Choose the operating depth
Start with the work you need now.
Prices are monthly. Internet-facing assets, business platforms, response expectations, and any work outside the listed scope are confirmed before the engagement starts.
Managed Security Program comparison
| Program | External validation | Business-platform review | Program leadership | Price |
| External Exposure ReviewFor organizations that want a reviewed public-exposure view. | Up to 5 approved internet-facing assets; monthly external vulnerability review | — | Concise findings report and monthly results call | $895per month |
| Managed Security ProgramFor a small organization with IT support but no dedicated security owner. | Up to 5 approved internet-facing assets; monthly reviewed validation | One business tenant and agreed identity, access, and configuration evidence | Risk register, monthly review, and up to 2 business-hours advisory hours | $1,895per month |
| Managed Security Program — StandardFor a growing organization that needs regular coordination. | Up to 25 approved internet-facing assets; monthly reviewed validation | One business tenant and expanded agreed evidence review | Risk register, remediation coordination, regular working sessions, and up to 6 business-hours advisory hours | $3,000per month |
| Managed Security Program — ExpandedFor an organization with deeper governance and reporting needs. | Up to 25 approved internet-facing assets; expanded review and executive reporting | One business tenant and expanded agreed evidence review | Biweekly working cadence, policy and vendor work, leadership reporting, and up to 12 business-hours advisory hours | $5,000per month |
| Embedded Security LeadershipFor organizations that need substantial security-program ownership. | Custom approved scope | Custom approved scope | Weekly operating cadence, executive leadership support, and substantial program ownership | Custom scopeleadership engagement |
An internet-facing asset is a public IP address, fully qualified domain name, gateway, application, or cloud system specifically listed in the approved scope. Endpoint assessment, internal scanning, agent deployment, or endpoint management are separately scoped. Programs do not include 24/7 monitoring, active containment, malware removal, forensics, legal advice, breach notification, penetration testing, or testing of third-party systems without their written authorization.