# Continuous Security Validation Service

> From $8.5K / mo · Offensive Security · https://cisomarketplace.services/services/continuous-security-validation

Subscription-based ongoing testing of your security controls, detection capabilities, and response procedures against real-world attack techniques. Our continuous validation approach provides evidence-based assessment of security effectiveness beyond traditional point-in-time assessments, ensuring your defenses work as expected against evolving threats.

## In scope

- Automated security control testing
- MITRE ATT&CK-based scenarios
- Detection capability validation
- Prevention control validation
- Response procedure testing
- Purple team exercises
- Evasion technique testing
- Security tool configuration validation
- Lateral movement simulation
- Data exfiltration testing

## Deliverables

- Monthly validation reports
- Control effectiveness metrics
- Detection gap analysis
- Prevention bypass findings
- Security improvement recommendations
- MITRE technique coverage mapping
- Response time analytics
- Executive dashboards
- Security ROI validation
- Continuous improvement roadmap

## Tiers

### Essential Security Validation: $8.5K / month

Monthly test cycle: up to 10 MITRE ATT&CK-based scenarios per cycle run from up to 5 test hosts against core prevention and detection controls (endpoint, email, network). Monthly report with detection gaps and 1 purple team session per year.

Limits: scenarios 10, internal hosts 5, sessions 1

Includes:
- 1 test cycle per month
- Up to 10 ATT&CK scenarios per cycle
- Prevention and detection control validation
- Monthly report and technique coverage map
- 1 purple team session per year

Excludes:
- Lateral movement and data exfiltration simulation
- Evasion technique testing
- Custom scenarios
- Detection rule writing in the client's SIEM

### Advanced Security Validation Program: $15K / month

Bi-weekly test cycles: up to 25 scenarios per cycle from up to 15 test hosts. Adds lateral movement, exfiltration and evasion testing, security tool configuration validation, response-time analytics and 4 purple team sessions per year.

Limits: scenarios 25, internal hosts 15, sessions 4

Includes:
- 2 test cycles per month
- Up to 25 scenarios per cycle
- Lateral movement, exfiltration and evasion tests
- Security tool configuration validation
- Response-time analytics
- 4 purple team sessions per year

Excludes:
- Custom scenarios built for the client's threat profile
- Full kill-chain simulations
- Named dedicated engineers
- Detection rule writing in the client's SIEM

### Enterprise Continuous Validation: $25K / month

Continuous testing with no fixed scenario cap, from up to 50 test hosts. Adds custom scenarios built to the client's threat profile, full kill-chain simulations, named security engineers, monthly purple team sessions and executive dashboards.

Limits: internal hosts 50, sessions 12

Includes:
- Continuous testing, no fixed scenario cap
- Custom threat-profile scenarios
- Full kill-chain simulations
- Named security engineers
- 12 purple team sessions per year
- Executive dashboards

Excludes:
- Full-scope red team engagement with physical or social engineering
- Licences for the client's own security tools
- 24/7 monitoring or incident response

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=continuous-security-validation
