Source Point Security 360 turns the security work you already need, leadership, testing, compliance readiness, and incident preparation, into one monthly program run by a named principal who scopes, performs, and reports every engagement. You pick a plan sized to your organization, add only the modules you need, and the work compounds across the year instead of restarting each quarter.
Every plan is a twelve-month program with a written scope and delivery schedule. Included milestones are counted within that scope; extra systems, frameworks, sessions or hours are quoted separately.
PICK A PLAN. ADD WHAT YOU NEED.
Monthly security, sized to where you are.
Five plans, each a twelve-month program delivered by the principal who does the work. Start where you are today, then layer on the add-ons that fit the year ahead. Not sure which one? Build a custom plan.
Monitor
A monthly view of your internet-facing exposure.
$750/ month
12-month program
Small teams that want ongoing visibility into what is exposed, before committing to a full program.
A scheduled monthly scan of your internet-facing systems, a plain-language report of observed changes and priorities, and a monthly check-in with a security professional.
One scheduled scan each month of the agreed internet-facing systems for known weaknesses
A short written report each month: observed changes, priorities, and recommended fixes
Review of material findings from that scheduled scan
A monthly check-in to answer questions and set priorities
A running record of issues found and closed
Cadence: One scheduled scan, report and check-in per month. This is a point-in-time scan, not continuous detection or 24/7 incident response.
A named security owner and a steady monthly rhythm.
$1,800/ month
12-month program
Small businesses and startups that need one accountable security owner and a basic program rhythm without a full-time hire.
A named owner on your security decisions, a risk register that stays current, policies kept up to date, and answers ready when customers send a security questionnaire.
Monthly security leadership session and a written report on posture, open risks, and decisions
A risk register stood up and kept current as items change
Policy upkeep: revise the policies due for review and log exceptions
Answers to customer security questionnaires from a maintained library
A baseline risk and program-maturity assessment at onboarding, re-scored each year
Cadence: Monthly leadership session and report; a quarterly written check-in. Baseline assessments front-loaded early.
Foundation, plus vendor risk, board reporting, and a yearly test.
$3,600/ month
12-month program
Growing companies answering customer security reviews, onboarding vendors, and reporting to a board or investors.
Everything in Foundation, plus reviews of the vendors you take on, a quarterly board update, governance for how your team uses AI, and one scheduled penetration test each year with a retest.
Everything in Foundation
Reviews of new vendors and third parties as you take them on, with a yearly refresh
A quarterly board or leadership update with the metrics and decisions that matter
Governance for how your team adopts and uses AI, with an approved-tools inventory
One scheduled, scoped penetration-test milestone each year, with one retest of remediated findings; additional tests are separate scope
Cyber-insurance evidence kept ready for renewal
Cadence: Monthly session and report; quarterly board update; vendor reviews as needed; one annual testing milestone with retest.
A full program: compliance readiness, layered testing, and exercises.
$6,000/ month
12-month program
Mid-market organizations pursuing SOC 2, ISO 27001, or HIPAA readiness while keeping testing and exercises on a schedule.
A complete program: readiness and evidence upkeep for one compliance framework, testing rotated across the year, a yearly practiced incident exercise, and ongoing tuning of how you detect and respond.
Everything in Program
Readiness and evidence upkeep for one framework you choose, such as SOC 2, ISO 27001, or HIPAA
Testing milestones rotated across the year within the agreed annual scope; systems, number of tests and retest windows are confirmed in writing
One incident exercise a year, with a written debrief and plan updates; extra sessions are separate scope
Ongoing tuning of how you detect and respond to attacks
Review of significant software releases before they ship, where you build software
Cadence: Monthly session and report; quarterly board update; testing milestones sequenced through the year; one annual exercise. Readiness support, not independent assessment.
Regulated readiness with a weekly leadership cadence.
$9,000/ month
12-month program
Regulated organizations and government contractors maintaining CMMC, FedRAMP, or similar readiness with auditor and insurer coordination.
Continuous compliance upkeep for regulated programs, a weekly leadership cadence with auditor and insurer coordination, scheduled adversary testing, and incident readiness for your AI systems.
Everything in Leadership
Continuous compliance upkeep for a government or regulated program, such as CMMC or FedRAMP readiness
Scheduled control and evidence reviews on the cadence your program requires; scope and review windows agreed in writing
A weekly leadership cadence, with coordination for your auditors and insurers
One larger scheduled adversary-testing milestone each year, with objectives and prerequisites agreed in advance
Incident response playbooks and a practiced exercise for your AI systems
Cadence: Weekly touchpoints, monthly report, quarterly board update; specialist testing scheduled as milestones, not always-on. Readiness is not independent assessment, and a Certified Assessor who prepares an organization cannot assess it.
Scheduled, higher-intensity work that layers onto any plan when the calendar calls for it, priced to your scope. Estimate a full plan in the custom plan builder.
Scoped Penetration Test
A scheduled test of an agreed network, application or cloud boundary, with findings, reproduction steps and remediation guidance. The starting price is for a small external-network scope; other environments and combined coverage use their published catalog ranges. Program and higher plans already include an annual scoped test; a separate charge applies only to extra scope.
per engagementFrom $2,400, quoted to scope
Full-Scope Red Team Operation
Objective-driven adversary simulation with rules of engagement agreed in advance, showing what a determined attacker would achieve and how your prevention, detection, and response hold up. Best after testing and basic hardening are in place.
per engagementFrom $15,000, quoted to scope
Compliance Readiness Sprint
Readiness work for the chosen framework and boundary: identify gaps, plan controls and organize evidence. The entry price reflects a small HIPAA or PCI DSS scope; SOC 2, ISO 27001 and CMMC use their own published ranges. Independent audits, certification and authorization are separate. One agreed framework is included in Leadership and higher plans.
per frameworkFrom $4,500, quoted to scope
AI Governance Stand-Up
A one-time build of baseline AI policy, approval workflow and an approved-tools inventory. Program and higher plans already include that baseline within the agreed boundary. A formal AI management system or additional business units require a separate scope.
per programFrom $4,500, quoted to scope
Additional Tabletop Exercise
An extra leadership or technical incident exercise beyond your plan, run against a realistic scenario, with a written debrief and updates to your response plan.
per exerciseFrom $3,000, quoted to scope
Continuous-Compliance Maintenance
A recurring module that keeps your compliance documentation and evidence current as your controls change, so you are not rebuilding the package before every audit. Readiness maintenance only, not independent assessment.
per monthFrom $750 / month, quoted to scope
Vendor & Third-Party Software Assessment
Evaluate a software product before purchase or deployment. The starting scope is a review of one product’s vendor documents and software components, without hands-on testing. Technical testing costs more. Routine vendor-risk reviews within Program and higher plans are reconciled before a separate software assessment is quoted.
per assessmentFrom $1,800, quoted to scope
YOUR FIRST TWELVE MONTHS
A year with a plan, not a scramble.
A menu of possible milestones for a full program, not a promise that every item is included in every plan. Monitor has its monthly scanning cadence. Program includes one annual scoped test and retest; Leadership includes one annual incident exercise. Additional tests, frameworks and exercises below require coverage in the written annual scope or a separately quoted add-on.
