ONE PARTNER, ALL YEAR

Source Point Security 360

Source Point Security 360 turns the security work you already need, leadership, testing, compliance readiness, and incident preparation, into one monthly program run by a named principal who scopes, performs, and reports every engagement. You pick a plan sized to your organization, add only the modules you need, and the work compounds across the year instead of restarting each quarter.

Every plan is a twelve-month program with a written scope and delivery schedule. Included milestones are counted within that scope; extra systems, frameworks, sessions or hours are quoted separately.
PICK A PLAN. ADD WHAT YOU NEED.

Monthly security, sized to where you are.

Five plans, each a twelve-month program delivered by the principal who does the work. Start where you are today, then layer on the add-ons that fit the year ahead. Not sure which one? Build a custom plan.

Monitor

A monthly view of your internet-facing exposure.

$750/ month

12-month program

Small teams that want ongoing visibility into what is exposed, before committing to a full program.

A scheduled monthly scan of your internet-facing systems, a plain-language report of observed changes and priorities, and a monthly check-in with a security professional.

  • One scheduled scan each month of the agreed internet-facing systems for known weaknesses
  • A short written report each month: observed changes, priorities, and recommended fixes
  • Review of material findings from that scheduled scan
  • A monthly check-in to answer questions and set priorities
  • A running record of issues found and closed

Cadence: One scheduled scan, report and check-in per month. This is a point-in-time scan, not continuous detection or 24/7 incident response.

See Monitor in detail Or start a conversation

Foundation

A named security owner and a steady monthly rhythm.

$1,800/ month

12-month program

Small businesses and startups that need one accountable security owner and a basic program rhythm without a full-time hire.

A named owner on your security decisions, a risk register that stays current, policies kept up to date, and answers ready when customers send a security questionnaire.

  • Monthly security leadership session and a written report on posture, open risks, and decisions
  • A risk register stood up and kept current as items change
  • Policy upkeep: revise the policies due for review and log exceptions
  • Answers to customer security questionnaires from a maintained library
  • A baseline risk and program-maturity assessment at onboarding, re-scored each year

Cadence: Monthly leadership session and report; a quarterly written check-in. Baseline assessments front-loaded early.

See Foundation in detail Or start a conversation

Program

Foundation, plus vendor risk, board reporting, and a yearly test.

$3,600/ month

12-month program

Growing companies answering customer security reviews, onboarding vendors, and reporting to a board or investors.

Everything in Foundation, plus reviews of the vendors you take on, a quarterly board update, governance for how your team uses AI, and one scheduled penetration test each year with a retest.

  • Everything in Foundation
  • Reviews of new vendors and third parties as you take them on, with a yearly refresh
  • A quarterly board or leadership update with the metrics and decisions that matter
  • Governance for how your team adopts and uses AI, with an approved-tools inventory
  • One scheduled, scoped penetration-test milestone each year, with one retest of remediated findings; additional tests are separate scope
  • Cyber-insurance evidence kept ready for renewal

Cadence: Monthly session and report; quarterly board update; vendor reviews as needed; one annual testing milestone with retest.

See Program in detail Or start a conversation

Regulated & Enterprise

Regulated readiness with a weekly leadership cadence.

$9,000/ month

12-month program

Regulated organizations and government contractors maintaining CMMC, FedRAMP, or similar readiness with auditor and insurer coordination.

Continuous compliance upkeep for regulated programs, a weekly leadership cadence with auditor and insurer coordination, scheduled adversary testing, and incident readiness for your AI systems.

  • Everything in Leadership
  • Continuous compliance upkeep for a government or regulated program, such as CMMC or FedRAMP readiness
  • Scheduled control and evidence reviews on the cadence your program requires; scope and review windows agreed in writing
  • A weekly leadership cadence, with coordination for your auditors and insurers
  • One larger scheduled adversary-testing milestone each year, with objectives and prerequisites agreed in advance
  • Incident response playbooks and a practiced exercise for your AI systems

Cadence: Weekly touchpoints, monthly report, quarterly board update; specialist testing scheduled as milestones, not always-on. Readiness is not independent assessment, and a Certified Assessor who prepares an organization cannot assess it.

See Regulated & Enterprise in detail Or start a conversation
PICK AND CHOOSE

Add-ons for the milestones.

Scheduled, higher-intensity work that layers onto any plan when the calendar calls for it, priced to your scope. Estimate a full plan in the custom plan builder.

Scoped Penetration Test

A scheduled test of an agreed network, application or cloud boundary, with findings, reproduction steps and remediation guidance. The starting price is for a small external-network scope; other environments and combined coverage use their published catalog ranges. Program and higher plans already include an annual scoped test; a separate charge applies only to extra scope.

per engagementFrom $2,400, quoted to scope

Full-Scope Red Team Operation

Objective-driven adversary simulation with rules of engagement agreed in advance, showing what a determined attacker would achieve and how your prevention, detection, and response hold up. Best after testing and basic hardening are in place.

per engagementFrom $15,000, quoted to scope

Compliance Readiness Sprint

Readiness work for the chosen framework and boundary: identify gaps, plan controls and organize evidence. The entry price reflects a small HIPAA or PCI DSS scope; SOC 2, ISO 27001 and CMMC use their own published ranges. Independent audits, certification and authorization are separate. One agreed framework is included in Leadership and higher plans.

per frameworkFrom $4,500, quoted to scope

AI Governance Stand-Up

A one-time build of baseline AI policy, approval workflow and an approved-tools inventory. Program and higher plans already include that baseline within the agreed boundary. A formal AI management system or additional business units require a separate scope.

per programFrom $4,500, quoted to scope

Additional Tabletop Exercise

An extra leadership or technical incident exercise beyond your plan, run against a realistic scenario, with a written debrief and updates to your response plan.

per exerciseFrom $3,000, quoted to scope

Continuous-Compliance Maintenance

A recurring module that keeps your compliance documentation and evidence current as your controls change, so you are not rebuilding the package before every audit. Readiness maintenance only, not independent assessment.

per monthFrom $750 / month, quoted to scope

Vendor & Third-Party Software Assessment

Evaluate a software product before purchase or deployment. The starting scope is a review of one product’s vendor documents and software components, without hands-on testing. Technical testing costs more. Routine vendor-risk reviews within Program and higher plans are reconciled before a separate software assessment is quoted.

per assessmentFrom $1,800, quoted to scope
YOUR FIRST TWELVE MONTHS

A year with a plan, not a scramble.

