Cybersecurity Consulting
The shortcut: Most cybersecurity consultants spend their first six months chasing enterprise clients who want SOC 2 or ISO 27001 audit experience. The actual money is small businesses who have never had a single security review and will pay $5K-$15K just to learn what they're exposed to.
Industry: Software & Tech | Investment level: Medium — $5,000-$25,000 | Time to launch: 6-12 weeks (one cert + one signed authorization template + one pilot risk assessment gate the launch)
Best for: A developer or IT/sysadmin person who can read a network diagram, write a one-page memo a non-technical owner will actually act on, and stay disciplined about written authorization before touching anything. What you'll likely make: $2,000-$4,000 month 3, $5,000-$10,000 month 6, $10,000-$18,000 month 12 (one risk assessment plus a small ongoing advisory book). Math is in Section 4.
Market Opportunity
Most cybersecurity consultants chase the wrong client. The pitch deck says "we help enterprises with SOC 2 audit prep," and they spend six months getting ignored by Fortune 1000 procurement teams who won't consider a vendor without three case studies and a Big-Four pedigree. Meanwhile, the auto dealer down the street, the local CPA firm, and the 30-person mortgage broker have never had a security review — and they have new federal obligations they don't understand.
The FTC Safeguards Rule (16 CFR Part 314) now applies to non-bank financial institutions — auto dealers, mortgage brokers, CPAs, tax preparers — and requires a written information security program. Most of these businesses have a 50-person staff, no IT lead, and a compliance deadline they half-understand. They will write a check for someone to walk them through it.
Healthcare is the second wedge. The HIPAA Security Rule requires covered entities and business associates to conduct a formal security risk analysis. Dental practices, small medical clinics, and therapy groups owe one and rarely have one. Risk assessments here typically bill $3,000-$10,000 per engagement.
The crowded slice is pen testing for tech-forward customers who want a glossy report. The quiet one is writing a 12-page risk roadmap an owner can hand to their accountant.
Launch With AI
Pro section. AI doesn't replace the work — it cuts the parts that drained you (reading 100-page network audit logs, drafting 12-page client reports against CIS Controls, writing FTC Safeguards explainers for non-technical SMB owners, personalizing 30 cold LinkedIn DMs to auto dealers and CPAs). Spend the saved time on what AI can't do: getting written rules-of-engagement signed before any active testing, the call to a dental-practice owner whose POS just got popped, and the judgment about which exposure actually matters at this client.
The trap most new cybersecurity consultants fall into: they think AI threatens their business (the "AI will automate security"). Wrong direction — AI security tools generate noise; SMBs still need a human to interpret findings and write the 12-page roadmap that maps to CIS Controls. The bottleneck on hitting $10K-$18K/month isn't the scan; it's getting in front of SMB owners (auto dealers, CPAs, mortgage brokers, dental practices) who have FTC Safeguards or HIPAA obligations and don't know where to start. AI compresses outreach + reporting; you keep the active testing strictly authorized.
Important up-front: AI cannot run a vulnerability scan with proper scoping; only you can read the rules-of-engagement before firing Nessus. AI cannot make Computer Fraud and Abuse Act (18 USC §1030) exposure go away (Section 5/8) — never let AI suggest "quick test" scans without signed authorization. AI handles outreach + report writing; you handle written authorization + final exposure judgment.
AI Tools You'll Use
| Tool |
Price |
What it does |
| ChatGPT Plus |
$20/mo |
SMB owner outreach, FTC/HIPAA explainers, written report scaffolds, retainer pitches |
| Claude Pro |
$20/mo |
Long-context — read 100-page network audit logs, scan outputs, summarize findings |
| Nessus Essentials/Pro |
$0-$3,990/yr |
Vulnerability scanning (industry standard, mentioned in plan) |
| KnowBe4 Partner Program |
$0 (20-30% reseller margin) |
Phishing simulation + security awareness training — retainer engine |
| LinkedIn Sales Navigator |
$79.99/mo |
SMB owner outreach filtered to FTC Safeguards-affected verticals |
The Workflow
Vertical-specific outreach (LinkedIn Sales Nav + ChatGPT, ~90 min/week). Per Section 6, "30 SMB owners in one regulated vertical" is your highest-yield outreach channel. Pull 30 owner profiles in your vertical (auto dealers, CPAs, mortgage brokers, dental practices), paste 5 at a time:
"For each LinkedIn profile below, write a 100-word direct message pitching my SMB cybersecurity consulting. The buyer is in [vertical — e.g., auto dealer / CPA / mortgage broker / dental practice], so the regulation that applies is [FTC Safeguards Rule for non-bank financial institutions / HIPAA Security Rule for healthcare]. Open with one specific detail from their profile (location, business size, recent post). One sentence on the exposure their peers in the same vertical are missing (unsecured RDP, no MFA, no incident response plan). Soft CTA: free 30-min 'where are you exposed?' call. Vary openers — no two should sound the same."
Send 30 messages/week. 5-8% reply, 20-30% reply-to-paid. That's 1-3 paid risk assessments per quarter from outreach alone.
Long-context audit log + scan output triage (Claude, ~30 min per client). Per Section 2, your assessment maps to CIS Controls v8. Most consultants spend 4-6 hours reading raw scan output. Paste:
"This is a Nessus scan output of [client]'s network ([N] hosts, [Y] vulnerabilities) plus their existing security policy doc. Cross-reference against CIS Controls v8. Output: (1) the 5 highest-priority exposures (rank by exploitability + business impact, NOT just CVSS score); (2) the 3 CIS Controls categories where they're weakest (e.g., 'Control 6 — Access Control Management has 0 of 8 sub-controls implemented'); (3) the 1-paragraph executive summary an SMB owner would actually understand (no jargon, name the 3 things to fix this quarter); (4) the suggested remediation roadmap with ballpark hours per fix."
Claude reads the dump in one pass. You verify each finding. Report production drops from 4-6 hours to 90 min.
12-page CIS Controls report scaffold (ChatGPT + Claude, ~2 hours per assessment). The deliverable is what justifies $5K-$8K. Build the template once:
"Build me a 12-page risk assessment report template structured as: (1) Executive summary (1 page) — top 3 exposures, business impact in plain English, $ estimate of risk, the 3 fixes to do this quarter; (2) Methodology (1 page) — CIS Controls v8 mapping, scan tools used, scope; (3) Findings by Control category (6 pages, 1 paragraph per control with status + gap description); (4) Prioritized remediation roadmap (2 pages — 30/60/90/180-day buckets with effort/impact); (5) Appendix — full vulnerability scan output, scan dates, reviewer signature. Tone: clear professional, not jargon-heavy, written for an SMB owner not a CISO."
Drop into a Google Doc or Word template. New client report drops to a 2-hour edit + Claude triage from step 2 vs. 12+ hours from scratch.
FTC Safeguards / HIPAA explainer assets (ChatGPT, ~3 hours one-time). Per Section 6, the "30-min exposure review" lead magnet converts at 5-10%. SMB owners in regulated verticals don't know what their compliance obligation actually means. Paste:
"Build me a 2-page PDF lead magnet for SMB owners in [vertical — auto dealer / CPA / dental / mortgage broker]. Title: 'What [FTC Safeguards / HIPAA Security] Means for Your [Vertical] in Plain English'. Cover: (1) what the rule actually requires (3 bullets, plain English not legal jargon); (2) the deadline + penalty structure; (3) the 5 highest-risk exposures most [vertical] businesses don't realize they have (unsecured RDP, missing MFA, no patch cadence, untested backups, untrained staff); (4) what a real risk assessment looks like; (5) my 30-min free exposure review CTA. No sales fluff."
Drop into Canva for design polish. Email + LinkedIn pin. One vertical-specific PDF works for 6-12 months of inbound.
KnowBe4 retainer pitching (ChatGPT, ~30 min per client). Per Section 3, the retainer book is what makes year 2 work. Quote a $300-$800/month phishing + advisory retainer in EVERY assessment proposal. Paste:
"I just delivered a $5,000 risk assessment to [client — vertical, employee count]. Their findings: [paste exec summary]. Quote them an ongoing advisory retainer alongside the assessment delivery. Include: (1) 200-word proposal explaining what ongoing advisory looks like (quarterly rescans, monthly phishing simulation via KnowBe4, on-call vendor security questionnaires, incident-response support); (2) tiered pricing — $300 (small biz under 25 staff), $500 (25-100 staff), $800 (100+ staff); (3) why retainer beats waiting until next breach; (4) soft CTA — '50% off first month if you sign within 30 days of assessment delivery'."
Half of assessment clients sign a retainer when offered alongside the deliverable. 8 retainers at $400 = $3,200/month base before any new engagement.
