Security consulting & vCISO intake

Cybersecurity Consultant Discovery Form Template

Qualify cybersecurity engagement prospects with a structured discovery — regulated data, cloud environment, existing controls, top risks, incident history, stakeholder map, timeline, and budget. Built for vCISO firms, pen test teams, SOC 2 / ISO 27001 advisors, and security consultancies replacing the generic 'free security assessment' lead-magnet with a real qualification flow.

Free — included in every plan

Cybersecurity Consultant Discovery Form Template

Live preview — try the fields below.

No fields to preview.

Who this template is for

Cybersecurity consulting engagements are high-stakes, high-trust, and high-budget — $25K-$500K+ projects with executive buy-in, regulatory implications, and a scoping process that needs to surface the real risk picture before the first call. This template structures the discovery itself — primary contact (typically a CISO, CIO, head of compliance, or VP engineering), industry and regulated-data scope (HIPAA for healthcare, PCI for cardholder data, SOX for public companies, GDPR for EU personal data, LGPD for Brazilian personal data, ENS for Spanish public sector, COPPA for children's data, CUI for federal contractors), cloud and infrastructure (AWS, Azure, GCP, on-prem, hybrid), existing security controls (SIEM via Splunk / Datadog Security / Sumo Logic / Panther; EDR/MDR via CrowdStrike / SentinelOne / Microsoft Defender / Sophos; SSO+MFA via Okta / Microsoft Entra ID / Google Workspace; DLP, vulnerability scanning, pen test program), the top three risks the buyer is losing sleep over (the most diagnostic field — vague answers signal exploratory, specific answers signal real engagement), recent incident history (none / minor / significant / major-public — incident-driven engagements close 3-5x faster than compliance-driven ones), internal security team size, stakeholder roster, timeline (ASAP / 1-3 months / 3-6 months / exploring), and budget range. It is the structured intake your security consulting firm, vCISO practice, pen test team, or SOC 2 advisory uses before the first scoping call — not the generic 'free security assessment' lead-magnet that converts at 2 % and burns consulting hours on prospects with a $5K budget who will never close.

From security prospect to scoping-call-ready in one discovery flow

Prospect submits the discovery with primary contact identity (name, title, work email — work email validation filters out the freemail tire-kickers), company and industry (auto-enriched against the standard B2B providers for size, funding stage, recent news, and security-incident-disclosure search), and company size band. Regulated-data scope is the most critical qualifier — multi-checkbox covering PHI (HIPAA), PCI (cardholder data), Financial/SOX, EU personal data (GDPR), Children's data (COPPA), Government / CUI (CMMC / NIST 800-171 / FedRAMP if applicable), and the regional equivalents (LGPD for Brazil, LOPDGDD for Spain, PIPEDA for Canada, POPIA for South Africa). Cloud-provider multi-checkbox captures AWS, Azure, GCP, on-prem only, hybrid, or specific compliance-cloud (AWS GovCloud, Azure Government, AWS China). Existing security controls — SIEM (Splunk, Datadog, Sumo Logic, Panther, Elastic Security, IBM QRadar, Microsoft Sentinel), EDR/MDR (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Sophos, Carbon Black, Cybereason, Huntress for SMB), SSO + MFA (Okta, Microsoft Entra ID, Google Workspace, Ping Identity, OneLogin, JumpCloud, Authy), DLP (Microsoft Purview, Symantec/Broadcom, Forcepoint, Digital Guardian, Nightfall AI), vulnerability scanning (Tenable Nessus, Qualys, Rapid7 InsightVM, Wiz, Snyk, Lacework), pen test program (Cobalt PtaaS, HackerOne, Bugcrowd, Synack, Intigriti, NetSPI, BishopFox, Trail of Bits) — surfaces the maturity gap that drives the engagement scope. Top 3 risks is the most diagnostic field — a buyer who answers 'shadow IT, third-party risk, ransomware preparedness' has clearly thought about it and is closer to engagement; a buyer who answers 'cybersecurity in general' is exploratory. Recent incident history is the urgency signal — 'major / public' incidents in the last 12 months mean the buyer is in remediation mode (and the engagement is a 90-day rapid response), 'none' means the engagement is preventive (longer cycle, harder close). Internal security team size sets the proposal architecture — none means the engagement includes operational handoff and possibly vCISO retainer; 1-2 means consultant-led with team augmentation; 3-10 means consultant-as-specialist for specific gaps; 11+ means the engagement is for very specific deep-expertise work (red team, threat hunting, GRC tooling implementation). Stakeholder roster reveals who is actually involved in the buying decision. Timeline and budget round out the qualification. On submission, the workflow scores the engagement-fit and auto-routes — high-fit (specific risks + regulated data + insider team + budget > $100K + timeline ≤ 3 months) goes to the principal/partner level with a calendar link; medium-fit goes to a senior consultant for the discovery call; low-fit (vague risks + 'exploring' timeline + 'under $25K') receives the polite templated 'here is our process and some starter resources' decline.

