Consulting Services

Trusted Cybersecurity Consulting and Implementation Services

Hands-on help from Blue Lantern Security's founder for teams that need a security plan they can actually execute: strategy and roadmaps, SOC 2 readiness, AI security, SIEM and SOAR builds, and cloud security automation. You work directly with the engineer doing the work, not an account manager.

30-minute discovery call, no charge and no obligation. Engagements are billed at $200 per hour plus travel where on-site work is needed.

Bring your own toolset

We work with what you already have

You do not need to buy anything new to work with us. Most engagements start with the SIEM, cloud accounts, EDR, firewalls, and identity platform you already run, and the job is to make them work together properly. If something is genuinely missing, we will tell you.

No rip and replace

Splunk, Sentinel, XSOAR, AWS, GCP, Azure, Google Workspace, Microsoft 365, and whatever EDR and firewalls you run. We deploy, integrate, and tune the platforms you have already paid for rather than proposing a migration you did not ask for.

Vendor-neutral advice

No reseller margins and no referral fees. When a tool recommendation is needed, it is based on what fits your team and budget, and we will tell you when the cheaper or free option is the right one.

Delivered as code you keep

Playbooks, scripts, integrations, and infrastructure land in your repositories as Terraform, AWS CDK, Python, or PowerShell, documented so your team can run and change them without us.

When you need this

Usually something specific is driving the work

These are the situations that most often lead to a discovery call.

A customer sent a security questionnaire

An enterprise deal is waiting on answers you are not sure how to give, or on a SOC 2 report you do not have yet.

The insurance renewal asks for controls you have not built

MFA everywhere, EDR, backups, and an incident response plan, due before the policy renews.

The SIEM still leaves gaps and produces too much noise

Splunk, Sentinel, or XSOAR is running, but log coverage never reached the goal, alerts are mostly noise, and the automations were never built.

AI arrived before the policy did

Half the company is using AI tools connected to Drive, mail, and code, and nobody knows what those tools can reach.

Who you work with

Meet your consultant

Every engagement is delivered personally by Will Burger, Blue Lantern Security's founder and CEO. No handoff to a junior team after the sales call.

Will Burger

Founder and CEO, Blue Lantern Security

Will has spent his career on the building side of security: as a security engineer for defense research contracts, as a consultant at EY where he led SIEM and SOAR implementations and cloud security strategy for enterprise clients, and as an early engineer at the startup TalonX, which became Longbow Security and was acquired by Veracode. At Veracode he worked as a product manager on what became Veracode Risk Manager before founding Blue Lantern Security to bring enterprise-grade monitoring to small businesses.

He has delivered enterprise security programs for telecom, financial services, entertainment and gaming, and retail clients, and has also built a security product with a small team and a small budget. Consulting engagements draw on both.

  • BackgroundDefense research contracting, EY consulting, TalonX and Longbow Security (acquired by Veracode)
  • IndustriesTelecommunications, financial services, entertainment and gaming, retail, and small businesses
  • SpecialtiesSIEM and SOAR implementation, cloud security strategy and automation, security product development
  • Working styleHands-on. Will writes the playbooks, the scripts, and the roadmap himself

Services

Eight areas, one practitioner

Pick the area that matches your problem, or describe the problem on the discovery call and we will scope it together.

Cybersecurity strategy and roadmap

A security roadmap your business can actually execute

A right-sized security plan that matches your business, your budget, and the threats that actually apply to you. You get a prioritized roadmap with owners, sequencing, and cost estimates, written so leadership can approve it and engineers can execute it.

  • Current-state assessment and gap analysis
  • Prioritized 6, 12, and 24-month roadmap
  • Budget and staffing recommendations
  • Board and executive briefing material

Good fit: founders and IT leads who need a defensible plan before the next funding round, audit, or insurance renewal.

Small business security: tool selection and rollout

The right tools for a 20-person company, not a 20,000-person one

Most small businesses need a handful of tools configured correctly rather than an enterprise stack. We help select them, size the licensing, and stand them up: identity and MFA, endpoint protection, email security, backups, and monitoring.

  • Vendor-neutral tool selection with cost comparison
  • Google Workspace and Microsoft 365 hardening
  • EDR, firewall, and backup deployment
  • Cyber insurance questionnaire readiness

Good fit: companies under 200 people without a dedicated security hire.

