Skip to content
CISO Marketplace Services

Security Architecture Review

Comprehensive analysis of your organization's security architecture design, evaluating defense-in-depth strategies, security control effectiveness, and alignment with business objectives and threat models.

In scope

  • Network segmentation analysis
  • Access control frameworks
  • Data flow assessment
  • Security boundary evaluation
  • Defense-in-depth review
  • Zero Trust framework compatibility
  • Identity and authentication architecture review

You receive

  • Detailed architecture assessment report
  • Security control gap analysis
  • Reference architecture recommendations
  • Risk mitigation roadmap
  • Prioritized security enhancement plan
  • Threat modeling documentation

Tiers

Choose the depth.

Core Architecture Assessment

$40K

One environment: up to 500 employees, up to 2 data centers/sites and up to 3 cloud accounts. Reviews segmentation, access control, identity architecture, data flows and security boundaries from diagrams, configs and workshops. One high-level threat model.

employees
500
Sites
2
cloud accounts
3
  • Network segmentation and security boundary analysis
  • Identity and authentication architecture review
  • Data flow assessment for critical data
  • One high-level threat model
  • Control gap analysis and prioritized enhancement plan
  • — Zero Trust implementation strategy
  • — Per-system threat models
  • — Reference architecture design
  • — Penetration testing or configuration scanning
Scope Core Architecture Assessment

Advanced Architecture Program

$75K

Up to 2,500 employees, up to 5 sites and up to 10 cloud accounts. Adds documented threat models for up to 5 critical systems, a defense-in-depth control mapping and a phased Zero Trust implementation strategy.

employees
2500
Sites
5
cloud accounts
10
  • Everything in the core assessment
  • Threat models for up to 5 critical systems
  • Zero Trust compatibility assessment and phased strategy
  • Defense-in-depth control mapping
  • Risk mitigation roadmap
  • — Target-state reference architecture
  • — Security governance framework
  • — Implementation or engineering work
  • — Penetration testing
Scope Advanced Architecture Program

Enterprise Security Architecture Transformation

$125K

No fixed headcount cap - scoped. Up to 10 sites and up to 25 cloud accounts. Adds a target-state reference architecture, a multi-year modernization roadmap, threat models for up to 10 critical systems and an architecture governance framework (review board, standards, exceptions).

Sites
10
cloud accounts
25
  • Everything in the advanced tier
  • Target-state reference architecture
  • Multi-year modernization roadmap with sequencing
  • Architecture governance framework
  • Threat models for up to 10 critical systems
  • — Building or deploying the target architecture
  • — Product selection RFPs
  • — Penetration testing
  • — Ongoing architecture review board participation
Scope Enterprise Security Architecture Transformation

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a readiness & governance assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & framework selection

    The standard or regulation, the systems and the business units in scope are fixed.

    You see · Your audit or regulatory driver.

  2. 02Evidence collection & interviews

    Policies, configurations and records reviewed; control owners interviewed.

    You see · Documents and time with control owners.

  3. 03Gap analysis

    Each requirement mapped to current state: met, partial or missing, with the evidence behind it.

    You see · A clear gap register.

  4. 04Roadmap & evidence plan

    Prioritized remediation with owners, and the evidence an auditor will ask for.

    You see · A plan you can execute or hand to us.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor