Security Cost Model Programme economics
Local scenario
Security programme economics · INR

Cost the whole defence,
not one scanner.

Build an annual operating model across governance, identity, data, product security, penetration testing, red teaming, detection, incident response and resilience. Start with illustrative rates, then enter annual quotes for each workstream.

NIST CSF 2.0 OWASP SAMM / ASVS NIST SP 800-115 CIS Controls
Annual programme ₹0 ₹0 per employee
Monthly run rate ₹0 including people and tooling
Internal security team 0% ₹0 annual loaded cost
Assurance and testing ₹0 VAPT, AppSec and red team
Allocation by CSF function

A balanced programme view

₹0 annual
Model signal

Calculating coverage…

Editable programme scope

Security workstreams

Switch a workstream off to model a phased rollout. Values are directional annual planning assumptions—not vendor quotes.

How the model works

Transparent drivers, not false precision.

The model combines organisation scale, asset and data scope, application count, assurance cadence, target maturity and loaded security staffing. The depth multipliers are 0.72, 1.00, 1.28 and 1.55. These are editable planning assumptions, not NIST maturity ratings or market benchmarks. Annual workstream overrides replace the model estimate. People are allocated 22% Govern, 8% Identify, 30% Protect, 20% Detect, 12% Respond and 8% Recover.

Govern + Identify

Policy, risk, asset, vulnerability and third-party coverage.

Protect

Identity, endpoint, cloud, data security and secure development.

Detect + Respond + Recover

Telemetry, SOC operations, exercises, incident handling, backup and continuity validation.

Validate before budgeting

Replace assumptions with current salaries, provider rates, scope statements and negotiated quotes.

Methodology references NIST CSF 2.0 ↗ NIST SP 800-115 ↗ OWASP ASVS ↗ OWASP SAMM ↗ CIS Controls ↗