What's included

Every field exists because some consultant has been burned by its absence — usually in the scoping call where 45 minutes were burned asking 'do you actually have a SIEM?' before realizing the engagement is a $30K compliance project, not the $300K transformation the prospect described, or in the proposal phase where the security team's actual incident history (which the proposal would have priced into the IR retainer) was hidden until the executive interview.

Security firms using cybersecurity consultant discovery forms

  • vCISO firms and security advisory boutiques

    vCISO (virtual CISO) firms (ScaleSec, Cynergy, GuidePoint, Pioneer Networks, BlueVoyant Advisory, Cybiant) and security advisory boutiques where the engagement is a 3-12 month retainer plus project work. The form's discovery captures the engagement scoping signals — internal team size (none = full vCISO; 1-2 = augmentation; 3+ = peer-level partnership), regulated data (drives the compliance focus), and the top-3-risks (sets the engagement priority stack). The free-form stakeholder roster surfaces the political topology that determines whether the engagement is purely technical or requires board-level engagement.

  • Pen test and offensive security firms

    Penetration testing firms (Cobalt PtaaS, HackerOne, Bugcrowd, Synack, Intigriti, NetSPI, BishopFox, Trail of Bits, Praetorian, Doyensec, Kudelski Security) where the engagement is a fixed-scope pen test (network, web app, mobile app, cloud, red team) or a continuous testing retainer. The form's cloud-provider field determines the test scope (AWS pen test is different from Azure pen test from GCP), the existing-controls section reveals whether the test should focus on detection gaps (against EDR/SIEM) or perimeter gaps, and the regulated-data field determines whether the test needs to satisfy a specific compliance requirement (PCI ASV scan, HIPAA risk assessment, SOC 2 penetration testing).

  • SOC 2 / ISO 27001 / compliance advisory firms

    Compliance advisory firms that help companies achieve SOC 2 Type II, ISO 27001/27002 certification, PCI-DSS attestation, HIPAA compliance, FedRAMP authorization, ENS for Spanish public sector, LGPD certification for Brazilian operators. The form's regulated-data and existing-controls sections directly map to the gap analysis the advisory firm produces — the maturity gap between current state and the target framework requirements. Compete with platforms like Vanta, Drata, Secureframe, Tugboat Logic, Sprinto, Strike Graph, Hyperproof, AuditBoard, Thoropass, who automate the audit-preparation but cannot replace the human advisory.

  • Incident response and digital forensics firms

    IR firms (Mandiant/Google Cloud, CrowdStrike Services, Stroz Friedberg, FireEye Mandiant, Kroll, BlueVoyant, Arete IR, Coveware for ransomware-specific) where the engagement is a 4-12 week incident response retainer. The form's 'recent incidents' field is the primary qualifier — 'major / public' incidents move directly to the principal's calendar with a 1-hour SLA, 'significant' incidents go to senior IR consultant queue, 'minor / contained' may be a tabletop exercise rather than full IR, 'none' indicates a preventive engagement (IR plan creation, tabletop exercises, retainer setup) which has a slower sales cycle.

  • Brazilian cybersecurity consultancies

    Brazilian cyber consulting firms (Tempest Security Intelligence, NSC Brasil, Resh, Cipher, Trinity Cybersecurity, Stefanini Cyber, Embratel Cyber, Eldorado, KPMG Cyber Brasil, EY Cyber Brasil) where the engagement is shaped by the local regulatory landscape — LGPD compliance, BCB Resolução 4.893/2021 for financial institutions, ANS (Agência Nacional de Saúde) cybersecurity rules for health insurance, Anvisa for pharma cybersecurity, Marco Civil da Internet, Lei do Habeas Data. The form's regulated-data field includes the LGPD-specific signals, and the regional incident-history captures whether the engagement is driven by a Banco Central or ANPD investigation.

  • Spanish-market cybersecurity firms

    Spanish cyber consultancies (S21Sec, Entelgy Innotec, Babel Ciberseguridad, Sothis, Cipherbit, Tecnocom Cyber, NTT Data Cyber España, BSecure, A3Sec, ITS by SIA, GMV Secure e-Solutions) and the LATAM-extension firms shaped by Spanish regulatory frameworks — RGPD/LOPDGDD compliance for personal data, ENS (Esquema Nacional de Seguridad) for public sector and contractors, AEPD enforcement landscape, sectoral rules from the Banco de España, CNMV for financial sector, AEAT for tax-data security. The form's regulated-data field captures the ENS scope (Bajo / Medio / Alto categorization) and the LOPDGDD-specific signals that drive the engagement.

Tailor it to your security practice

Every security consulting firm has its own specialty depth. Configure the engagement-type field to match your offerings — vCISO retainer, SOC 2 / ISO 27001 / PCI-DSS / HIPAA / LGPD readiness, penetration test (network / web app / mobile app / cloud / red team / continuous), incident response retainer, threat hunting, security architecture review, M&A due diligence, board-level briefing. Configure the regulated-data field with the frameworks you specialize in — most US firms cover SOC 2, ISO 27001, HIPAA, PCI; firms doing federal work add CMMC, FedRAMP, NIST 800-171, CJIS, ITAR; firms doing financial work add FFIEC, NYDFS Part 500, GLBA; firms doing EU work add GDPR, NIS2, DORA for financial sector, eIDAS for trust services; firms doing Brazilian work add LGPD with ANPD certification, BCB Resolução 4.893 for financial, ANS for healthcare; firms doing Spanish work add LOPDGDD, ENS at all three categories. Configure the cloud-provider multi-checkbox with the providers you have practical expertise in — AWS, Azure, GCP, Oracle Cloud, IBM Cloud, AWS GovCloud, Azure Government, AWS China, regional providers (Locaweb, KingHost, UOL Host for Brazil; Acens, Arsys for Spain). Add the AI / ML-security specialty fields if you cover that — model security, prompt injection, training-data poisoning, MLOps security, AI governance per the EU AI Act, OECD AI Principles. Configure the budget tiers to match your engagement floor — most senior consulting firms set the lowest tier above $25K to filter out non-fits; mid-tier firms may set it at $10K or $15K to capture compliance-only engagements; offensive-security firms doing single pen tests may set it at $5K-$10K for standard scoped tests. Add the urgency-modifier field that captures whether this is incident-driven (auto-route to IR team), compliance-driven (auto-route to advisory), insurance-driven (auto-route to insurability assessment), or strategic (auto-route to vCISO scoping).