Time Saved Per Week
Roughly 8-12 hours/week at 2-3 active engagements once your outreach + reports + retainer pitches are dialed:
- SMB outreach: 4 hours/week → 60 min (Sales Nav + ChatGPT bulk)
- Audit log triage per client: 6 hours → 30 min (Claude long-context)
- Risk assessment report production: 12 hours/assessment → 2 hours (template + Claude)
- FTC/HIPAA explainer per vertical: 8 hours one-time → 3 hours (template + Canva)
- Retainer pitch drafting: 90 min/proposal → 15 min (template ready)
Trade that time for: actually walking 1 chamber of commerce / BNI breakfast per month, sitting CompTIA Security+ if you don't have it ($404, week 1-3), and getting OSCP under your belt by year 2 to unlock pen-test rate ladder.
Total AI Stack Cost
- Budget tier ($40/mo): ChatGPT Plus + Claude Pro. Skip Sales Nav (LinkedIn Premium $39.99/mo handles low-volume outreach), Nessus Essentials free under 16 IPs, KnowBe4 partner is free. Right for the first 60 days at 1-2 engagements.
- Full tier ($120/mo + Nessus Pro): ChatGPT + Claude + Sales Nav + Nessus Pro ($3,990/yr) + KnowBe4 partner. Worth it once you cross 3 active engagements and report volume becomes the bottleneck.
- Compare: A part-time security analyst doing report drafting + scan triage runs $5,000-$10,000/month. The full AI stack is one-fifteenth that.
Cancel anything you don't open in a 7-day window.
Your First Win
30 minutes from now your vertical-specific outreach is drafted. Open ChatGPT (free works). Paste:
"I'm a cybersecurity consultant. I want to land my first paid SMB risk assessment. Pick the vertical I should target based on: (a) regulation that creates urgency [FTC Safeguards Rule for auto dealers / CPAs / mortgage brokers, HIPAA Security Rule for dental / medical / therapy], (b) typical employee size 25-100, (c) lowest-competition consultant supply in my market. Recommend the vertical. Then build me 5 cold-DM templates for that vertical: (1) opens with the regulation deadline; (2) opens with a peer breach reference; (3) opens with a specific CIS Control gap question; (4) opens with the 'free 30-min exposure review' offer; (5) follow-up if they don't reply within 7 days. Each: 90 words, soft CTA, vary openers."
Send 30 messages this week to one vertical. Pick the vertical you have any prior connection to (your dentist, your accountant, your auto-dealer brother-in-law) — the first paid client almost always comes from your existing network, and the cold messages warm up faster when "I'm referred by [name]" is option 1.
Product / Service Offering
You are selling one of four things. Pick the first two for year one and ignore the rest until you've shipped 10 paid engagements.
- SMB security risk assessment — Network discovery, vulnerability scan, policy review, written report mapped to the CIS Controls framework. $3,500-$8,000, 2-3 weeks. Your bread-and-butter.
- FTC Safeguards / HIPAA compliance package — Written information security program, risk analysis, employee training plan, incident response plan. $5,000-$15,000, 4-6 weeks. Your higher-margin offer.
- Phishing simulation + security awareness training — Quarterly campaigns delivered through KnowBe4 (white-labeled or resold). $1,500-$3,000 setup + $200-$500/month. Where your retainer book lives.
- Virtual CISO advisory retainer — Monthly call, quarterly board memo, vendor security review on demand. $1,500-$4,000/month. Year-two offer once you have references.
The standard delivery backbone is the CIS Controls v8 — 18 prioritized controls, free to use, gives every report the same skeleton. Pair with Nessus Essentials (free for up to 16 IPs) for vulnerability scanning, and KnowBe4 for phishing simulation. You're not building proprietary methodology. You're translating a free framework into something a 40-person business can act on. Rapid7 — now public — built its consulting practice on exactly this SMB vulnerability-management entry point before moving upmarket.
Revenue Model
Solo consultant, billing through Stripe, no employees, working from a laptop:
| Service |
Price |
Variable cost |
Delivery time |
Take-home |
| SMB risk assessment |
$5,000 |
$50 (scan tool) + $145.30 (Stripe 2.9% + $0.30) |
2-3 weeks |
~$4,805 |
| FTC Safeguards / HIPAA package |
$9,000 |
$80 (scan + templates) + $261.30 |
4-6 weeks |
~$8,659 |
| Phishing + training retainer |
$400/mo |
$50 (KnowBe4 reseller) + $11.90 |
2-3 hrs/mo |
~$338/mo |
| Virtual CISO retainer |
$2,500/mo |
$30 + $72.80 |
6-8 hrs/mo |
~$2,397/mo |
Your first $1K month = one risk assessment at $5,000 with a 50% deposit upfront = $2,500 in the door. Two weeks of work. Easily clears the threshold.
Your first $3K month = one full FTC Safeguards package at $9,000 (50% deposit = $4,500) plus one $400 phishing retainer signed = $4,900 in the door. Roughly three weeks of work plus a few hours of monthly retainer setup.
The retainer is what makes year two work. Every assessment client needs ongoing phishing simulations, quarterly rescans, and a quick call when their bookkeeper gets a suspicious email. Quote a $300-$800/month advisory retainer in the same proposal as the assessment — clients who valued the report almost always sign. Eight retainers at $400 is $3,200/month base before any new engagement lands.
Startup Costs
- CompTIA Security+ exam: $404 at comptia.org. No experience prerequisite — your day-one credible badge. CISSP at $749 (isc2.org) requires 5 years of paid experience in 2+ of 8 CBOK domains; plan for it as a year-2 or year-3 milestone.
- Vulnerability scanner: Nessus Essentials is free up to 16 IPs (good for first 3-5 demos). Nessus Professional is ~$3,990/year once you have paying clients.
- KnowBe4 partner program: Apply via their partner page. Margins are 20-30% on subscriptions you bring in.
- CIS Controls framework: Free at cisecurity.org/controls. Your report skeleton.
- Cyber + E&O insurance: $1,500-$4,000/year via Hiscox or Insureon. Bundle them — separate policies cost more.
- LLC + EIN: $35-$500 LLC filing per the LLC University 50-state table. EIN is free at IRS EIN Online — never pay a third party.
- MSA + SOW + rules-of-engagement template: $500-$1,000 for attorney review of templates from Bonsai.
Realistic all-in: $5,000 if you stick to passive risk assessments, free Nessus tier, defer Nessus Pro until client three; $25,000 if you pay for Nessus Professional year one, bind a $1M cyber + E&O policy on day one, sit a full attorney review of every template, and budget for CISSP study materials and a single conference (BSides or Wild West Hackin' Fest).
Legal & Formation
Business entity. Form a single-member LLC the day before your first client signs. A vulnerability scan that knocks a client's POS offline mid-Saturday-rush, or a missed exposure that becomes a breach, is a smaller problem when the lawsuit names your LLC, not your house. Filing fee is $35-$500 — see the LLC University 50-state table. EIN is free at IRS EIN Online — never pay a third party. Once net profit clears $80K-$100K/year, run the math on an S-corp election via IRS Form 2553.
Licenses & sales tax. No state license is required for cybersecurity consulting. Security+ and CISSP are credibility credentials, not legal prerequisites. Most states don't tax custom consulting as professional services. The line gets fuzzy when you bill recurring access to a phishing simulation platform — about 25 states tax that as SaaS. Cross $100K in sales or 200 transactions in any state and you have economic nexus there. Use Stripe Tax or the Avalara state tracker before billing recurring across states.
Industry-specific risk. This is the section that protects your business. Three things matter and they trip people up in this exact order.
First, written authorization before any active testing. Pen testing — or even an aggressive vulnerability scan — without a signed scope-of-work and explicit written authorization is illegal under the Computer Fraud and Abuse Act (18 USC §1030). Federal felony exposure. A "rules of engagement" document signed by the client owner before every test is not a nice-to-have. List the IP ranges in scope, the testing windows, the techniques permitted, the contact who can pause the test, and an emergency stop number. No verbal okays. Get the signature before you fire up Nessus.
Second, cyber + E&O liability insurance from day one. A botched scan that takes a client's network down, or a missed exposure that becomes a breach, can produce losses that dwarf your fee. The bundled policy runs $1,500-$4,000/year through Hiscox or Insureon. Cap liability in every contract at fees paid in the prior 12 months. Many SMB clients ask for a Certificate of Insurance before signing — have one ready.
Third, HIPAA Business Associate Agreements before touching any healthcare client's network. If the prospect is a covered entity (dental, medical, therapy, billing service) and your work touches their environment, you need a signed Business Associate Agreement before access. Without one, you are personally exposed under HIPAA. The HIPAA Security Rule governs the substance; the BAA is what makes you legally allowed to handle the data. Refuse to start until it's signed.