SOC 2 readiness strategy

Get SOC 2 ready without hiring a compliance team

We handle the design and implementation side of SOC 2 Type I or Type II. That means scoping the trust services criteria your customers care about, mapping the controls you already have, designing and implementing the ones you are missing, and preparing your team for the auditor. Evidence collection is left to your compliance platform, which does it far better than anyone can by hand.

  • Scope and criteria selection
  • Control mapping and policy set
  • Control implementation across identity, cloud, endpoints, and code
  • Compliance platform setup guidance so evidence collection runs itself
  • Auditor selection and readiness review

Good fit: SaaS and services companies whose first enterprise deal is waiting on a report.

AI security and implementation strategy

Adopt AI without leaking your data, and use it to run security better

Your team is likely already using AI tools that can reach company data, and you may also want to use AI to run security more efficiently. We inventory what has access, set a practical AI policy, and design how AI fits into detection, triage, and code review without creating new exposure.

  • AI and OAuth app access review across Google Workspace and Microsoft 365
  • Practical AI acceptable-use policy and data handling rules
  • Securing internal AI agents, MCP servers, and model integrations
  • AI-assisted triage and code scanning pipelines

Good fit: teams adopting AI faster than their security program can keep up.

SIEM and SOAR consulting and implementation

Deploy, integrate, and tune the SIEM and SOAR platform you already own

Bring your own toolset. We deploy, integrate, and tune Splunk, Microsoft Sentinel, Splunk SOAR (Phantom), and Cortex XSOAR so the platform does the job it was bought for: finely tuned detections your analysts trust, working integrations with your EDR, firewalls, identity, and ticketing tools, and automations that run reliably. Delivered for telecom, finance, entertainment, and retail environments, from initial deployment and log onboarding through automated response.

  • Deployment, migration, and licensing right-sizing
  • Log source onboarding, data normalization, and integrations with the tools you run
  • Detection tuning: fewer, higher-quality alerts instead of more noise
  • SOAR playbook design, build, and rollout

Good fit: security teams whose SIEM or SOAR is noisy, under-integrated, or still not fully deployed.

Cloud security automation

Catch cloud misconfigurations as they happen, not at the next audit

Turn cloud security from a quarterly audit into something that runs continuously. We build event-driven guardrails on AWS, GCP, and Azure using native services, so misconfigurations, risky identities, and exposed secrets are detected quickly and routed to the right people, with automated remediation for the cases where you decide it is safe.

  • IAM and identity risk review (users, roles, service principals)
  • Lambda, Cloud Functions, and Azure Functions for detection, alerting, and approved remediation workflows
  • Guardrails for new accounts, projects, and subscriptions, delivered as Terraform or AWS CDK
  • Secrets and PII scanning in pipelines and storage

Good fit: engineering-led companies with more cloud than security headcount.

Playbook, script, and integration development

Automate the response work your team still does by hand

Response playbooks, automation scripts, and integrations between the tools you already own, delivered as working, documented code your team can maintain after the engagement ends.

  • XSOAR and Splunk SOAR playbooks and custom integrations
  • Python and PowerShell automation for EDR, firewall, and identity platforms
  • API integrations between ticketing, chat, SIEM, and security tools
  • GitHub Actions and CI security checks

Good fit: teams with a clear backlog and no one free to build it.

Security process and operations design

Security processes people will actually follow

We design incident response, vulnerability management, access review, and onboarding and offboarding processes that fit the size of your team, with clear owners, runbooks, and metrics.

  • Incident response plan and tabletop exercise
  • Vulnerability and patch management workflow
  • Access review, joiner and leaver, and vendor risk processes
  • Security metrics and reporting for leadership

Good fit: teams that bought the tools and still feel disorganized.

How it works

From first call to finished work

No retainers you did not ask for and no discovery phase that costs more than the work. Most engagements follow four steps.

Discovery call

A free 30-minute conversation about your environment, what is driving the work, and whether we are the right fit. If we are not, we will say so.

Scope and estimate

A short written scope with deliverables, an hour estimate, and a not-to-exceed number. You approve before any billable work starts.

Do the work

Weekly check-ins and a shared task list, so you always know what has been done and what is next. Time is tracked to the quarter hour and invoiced monthly.