Month 1
Onboarding and charter
Kickoff, and a charter naming what the principal may decide, draft, and sign
A map of your business, data, vendors, obligations, and insurance
Review of any open customer questionnaires and a first-year priorities readout
Begin the baseline risk assessment
Month 2
Baseline and roadmap
Finish the baseline risk and program-maturity assessment
Stand up the risk register and a sequenced roadmap
Start the security-questionnaire answer library
Month 3
First quarter close and perimeter test
First quarterly board update
First batch of policy reviews
External penetration test of your perimeter, with a retest of fixes
Month 4
Steady cadence and AI governance
Monthly leadership session and report
Reviews of new vendors and third parties
Stand up AI governance and an approved-tools inventory
Baseline how you detect attacks today
Month 5
Exercise the plan
Leadership incident exercise: activation, decisions, counsel and insurer, disclosure timing
Update the incident response plan from the debrief
Month 6
Mid-year review
Second quarterly board update
Re-check the early quick wins
Web application penetration test after a major release
Month 7
Governance depth
Second batch of policy reviews
Re-check AI risk and watch vendors for model and subprocessor changes
Pull and refresh compliance evidence
Month 8
Technical rehearsal
Technical incident exercise: detect, contain, remove, and recover
A session proving the detection gaps it surfaced are closed
Month 9
Third quarter close and internal test
Third quarterly board update
Internal or assumed-breach penetration test
Retest of findings remediated earlier in the year
Month 10
Assurance upkeep
Full refresh of vendor risk ratings
Compliance evidence and monitoring cycle
Cyber-insurance renewal preparation
Month 11
Adversary milestone
The year's largest test: a comprehensive penetration test or full-scope red team, once basics are fixed
Annual test of the incident response plan
Month 12
Year in review
Annual re-assessment of program maturity and risk
Fourth quarterly board update
Next-year roadmap and a risk-framed budget request
Close out the year's evidence for auditors, insurers, and customers
BEFORE YOU COMMIT
Common questions.
Is this a twelve-month program?
Yes. Every plan runs as a twelve-month program so the work builds across the year instead of restarting each quarter. You can move up a plan as you grow, and add-ons can be scheduled whenever the calendar calls for them. We shape the exact sequence around your risks, renewals, and audit dates in the first month.
Who actually does the work?
The same principal who scopes your program performs and reports it. There is no hand-off to junior staff, and nothing is offshored. When a milestone needs specialist depth beyond one person, it is scheduled and scoped in advance rather than promised as always-on.
Can you also assess or certify us against a framework?
No. These plans are readiness and program support, which is deliberately separate from the independent examination or certification. We prepare you and organize your evidence; an independent assessor, auditor, or certification body makes the formal decision. A Certified Assessor who prepares an organization cannot also assess it.
Does Monitor provide continuous monitoring or emergency response?
No. Monitor includes one scheduled external scan, report and check-in each month. Findings reflect that scan; changes between scans may not be detected. It does not include a staffed security operations center, managed detection and response, 24/7 review or an emergency-response service level. Review windows and escalation contacts are agreed in the written scope.
Will I be charged twice for work already in my plan?
No. The builder and request form identify included baseline work, use one annual-test slot for Program, and flag uncertain overlaps for scoping instead of automatically charging again. Choose extra scope only for a separate boundary, additional session or work beyond the agreed plan. Leadership’s testing rotation is scheduled in writing; it is not an unlimited testing allowance.
Can I add a penetration test or compliance sprint to any plan?
Yes. The add-ons are designed to layer onto any plan when the year calls for them, from a scheduled penetration test to a red team, a compliance readiness sprint, extra incident exercises, or a vendor software review. We place them on the calendar so the bigger milestones land when they are most useful.
Which plan is right for us?
Start with the plan that matches where you are: Monitor for basic visibility, Foundation for a named owner and a real rhythm, Program once vendors and a board are involved, Leadership when you are pursuing a compliance framework, and Regulated & Enterprise for government or heavily regulated obligations. If you are unsure, we will recommend one after a short conversation, and you can move up as you grow.
How do we get started?
We start with a short scoping conversation about your systems, risks and obligations. We confirm the plan, included boundaries, milestone counts, review windows and any add-ons in writing. Monitor begins with its scheduled external scan; Foundation and higher plans include the onboarding baseline assessment.
START AT THE SOURCE
Turn one-off projects into a program.
Tell us what you run and what the year holds. We’ll recommend a plan and shape the cadence around it.