Buyer FAQ

How working with Dephiant actually works.

Straight answers to the questions security leaders, finance teams, and procurement ask before they engage an advisory firm. For regulatory questions, see the compliance FAQ.

How do engagements usually start?

With a short consult where we review your current state, deadlines, and constraints. If there is a fit, we send a written scope with deliverables, timeline, and a fixed fee before any work begins.

How long is a typical engagement?

Assessments and readiness reviews usually run four to eight weeks. Virtual CISO relationships are ongoing and reviewed quarterly, with a defined off-ramp so you are never locked in.

How is pricing structured?

Project work is fixed fee against a written scope. Ongoing advisory is a monthly retainer based on the hours and seniority the program needs. We publish pricing guidance so you can budget before you talk to us.

Do you work with our existing IT team or provider?

Yes, and that is the usual arrangement. We provide the security leadership and assurance layer while your internal team or managed provider continues to run operations. We define who owns what in writing at the start.

What does onboarding look like in the first 30 days?

We collect current documentation, interview the people who run your systems, review your environment and telemetry, and deliver a prioritized risk picture with a roadmap you can take to leadership.

Which regions and regulations do you cover?

We support clients across North America, EMEA, APAC, Africa, and LATAM, including GDPR, NIS2, DORA, UK data protection, POPIA, NDPR, LGPD, and US federal and state requirements.

Can you help us pass a specific audit?

Yes. We run readiness programs for SOC 2, ISO 27001, HIPAA, PCI-DSS, and CMMC, including control mapping, evidence collection, gap remediation, and auditor coordination. We do not issue the certification ourselves, which keeps our advice independent.

Who will actually do the work?

A named senior advisor leads your engagement from scoping through delivery. Specialists join for cloud, incident response, privacy, or audit work when the scope requires them.

How do you report progress?

You receive regular working updates plus board-ready reporting that translates technical findings into risk, cost, and decisions. Metrics are agreed at the start so progress is measurable.

What happens if we have an incident during the engagement?

We support containment, evidence handling coordination, regulatory notification timelines, and executive communication, then run a post-incident review that feeds back into the roadmap.

Do you sell or resell security tools?

No. We are advisory only, so our recommendations are not tied to vendor commissions. We help you evaluate, procure, and operationalize tools you select.

How do you handle confidentiality and our data?

We work under a mutual NDA, limit collection to what an engagement requires, and follow the practices described on our security and privacy pages. Data handling terms are confirmed in the engagement agreement.

Are you a diverse supplier we can report on?

Yes. Dephiant Consulting Inc. is a Woman-, Minority-, Black-, and Veteran-owned business, including service-connected disabled veteran status, and can support Tier 1 and Tier 2 supplier diversity reporting.

Can you subcontract under our prime contract?

Yes. We team with prime contractors, managed service providers, and law firms. Our partners page covers teaming arrangements and the documentation procurement teams typically request.

What if we are not ready to start?

Use the free assessment and the resource library to understand your gaps at your own pace. When a deadline appears, you will already have the context needed to move quickly.

Still deciding? Ask us directly.

A 20-minute consult is usually enough to tell you whether we can help and what it would take. There is no obligation and no sales script.