Hand off

Documentation, runbooks, and a walkthrough with your team so you can run everything without us.

Platforms and tools

Technology we have implemented

We are vendor-neutral on what you should buy, and experienced on what you already own. These are platforms Will has designed, deployed, or integrated in production, and the delivery mechanisms we use to ship them as code your team can version and rerun.

SIEM and SOAR

  • Splunk Enterprise and Cloud
  • Splunk SOAR (Phantom)
  • Cortex XSOAR
  • Microsoft Sentinel

Cloud

  • AWS (Lambda, IAM, EventBridge)
  • Google Cloud (Cloud Functions, IAM)
  • Azure (Functions, Entra ID)
  • Google Workspace
  • Microsoft 365

Endpoint, network, and identity

  • EDR platforms
  • Next-generation firewalls
  • MFA and SSO

Delivery and automation

  • Terraform
  • AWS CDK
  • Python and PowerShell
  • GitHub Actions

Pricing

Simple hourly pricing, no retainer required

We publish the rate because you should not need a sales call to find it out. Every engagement gets a written estimate and a not-to-exceed cap before work begins.

Fixed-scope starters

These packaged engagements are the most common first projects. Hours are typical ranges at the standard rate and are confirmed in your written scope.

Security Strategy Sprint

Typically 12 to 20 hours

Current-state review, prioritized roadmap, and an executive summary you can take to leadership or your insurer.

SOC 2 Readiness Gap Assessment

Typically 15 to 25 hours

Scope recommendation, control-by-control gap list, and an implementation plan with effort estimates for each gap.

SIEM and SOAR Health Check

Typically 10 to 16 hours

Review of data sources, detections, licensing, and playbooks in Splunk, Sentinel, or XSOAR, with a ranked fix list.

AI Access Review

Typically 8 to 12 hours

Inventory of AI and third-party apps with access to Google Workspace or Microsoft 365 data, risk ranking, and a usable AI policy.

Questions

Frequently asked questions

How much does cybersecurity consulting cost?

Our rate is $200 per hour for both strategy and implementation work, plus documented travel for on-site days. Every scope comes with an hour estimate and a not-to-exceed cap, and you can convert it to a fixed quote after discovery. For context, published guides put independent security consultants and virtual CISO services between $200 and $500 per hour, and full-time security leadership well into six figures a year.

Do I have to use the Blue Lantern Security platform to hire you?

No. Consulting is independent of the product. We recommend whatever fits your environment, which is sometimes our platform and often tools you already own. When our monitoring is a good fit we will say so, and you can see the pricing for yourself.

What size of company do you work with?

Most clients are between 10 and 500 people. Strategy, SOC 2, and small business tooling work skews toward the smaller end. SIEM, SOAR, and cloud automation work also fits larger security teams that need an experienced builder for a defined project.

How is this different from a fractional CISO?

A fractional CISO typically sells a monthly retainer for advisory time. We are happy to do ongoing advisory, but the core offer is strategy and implementation billed by the hour: someone who can write the roadmap and then build what is on it. You pay for hours worked, not for a seat at the table.

Can you help with SOC 2 if we already use a compliance platform?

Yes, and we recommend one. Platforms like Vanta, Drata, and Secureframe handle evidence collection and monitoring, and we do not do that work by hand. What they do not do is decide your scope, design controls that fit how you operate, or implement the fixes for the gaps they find. That is the part we cover.

Do you work on-site?

Remote by default, because it keeps your cost down. On-site days for workshops, cutovers, or executive sessions are available in the United States and are billed at the same hourly rate plus travel, agreed in writing before the trip.

What do I actually receive at the end?

It depends on the engagement: a roadmap and executive summary, a control mapping and policy set, working playbooks and scripts in your repository, configured platforms, and documentation and a walkthrough for your team.

What happens on the discovery call?

Thirty minutes. You describe what is driving the work and what your environment looks like. Will asks questions, tells you what he thinks the real problem is, and says whether it is something we should do together. If it is, you get a written scope and estimate within a few business days.

Get started

Tell us what is driving the work

An audit deadline, a customer questionnaire, an insurance renewal, or a SIEM deployment that never reached its coverage goals. Start with a free call.