Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Cyber Security Consultancy See Real Billable Utilisation Across Testers and Consultants?
Problems We Solve

How Does a Cyber Security Consultancy See Real Billable Utilisation Across Testers and Consultants?

Cyber security firms cannot see true consultant utilisation until month end. We build utilisation reporting from bookings, timesheets and invoices.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Utilisation is hard to see because bookings are in a scheduling spreadsheet, time is logged loosely, report writing and pre-sales are mixed in, and invoices go out weeks later. We build utilisation reporting that joins bookings, time and invoicing per consultant, separates billable delivery from scoping, report QA and internal work, and shows the weeks ahead as well as the weeks behind.

A busy team that does not feel profitable

Everyone in the practice is busy. Testers are on engagements, writing reports, reviewing each other's work, helping with scoping calls, doing research, sitting certification exams. Yet at the end of the quarter the numbers feel thin, and nobody can say exactly why.

When you try to work it out, the data does not line up. The scheduling spreadsheet shows planned bookings, some of which moved. The timesheet system, if you have one, shows time logged in broad categories. Invoices lag delivery by weeks. A test booked for five days took six because the report ran over, and the extra day was absorbed.

So utilisation is discussed as a feeling. Some people are 'always busy', some are 'on the bench'. Neither is backed by figures.

The questions you actually need to answer are simple ones. How many days did we sell last month, and how many did we deliver? Where did the rest go? Which kinds of work overrun most? None of them can be answered from the data you have without days of spreadsheet work.

Why utilisation is invisible

  • Bookings, time and invoices are in three places with no common reference.
  • Report writing and QA are sometimes billable and sometimes absorbed, depending on the proposal.
  • Pre-sales scoping and proposal work is done by billable people and not recorded.
  • Overruns are absorbed rather than recorded as unbilled time.
  • Forward bookings are not compared with capacity, so gaps are seen too late.

What not knowing costs

Blind spotResult
Overruns absorbedEngagements less profitable than priced
Pre-sales time unrecordedCost of winning work unknown
Bench time seen lateGaps not filled with other work
No per-type viewSome test types quietly lose money
Hiring on feelToo many or too few people

Report writing is the usual hidden leak. A five-day test is often sold as four days of testing and one of reporting. When the report takes two days, and QA takes another half day of a senior tester's time, the engagement has cost more than it earned, and nothing in your current records says so.

The utilisation reporting we build

  1. Every booking, time entry and invoice line is linked to an engagement reference, from your scheduling tool, timesheets or PSA, and accounts package.
  2. Time categories are set up to match how you actually work: testing, report writing, QA review, retest, scoping and proposals, internal, training, leave.
  3. Where you do not use timesheets, booked time is used as the baseline, and testers can record exceptions (overruns, extra QA) quickly without filling in a whole timesheet.
  4. Each engagement shows days sold, days delivered and days invoiced, so overruns and unbilled time are visible per engagement and per test type.
  5. Per-consultant views show billable, non-billable and available time, for past weeks and booked weeks ahead.
  6. A monthly practice report shows utilisation, overruns by test type, pre-sales effort and the forward booking position.

We keep this as light as possible for your testers. The aim is accurate figures with the least extra logging, not a new admin burden.

What the practice lead sees

Real figures for billable and non-billable time, per person and per test type. Which engagements overran, and by how much, compared with what was sold. How much senior time goes into pre-sales. And the weeks ahead: who is booked, who has gaps, and where a postponement will leave someone idle.

That changes decisions. Scoping rules can be adjusted for test types that consistently overrun. Pre-sales can be shared more evenly. Hiring can be based on the forward booking position rather than on how busy everyone feels.

Pricing improves too. If the figures show that mobile application tests routinely take longer than scoped, the next proposal for one can reflect that, or the scoping questions can be improved so the estimate is right. Over a few quarters the gap between days sold and days delivered narrows because you can see it.

Is this your practice?

  • Utilisation is discussed as a feeling, not a figure.
  • Overruns are absorbed without being recorded.
  • Senior testers spend unrecorded time on scoping.
  • You find out about bench time when it happens.
  • Bookings, time and invoices do not line up.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do our testers need to fill in detailed timesheets?

Not necessarily. Booked time can be the baseline, with quick exception logging for overruns and extra work.

Which systems does it connect to?

Your scheduling tool, PSA or timesheet system, and accounts package, where they have APIs or exports. We check first.

Can it show profit per engagement?

It shows days sold, delivered and invoiced per engagement. With your cost rates added, it can show margin too.

Is it used to judge individuals?

That is your choice. We recommend it for planning and pricing, and design it accordingly.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →