Event-Specific Security Enhancement Program
Specialized security packages tailored for specific major events like the Super Bowl, World Series, Kentucky Derby, focusing on unique venue characteristics and event-specific requirements.
In scope
- Event-specific threat assessment
- Historical incident analysis
- Local coordination planning
- Specialized venue security
- Event-specific access control
- Local threat intelligence
- Cultural considerations
- Regional security integration
You receive
- Event-specific security plan
- Local coordination framework
- Specialized venue protocols
- Cultural sensitivity guidelines
- Regional security matrix
- Local threat analysis
- Event-specific playbooks
- After-action documentation
Tiers
Choose the depth.
Core Event Enhancement Package
$150K
One named event at 1 venue: event-specific threat assessment, historical incident analysis, local threat intelligence and an event security plan with up to 3 playbooks. One coordination session with local agencies.
- Sites
- 1
- Objectives
- 3
- sessions
- 1
- Event-specific threat assessment
- Historical incident analysis
- Local threat intelligence summary
- Event security plan with up to 3 playbooks
- One local coordination session
- — Venue-specific access control design
- — On-site presence during the event
- — After-action documentation
- — Tabletop exercises
Advanced Event Enhancement Program
$275K
One event across up to 2 venues: everything in the basic tier, venue-specific protocols and access control design, a local coordination framework, regional security matrix, up to 6 playbooks and up to 3 sessions including 1 tabletop exercise.
- Sites
- 2
- Objectives
- 6
- sessions
- 3
- Everything in the basic tier
- Venue-specific security protocols and access control design
- Local coordination framework and regional security matrix
- Up to 6 playbooks
- One tabletop exercise with local agencies
- — On-site team during event days
- — Custom coordination tooling
- — After-action review
Premium Event Enhancement Solution
$450K
One event across up to 4 venues: everything in the advanced tier, custom coordination tooling for local partners, up to 10 playbooks, up to 6 sessions including 2 exercises, on-site advisory presence during event days and after-action documentation.
- Sites
- 4
- Objectives
- 10
- sessions
- 6
- Everything in the advanced tier
- Custom local coordination and reporting tooling
- On-site advisory team during event days
- Two exercises including one full rehearsal
- After-action documentation
- — Guard force or physical security staffing
- — Security equipment and screening hardware
- — A second event
Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.
What's inside this engagement
Phase by phase.
How a security assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.
01Scoping
Systems, sites, stakeholders and the question the assessment must answer.
You see · Your objectives and constraints.
02Discovery & evidence
Documents, configurations and interviews, plus technical testing where the service includes it.
You see · Access and time with key people.
03Analysis
Findings rated by risk to your business, not by a generic score.
You see · A prioritized view of your risk.
04Report & debrief
Executive summary, findings and a remediation roadmap, walked through with your team.
You see · The report and the debrief.
Commercials
From first call to final report.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Related
Blockchain Contact Analysis Service
In-depth analysis of blockchain contacts and transactions to trace asset movement, identify patterns, and assess security risks in cryptocurrency operations.
Quantum-Safe Cryptography Readiness
Future-proof your cryptographic infrastructure with quantum-safe algorithms and protocols. Includes assessment, migration planning, and implementation support.
Banking and Web3 Redundancy Assessment
Advanced assessment of banking and Web3 infrastructure focusing on redundancy, privacy, and security measures for cryptocurrency and traditional banking operations.
Research
Latest from the blog

events · Aug 11, 2026
Hacker Summer Camp 2026: The Monday Morning Action Plan
Black Hat, BSidesLV and DEF CON 34 produced one coherent argument across nine days: agent identity is the new privileged access problem, exposure reduction has replaced patch velocity, and supply chain defenses that everyone knows about still aren't finished. Here are eleven things to do this week, sequenced by effort, plus the four numbers to put in front of your board.

events · Aug 10, 2026
DEF CON 34 Debrief: "Agency" Was the Theme, and the Sandbox Turned Out to Be a Suggestion
DEF CON 34 ran August 6–9 at the Las Vegas Convention Center under the theme "Agency" — self-determination in an increasingly automated world. Thirty-eight villages, the AI Village's first HALctf autonomous pentest competition, TEEs broken via DDR5 and timing side channels, a million vehicles exposed via BLE, and a keynote panel on dual-use AI with Schneier and Adkins. The CISO read.

events · Aug 8, 2026
BSidesLV 2026: The Track That Called ChainDrop a Day Early, and Why Ground Truth Is the Best Data in Vegas
While Black Hat filled Mandalay Bay, BSidesLV ran August 3–5 at the Tuscany with the research that had no vendor budget behind it. The [un]prompted AI track warned about agentic worm risk the day before ChainDrop poisoned 444 npm packages. Ground Truth put vishing success at up to 36% and dissected 95 red team engagements. Proving Ground's npm supply chain talk read like a prophecy.
Start an engagement