Cybersecurity consultant discovery FAQs

The generic 'request a security assessment' form asks 3-5 fields (name, email, company, brief description) and produces a 2 % conversion rate from inbound leads. The structured discovery form asks the qualification questions upfront — regulated data scope, existing controls, top risks, incident history, internal team size, timeline, budget — and produces a 15-25 % conversion rate because the prospect who completes a 12-field form has already self-qualified as serious. The buyer-side benefit: completing the form prompts the buyer to actually articulate their risk picture, which is often the value-add moment — they realize they have not actually written down their top 3 risks before, and the act of writing them down changes the engagement conversation. The consulting firm's benefit: scoping calls start with a written risk picture instead of starting from scratch, which compresses the typical scoping cycle from 3-5 calls to 1-2.
Yes, the budget field scares away prospects whose budget is below your engagement floor — and that is the intent. Cybersecurity consulting at the senior level is $25K-$500K+ per engagement; spending 90 minutes of partner time on a discovery call with a prospect who has a $5K budget is a costly mismatch. The budget field's typical brackets (Under $25K / $25K-$100K / $100K-$500K / $500K+) align with engagement archetypes (small audit / mid compliance project / major transformation / large strategic program), which lets the routing logic send each bracket to the appropriate consultant level. For firms that worry the budget field will reduce funnel volume too much, a workable alternative is to make budget optional but track which submissions complete it — submissions that complete the budget field convert 5-10x higher than those that skip it, regardless of the budget amount. The buyer who fills in 'under $25K' on a budget field is still 5x more qualified than the buyer who leaves it blank because they have engaged with the question.
The top-3-risks field is the most diagnostic field in the entire form — a buyer who has written down 'third-party risk exposure from our SaaS supply chain, ransomware preparedness given our backup posture, and insider risk from the recent layoffs' is in a fundamentally different conversation than a buyer who writes 'cybersecurity in general' or 'compliance.' Use the field three ways: (1) at the start of the scoping call, read back the risks and ask 'is this still where you are?' — the buyer often updates or refines, which is itself useful intelligence; (2) anchor the engagement scope against the named risks — the proposal should explicitly address each of the three with specific engagement components and outcomes; (3) use it for executive briefing — when you present to the buyer's leadership team, the named risks become the agenda, which prevents the meeting from drifting into generic security platitudes. The field also surfaces the buyer's level of security literacy, which determines the technical depth appropriate for the scoping call.
Yes — on submission, the workflow can create a discovery record in your GRC platform with the qualification fields pre-populated. For Vanta (the most common SOC 2 / ISO 27001 automation platform), the submission creates a prospect record with the framework scope identified for the readiness assessment. For Drata (similar to Vanta with stronger continuous monitoring), the same pattern. For Secureframe, Tugboat Logic, Sprinto, Strike Graph, Hyperproof, AuditBoard, Thoropass — equivalent integrations. For firms that have built their own internal practice management (often on Notion, Airtable, ClickUp, Monday), the form's data export feeds the engagement tracker. For pen test firms running on Cobalt, HackerOne, or Bugcrowd, the submission creates the engagement scoping record with the test surface, regulated-data scope, and timeline pre-populated. For IR firms running on case-management tools (Mandiant Advantage, CrowdStrike Falcon Insight, IBM Resilient, Splunk SOAR / Phantom, Tines, Torq), the submission can pre-populate the IR engagement-intake structure. The audit trail captures the discovery-to-engagement progression which is the documentation senior partners use for the quarterly business review.
Each major regulatory regime has its own discovery angles. For LGPD (Brazil), the form captures whether the prospect is a controller, operator, or both (different obligations under LGPD), the data subject volumes (drives the DPO obligation under Art. 41 — typically required above ~5000 affected subjects per industry norms, though ANPD has not published a fixed threshold), the cross-border transfer footprint (international transfers require explicit basis under Art. 33), and the incident notification history (Art. 48 requires notification to ANPD and titulares in case of relevant incidents). For LOPDGDD (Spain) and NIS2 (EU critical-infrastructure directive), the form captures the entity classification (essential service operator vs digital service provider vs critical-infrastructure operator), the ENS category if applicable (Bajo, Medio, Alto with progressively stricter controls), and the prior AEPD interaction history. For US-equivalent frameworks (CMMC 2.0 for federal contractors, NYDFS Part 500 for New York financial services, California CCPA/CPRA for businesses with California consumers, Texas DIR for state contractors), the form captures the certification stage (initial readiness vs ongoing maintenance vs audit response). The structured intake produces the gap-analysis starting point that the advisory engagement begins from.

Ready to build forms that work for you?

Create your first form in minutes. Your submissions will thank you.

Be first in lineLimited early accessSet up in 2 minutes