A menu of possible milestones for a full program, not a promise that every item is included in every plan. Monitor has its monthly scanning cadence. Program includes one annual scoped test and retest; Leadership includes one annual incident exercise. Additional tests, frameworks and exercises below require coverage in the written annual scope or a separately quoted add-on.

Month 1

Onboarding and charter

  • Kickoff, and a charter naming what the principal may decide, draft, and sign
  • A map of your business, data, vendors, obligations, and insurance
  • Review of any open customer questionnaires and a first-year priorities readout
  • Begin the baseline risk assessment
Month 2

Baseline and roadmap

  • Finish the baseline risk and program-maturity assessment
  • Stand up the risk register and a sequenced roadmap
  • Start the security-questionnaire answer library
Month 3

First quarter close and perimeter test

  • First quarterly board update
  • First batch of policy reviews
  • External penetration test of your perimeter, with a retest of fixes
Month 4

Steady cadence and AI governance

  • Monthly leadership session and report
  • Reviews of new vendors and third parties
  • Stand up AI governance and an approved-tools inventory
  • Baseline how you detect attacks today
Month 5

Exercise the plan

  • Leadership incident exercise: activation, decisions, counsel and insurer, disclosure timing
  • Update the incident response plan from the debrief
Month 6

Mid-year review

  • Second quarterly board update
  • Re-check the early quick wins
  • Web application penetration test after a major release
Month 7

Governance depth

  • Second batch of policy reviews
  • Re-check AI risk and watch vendors for model and subprocessor changes
  • Pull and refresh compliance evidence
Month 8

Technical rehearsal

  • Technical incident exercise: detect, contain, remove, and recover
  • A session proving the detection gaps it surfaced are closed
Month 9

Third quarter close and internal test

  • Third quarterly board update
  • Internal or assumed-breach penetration test
  • Retest of findings remediated earlier in the year
Month 10

Assurance upkeep

  • Full refresh of vendor risk ratings
  • Compliance evidence and monitoring cycle
  • Cyber-insurance renewal preparation
Month 11

Adversary milestone

  • The year's largest test: a comprehensive penetration test or full-scope red team, once basics are fixed
  • Annual test of the incident response plan
Month 12

Year in review

  • Annual re-assessment of program maturity and risk
  • Fourth quarterly board update
  • Next-year roadmap and a risk-framed budget request
  • Close out the year's evidence for auditors, insurers, and customers
BEFORE YOU COMMIT

Common questions.

Is this a twelve-month program?

Yes. Every plan runs as a twelve-month program so the work builds across the year instead of restarting each quarter. You can move up a plan as you grow, and add-ons can be scheduled whenever the calendar calls for them. We shape the exact sequence around your risks, renewals, and audit dates in the first month.

Who actually does the work?

The same principal who scopes your program performs and reports it. There is no hand-off to junior staff, and nothing is offshored. When a milestone needs specialist depth beyond one person, it is scheduled and scoped in advance rather than promised as always-on.

Can you also assess or certify us against a framework?

No. These plans are readiness and program support, which is deliberately separate from the independent examination or certification. We prepare you and organize your evidence; an independent assessor, auditor, or certification body makes the formal decision. A Certified Assessor who prepares an organization cannot also assess it.

Does Monitor provide continuous monitoring or emergency response?

No. Monitor includes one scheduled external scan, report and check-in each month. Findings reflect that scan; changes between scans may not be detected. It does not include a staffed security operations center, managed detection and response, 24/7 review or an emergency-response service level. Review windows and escalation contacts are agreed in the written scope.

Will I be charged twice for work already in my plan?

No. The builder and request form identify included baseline work, use one annual-test slot for Program, and flag uncertain overlaps for scoping instead of automatically charging again. Choose extra scope only for a separate boundary, additional session or work beyond the agreed plan. Leadership’s testing rotation is scheduled in writing; it is not an unlimited testing allowance.

Can I add a penetration test or compliance sprint to any plan?

Yes. The add-ons are designed to layer onto any plan when the year calls for them, from a scheduled penetration test to a red team, a compliance readiness sprint, extra incident exercises, or a vendor software review. We place them on the calendar so the bigger milestones land when they are most useful.

Which plan is right for us?

Start with the plan that matches where you are: Monitor for basic visibility, Foundation for a named owner and a real rhythm, Program once vendors and a board are involved, Leadership when you are pursuing a compliance framework, and Regulated & Enterprise for government or heavily regulated obligations. If you are unsure, we will recommend one after a short conversation, and you can move up as you grow.

How do we get started?

We start with a short scoping conversation about your systems, risks and obligations. We confirm the plan, included boundaries, milestone counts, review windows and any add-ons in writing. Monitor begins with its scheduled external scan; Foundation and higher plans include the onboarding baseline assessment.

START AT THE SOURCE

Turn one-off projects into a program.

Tell us what you run and what the year holds. We’ll recommend a plan and shape the cadence around it.

Let’s talk security