Marketing & First Customers
Your first three paying clients come from your existing network — the bookkeeper, the dentist, the brother-in-law's law firm. The cold-channel work follows.
- Direct outreach to 30 SMB owners in one regulated vertical. Pick auto dealers, CPAs, mortgage brokers, or dental practices (FTC Safeguards or HIPAA-driven demand). Send a 4-line LinkedIn or email: name the rule that applies, name one specific exposure their peers are missing, offer a free 30-minute "where are you exposed?" call. Target: 30 messages/week, 5-8% reply rate, 20-30% reply-to-paid.
- Local Chamber of Commerce + BNI breakfasts. SMB owners over 45 still live in these rooms. Show up monthly with a 30-second intro that names the FTC Safeguards Rule. Expect 1-2 referrals a quarter from a chapter of 30. Cost: $300-$700/year membership.
- Free "30-minute exposure review" lead magnet. A 2-page PDF that walks a prospect through the 5 highest-risk SMB exposures (unsecured RDP, no MFA on email, no patch cadence, no backup test, untrained staff). Converts at 5-10% to paid scoping calls when paired with channel 1.
- Vertical-specific webinar. A 30-minute "What FTC Safeguards Means for Your Dealership" delivered to one regional trade association per quarter. Expect 2-4 inbound leads per session.
A clean LinkedIn profile with two case studies, your Security+ badge, and an E&O insurance line will close more SMB engagements than any marketplace listing.
First 90 Days
- Week 1. File LLC. Get free EIN. Pick your vertical (auto dealers, CPAs, dental, or mortgage brokers).
- Week 1-3. Sit and pass CompTIA Security+ ($404) if you don't already hold it. CISSP comes later — Security+ is the credible day-one badge.
- Week 2-4. Build your assessment template: CIS Controls v8 mapped to a 12-page client report. Include scan output sections, policy gap section, and prioritized remediation roadmap.
- Week 3-4. Attorney reviews MSA + SOW + rules-of-engagement template ($500-$1,000). Bind cyber + E&O bundle through Hiscox or Insureon. Set up Stripe.
- Week 4-6. Spin up Nessus Essentials free tier on a private lab network. Run 3 practice scans on your own infrastructure. Document every step.
- Week 5-8. Send 30 cold messages to your vertical. Land one paid pilot risk assessment at $2,500-$4,000 in exchange for a written case-study testimonial and referral introductions.
- Week 8-10. Ship the pilot. Deliver the 12-page report on a 30-minute video walkthrough. Capture the testimonial. Quote a $300-$500/month phishing + advisory retainer in the same conversation.
- Week 10-12. Raise the assessment price to $5,000-$8,000. Close two more engagements and convert the pilot to a retainer. Target: 3 paying clients, 1-2 retainers, ~$8,000-$14,000 in 90-day revenue.
Common Pitfalls
- Doing any active testing without signed rules of engagement. This is not a paperwork issue. A pen test or aggressive scan without explicit written authorization is a federal felony under 18 USC §1030 — and a single complaint to the FBI ends your business permanently. Cost of avoiding it: 15 minutes and a signed PDF before every engagement. Cost of skipping it: your career.
- Quoting penetration testing day rates above $2,500 with only a Security+ badge. Buyers in the $3,000-$5,000/day pen-test market expect OSCP or CEH certification and 3+ years of hands-on offensive work. Quote those rates without the credentials and you will lose the engagement, the reference, and the referral chain that follows. Stay in the $1,200-$2,000/day range until you hold OSCP — about $1,500 of study and exam costs — and have shipped 5+ pen tests under supervision.
- Treating SOC 2 Type II audit prep as a day-one offer. SOC 2 requires a partner audit firm relationship, multi-month evidence collection, and enterprise-grade documentation experience. SMBs asking for it usually mean "we got asked for one in a vendor questionnaire" and need the underlying risk-assessment work first. Sell the risk assessment for $5,000-$8,000, then route to a SOC 2 audit partner for the formal attestation. Trying to deliver SOC 2 yourself in year one means six months of unbillable work and a burned client reference.
- Skipping cyber + E&O insurance to "save $200 a month." A botched scan or missed exposure can produce client losses in the $50K-$500K range — and your homeowner policy and standard general liability cover none of it. The bundled cyber + E&O policy at $1,500-$4,000/year is less than the take-home on a single risk assessment. Bind it before your first signed engagement, not after the first scary email.
Get your full launch plan — take the free 60-second quiz.