Cost the whole defence,
not one scanner.
Build an annual operating model across governance, identity, data, product security, penetration testing, red teaming, detection, incident response and resilience. Start with illustrative rates, then enter annual quotes for each workstream.
A balanced programme view
Calculating coverage…
Security workstreams
Switch a workstream off to model a phased rollout. Values are directional annual planning assumptions—not vendor quotes.
Transparent drivers, not false precision.
The model combines organisation scale, asset and data scope, application count, assurance cadence, target maturity and loaded security staffing. The depth multipliers are 0.72, 1.00, 1.28 and 1.55. These are editable planning assumptions, not NIST maturity ratings or market benchmarks. Annual workstream overrides replace the model estimate. People are allocated 22% Govern, 8% Identify, 30% Protect, 20% Detect, 12% Respond and 8% Recover.
Policy, risk, asset, vulnerability and third-party coverage.
ProtectIdentity, endpoint, cloud, data security and secure development.
Telemetry, SOC operations, exercises, incident handling, backup and continuity validation.
Validate before budgetingReplace assumptions with current salaries, provider rates, scope statements and negotiated quotes.
