Why My Cybersecurity Practice Almost Ran on Goodwill Alone
By Rachel Torres, Cybersecurity Consultant — Austin, TX
I spent a decade in enterprise security before going independent. I knew how to run penetration tests, structure incident response plans, design zero-trust architectures, and brief C-suite executives on risk posture. What the corporate world had not prepared me for was the administrative reality of running a solo consulting practice — specifically, the billing.
My first year as an independent consultant was technically productive and financially disorganized. Clients were getting real value. I was getting paid — eventually, irregularly, sometimes incompletely.
The problem was not client willingness. It was my billing structure, or rather the absence of one.
The Engagement That Exposed the Problem
My third independent client was a regional healthcare network. A thirty-day security assessment engagement: vulnerability scanning, configuration review, staff phishing simulation, executive risk briefing. We agreed verbally on a scope and a price — $14,500.
I completed the work. I sent an invoice at the end of engagement. The client’s AP department responded that they needed a purchase order, which they had never mentioned, and that payment would follow net-60 terms, which was not what I had understood.
We eventually resolved it. I was paid, sixty-two days after completing the work. During those sixty-two days I had to manage cash flow on three other engagements while waiting for a check I had fully earned.
The problem was not the client. It was that I had no standard engagement agreement, no deposit requirement, no milestone billing structure, and no documented payment terms. I had done enterprise-grade security work and billed it like a handshake deal.
Building the Cybersecurity Billing Framework
After the healthcare network experience, I built a billing framework using InvoiceFlow that I now apply to every engagement.
For assessment and audit engagements:
I split every fixed-scope engagement into three billing milestones.
“Cybersecurity Assessment — [Client Name] — Engagement SOW-2026-SEC-004:
Milestone 1 — Engagement Deposit (40%): Due upon signed agreement. Covers kick-off meeting, scope confirmation, tool deployment, access provisioning. Due: January 15, 2026. $5,800.00
Milestone 2 — Assessment Completion (35%): Due upon delivery of preliminary findings report. Covers all active testing, scanning, interview sessions, initial findings documentation. Due: February 10, 2026. $5,075.00
Milestone 3 — Final Report & Briefing (25%): Due upon delivery of final report and executive briefing. Covers remediation recommendations, priority matrix, executive summary. Due: February 28, 2026. $3,625.00
Total Engagement Value: $14,500.00 Payment Terms: Net-15 on each milestone SOW Reference: SOW-2026-SEC-004 dated January 10, 2026”
The 40% deposit ensures I have meaningful payment before spending significant time on the engagement. Milestone 2 pays while I am still active on the work. Milestone 3 closes out cleanly after final delivery. Net-15 on each milestone means I am not waiting sixty days for any single payment.
The Retainer Model for Ongoing Security Programs
Assessment engagements are valuable but episodic. The revenue model that transformed my practice was monthly security retainers.
After every assessment, I present a retained security program to the client. The business case is straightforward: they now have a findings report, a priority matrix, and a list of vulnerabilities. Implementing the remediation, monitoring for new threats, and maintaining program documentation is ongoing work. Most clients do not have internal staff to do this. They need me.
My retainer tiers:
“Monthly Security Retainer — [Client Name]:
Essential Program — 8 hours/month: Monthly vulnerability scan review, critical findings remediation guidance, security patch advisory, incident response on-call access. $1,600/month.
Active Program — 16 hours/month: Above plus monthly security awareness training session, quarterly phishing simulation, policy review and updates, vendor security questionnaire support. $3,200/month.
Comprehensive Program — 24 hours/month: Above plus monthly executive risk briefing, continuous monitoring support, regulatory compliance tracking (HIPAA/SOC2/PCI-DSS as applicable), board-level reporting. $4,800/month.”
I set up recurring invoices in InvoiceFlow for each retainer client. They generate and send on the first of each month automatically. Seven of my last ten assessment clients converted to retainer agreements. My current monthly retainer income is $22,400.
The retainer relationship also changes how clients treat security. When they have a retained security program, they call me before a vendor deploys something new instead of after a breach. The work becomes prevention-oriented rather than incident-driven.
Incident Response Billing: A Different Structure
Incident response engagements follow a different billing model than planned assessments. When a client calls because they suspect a breach, the work begins immediately and the scope is uncertain.
I handle IR billing with a structured hourly invoice that documents every phase of the response:
“Incident Response Services — [Client Name] — IR-2026-008:
Phase 1 — Initial Triage and Containment: March 3, 2026 09:00-17:00 (8 hours × $275/hr): $2,200.00 Phase 2 — Forensic Analysis — Server log review, endpoint forensics (2 analysts × 6 hours = 12 hours × $275/hr): $3,300.00 Phase 3 — Eradication and Recovery (4 hours × $275/hr): $1,100.00 Phase 4 — Post-Incident Documentation and Client Briefing (3 hours × $275/hr): $825.00
Total: $7,425.00 Emergency response surcharge (weekend engagement): $750.00 Grand Total: $8,175.00
Payment Terms: Net-7 — Incident response engagements payable within seven days of invoice delivery.”
IR billing requires a premium rate and short payment terms. Clients understand both: they are in distress and they know the response service has real value. Net-7 terms on incident response is standard in the industry and every client I have billed this way has paid within terms.
Corporate Procurement and Compliance-Adjacent Billing
Several of my clients are in regulated industries — healthcare, financial services, government contractors. Their procurement requirements are detailed, and their billing requirements include documentation that maps to their compliance frameworks.
Every invoice for a regulated-industry client includes:
“Cybersecurity Consulting Services — [Client Name] — [Date]: SOW Reference: SOW-2026-HC-019 Compliance Framework: HIPAA Security Rule Assessment PO Number: PO-2026-IT-0291 Vendor ID: VND-74821 Assessment deliverables: Network vulnerability report, access control gap analysis, workforce training completion records, risk assessment documentation per 45 CFR 164.308(a)(1). Amount: $18,200.00 Payment Terms: Net-30”
Compliance-adjacent documentation on invoices signals professional competency to regulated clients. It also creates a paper trail that supports their own audit documentation — a genuine value-add they notice.
The Practice After Three Years
Three years into independent consulting:
- Seven clients on monthly retainers generating $22,400/month in predictable recurring revenue
- Assessment engagements structured with 40% deposits and milestone billing — no more waiting sixty days
- Incident response billed at premium rates with net-7 terms
- Regulated industry clients invoiced with full compliance-adjacent documentation
- Zero unresolved billing disputes since implementing structured invoicing
The healthcare network experience three years ago cost me sixty days of float. What it gave me was the motivation to build a billing practice that matches the quality of my security work.
Download InvoiceFlow. Set up your milestone billing structure. Present a retainer to your next completed assessment client. The recurring income changes everything about how you manage the practice.
Rachel Torres is a cybersecurity consultant in Austin, Texas, serving healthcare organizations, financial services firms, and technology companies on security assessments, compliance programs, and incident response.