How I Work

Two engagement models, what each one costs you in commitment, and what the work actually looks like once it starts.

Process

How I Work

Two ways to work together. Both have clear scope and no surprise invoices.

MODEL A

Fixed-Price Projects

Assessment, remediation, migration. Fixed scope, fixed price, defined end date.

01
PHASE 01

Discovery & Assessment

1–2 weeks, fixed fee

I embed with your team, audit your systems, and interview stakeholders. Depending on the engagement that means threat modeling, reviewing your architecture and cloud posture, working through penetration test findings, or assessing where your documentation falls short of what a regulator expects. You get a technical assessment with a prioritized remediation roadmap, not a slide deck, a real plan with real estimates.

02
PHASE 02

Scoped Engagement

4–12 weeks, fixed price

Fixed-price proposal with clear deliverables, milestones, and a defined end date. I do the work: close the findings, harden the platform, build the integration, migrate the data. No scope creep, no hourly surprises.

03
PHASE 03

Delivery & Handoff

Milestone payments, final at handoff

Working software, closed findings, and documentation that holds up under audit, plus your team trained to maintain it. Payment tracks the milestones agreed in the proposal, with the final payment due at handoff rather than the whole fee landing at the end. You own everything. No dependency on me. If you want ongoing support, that’s a separate conversation, not a condition of the work. If you need me again, you know where to find me.

MODEL B

Fractional Technology Leadership

Ongoing technical ownership for companies too small for a full-time CTO and too regulated to go without one.

I take the leadership role on a monthly basis, on either side of the practice: the security program, or the architecture and the roadmap. Risk, policy, regulator and audit response and premarket cybersecurity on one side; architecture ownership, cloud cost and posture and build-versus-buy on the other. Both include the hands-on engineering to close findings rather than just document them. Defined monthly scope, no hourly billing.

SERVICE

Penetration Test Remediation

You’ve got a thorough report full of findings and no one to close them. Testing firms can’t remediate their own findings without compromising their independence as the assessor, so the report lands and the work stalls. I close findings, document the remediation so it holds up for a regulatory reviewer, and get you back through retest.

What remediation involves →
SERVICE

FDA Cybersecurity Remediation

A deficiency letter with a 180-day clock on it, or a premarket submission with a cybersecurity package nobody is confident in. FDA wants uniquely identified testable requirements traced to verification evidence, not security principles, and that conversion is most of the work. Connected devices and software-only products alike.

What the engagement involves →

Which one fits?

If you are not sure whether your problem is a project or a role, that is a reasonable thing not to know yet. Tell me what’s going on and I will tell you which one it is.

Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.

Not ready for a call? Send a message instead.

For companies looking to engage BATO. Vendors, please email.