Skip to content
CISO Marketplace Services

The services arm of CISO Marketplace

Offensive security.
AI security.
Done by operators.

We break into networks, applications and AI systems the way real adversaries do, then show you exactly how to close the path. Fixed scope, published starting prices, evidence behind every finding.

attack-path.graph objective reached
Illustrative attack path: exposed VPN and a phished user lead to a workstation, then Kerberoasting and a file server, ending at Domain Admin.Exposed VPNT1133Phished userT1566WorkstationT1059KerberoastT1558File serverT1021Domain AdminT1078
Illustrative. Each engagement report maps the real path to MITRE ATT&CK.

Flagship practices

Two disciplines, one team.

Most real breaches now chain a traditional weakness with an AI one. We test both, together.

Not sure where to start?

Start with Phase 0.

The six pillars of the AI security program are not sold off a shelf — they are built into your ecosystem, and that requires knowing the ecosystem first. Phase 0 is a scoped, fixed-fee assessment that maps your environment end to end: every AI system in use (sanctioned and shadow), the DevSecOps reality, the data and identity stack, the SIEM / EDR / tooling landscape, and where testing should start. It defines how each pillar gets built for you (BYOK and open-source first, commercial upgrades where they earn their place), designs the integration seams into what you already run, and plans the deployment topology for distributed sites. The output is the current-state map, the future-state design and a sequenced build plan — and only then does the program get a number. CISO Marketplace members get the Phase 0 fee credited toward the program if they proceed.

From$17.5K

See Phase 0 →

The full practice

182 services across the security program.

When testing finds the gaps, the same team can close them: cloud, incident response, leadership and compliance.

Process

How every engagement runs.

Same six steps whether it's a single web application or a multi-site red team.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor