proposal a week later. If something about your setup changes the scope, I will tell you before we start rather than after.
Your IT company sells you services and tools. I do not. No referral fees. No vendor partnerships. No commission on anything I recommend. When your IT company reviews their own work, you get the answer they’re comfortable giving you. When I review it, you get the answer.
You do not buy anything. Everything needed to do the work is included in what you pay me.
Your assessment is done in SecurityStudio, which holds your score, your risk list, and your plan. You have access while the engagement runs, and everything in it is delivered to you as documents you keep. If you want that access to stay open month to month after the assessment ends, that comes with the retainer.
Your policies and your evidence do not live in a platform at all. They live in documents you own, in a folder you control. That is deliberate. Most software built for this is priced for large companies, and a small organization should not be paying a subscription to hold its own paperwork.
Anything else I use during the assessment is my own equipment. You never touch it and you never pay for it separately.
I do not mark anything up and I take no commission on any tool I use or recommend.
No. A good IT provider is doing real, valuable work. Patching, monitoring, backups, support. My role is independent oversight that complements that work and gives you confidence the right things are actually happening. Most of my clients keep their IT company and run me alongside.
Northline executes a Non-Disclosure Agreement with every client before any engagement begins. All work product is yours; nothing is shared with vendors or third parties without your written consent.
Most nonprofits are not directly regulated. That does not mean you are off the hook. Your funders, your bank, your insurer, and your board still ask hard questions about donor and client records, and state breach laws still apply. Your work with me gets built on standards that fit you, not on a rule that does not.
Then start with an entry offer. Every one of them produces something written you can act on, and none of them requires you to buy the next thing. Needing something and being able to afford it are two different problems. I would rather help you with the second one honestly than pretend the first one went away.
Yes. Engagements are delivered remotely, so location isn’t a barrier. Your risk register, evidence, and reporting are files you can open from anywhere. On-site work is available regionally. If you’re wondering whether distance is a problem, it probably isn’t. Reach out and we’ll talk.
Every engagement on this page is done by me, not handed off to a junior analyst. I am Tom Polk. Thirty years in IT leadership, most recently as CIO and Chief Security Officer for a multi-state healthcare group.
If you’re new and exploring. Book a 30-minute consultation. No pitch, no pressure. We’ll talk through what you’re actually worried about.
If you have a specific question. Pick the entry offer that fits and we’ll get on a call to scope it.
If you’re ready for a Risk Assessment. Send a note describing your organization (number of locations, Donor platform, IT arrangement, staff size) and we’ll talk timing.
© 2026 NORTHLINE ADVISORS, LLC