Skip to content
CISO Marketplace Services

Practice 03

Cloud & Application Security

Cloud posture, application and API security, secure code review and DevSecOps. Security built into how you ship, not bolted on afterwards.

20 services

What we deliver.

Starting prices come from our live catalog. Your proposal fixes the tier and price before anything is signed.

Zero Trust Architecture Implementation

Comprehensive zero trust security architecture design and implementation service tailored for enterprise environments. Includes network segmentation, identity-based access controls, and continuous monitoring setup.

From $75K

Cloud Security Posture Management

Advanced cloud security assessment and continuous monitoring implementation across multi-cloud environments, focusing on compliance, cost optimization, and security automation.

From $65K

Secure Code Review

Comprehensive analysis of application source code to identify security vulnerabilities, coding flaws, and implementation issues that could lead to security breaches. Our expert review combines automated scanning with manual expert analysis.

From $35K

SaaS Security Posture Assessment

Comprehensive security evaluation of your cloud-based productivity and collaboration platforms, including Microsoft 365, Google Workspace, and other critical SaaS environments. Our assessment identifies security misconfigurations, access control weaknesses, data protection gaps, and provides actionable recommendations to secure your cloud-based business operations.

From $32K

SMB Comprehensive Security Assessment

Practical and efficient security evaluation designed specifically for small and medium-sized businesses. This streamlined assessment focuses on essential security controls, cloud security, and practical recommendations that can be implemented with limited resources. Our SMB-focused approach delivers actionable security guidance without requiring enterprise-scale security teams or budgets.

From $25K

Comprehensive Container Security Assessment

Deep-dive security assessment of container environments, including infrastructure, images, runtime security, and orchestration platforms.

From $15K

Microsoft 365 Copilot & GenAI Data-Oversharing Readiness

Copilot and other GenAI assistants answer with whatever a user can technically reach. This engagement maps overshared SharePoint, OneDrive and Teams content, stale and broken permissions, sensitivity labelling gaps and risky sites, then delivers the remediation and governance plan that makes a Copilot rollout defensible — including an AI acceptable-use policy and the Purview controls to enforce it.

From $12.5K

DevSecOps Pipeline Testing

Comprehensive security testing integrated into your development pipeline with regular assessments.

From $12K / mo

API Security Assessment

Comprehensive testing of API endpoints and integrations

From $12K

Cloud Security Assessment

Security evaluation of cloud infrastructure and configurations

From $12K

Cloud Security Monitoring

Continuous monitoring and assessment of your cloud infrastructure security posture.

From $10K / mo

Mobile Application Security Assessment

Comprehensive security testing of iOS and Android applications

From $10K

Web Application Security Assessment

In-depth testing of web applications for security vulnerabilities

From $8K

SMB Advanced Tech

Modern tech stack security assessment for digital-first SMBs.

From $7.5K

Threat Modeling as a Service

Threat modelling finds design flaws before they are built, which is cheaper than finding them in a pentest. Per application or major feature, we run facilitated sessions with your engineers, produce data-flow diagrams and a STRIDE-based threat register, rate the risks, and hand back mitigations as backlog-ready stories. AI-assisted diagramming keeps it fast; a security architect keeps it right.

From $6.5K

Microsoft 365 & Entra ID Security Assessment

A fixed-scope assessment of the Microsoft 365 tenant most organizations run their business on: identity and conditional access in Entra ID, Exchange Online and anti-phishing, SharePoint/OneDrive/Teams sharing, Defender and Purview configuration, admin roles and break-glass accounts. Measured against the CIS Microsoft 365 Foundations Benchmark and Microsoft Secure Score, delivered as a prioritized hardening plan your IT team or MSP can execute.

From $4.5K

Secure Development Training & Security Champions Program

Annual slide-deck training does not change how code is written. We train developers on the vulnerabilities found in your own stack and findings, run hands-on labs, and stand up a security champions program — named engineers in each team with a playbook, office hours and metrics — so secure design survives after the training ends. Satisfies SOC 2, ISO 27001 and PCI developer-training requirements.

From $4.5K

Managed DMARC & Email Authentication Enforcement

Spoofed email is how business email compromise starts, and mailbox providers now require authentication from bulk senders. We inventory every service sending as your domains, fix SPF, DKIM and alignment, move DMARC from monitoring to quarantine to reject in controlled steps, and then monitor it so a new marketing tool does not quietly break it.

From $3.5K

MCP & Agent Tool-Chain Security Assessment

Assess the security of agent tool-chains: MCP servers, tool/function connections, inter-agent communication, and the authz/credential model behind agent actions.

Scoped per engagement

Data Security Posture Management (DSPM) Assessment

Discover known and shadow data across cloud and on-prem, classify sensitive data, map access and flows, and remediate exposure. Establishes a continuous data security posture aligned to privacy regimes.

Scoped per engagement

Process

How an engagement runs.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor