(01)STACK BUILDER · DESIGN MODE

Three priced stacks, before you spend a dollar.

Tell the engine your industry and size. It answers with Lean, Balanced and Advanced — real products at list prices, the architecture they form, and the order to deploy them. What you see below is the engine on a sample company; the app runs it on your answers and your uploaded configs.

INDUSTRY
COMPANY SIZE

Sample profile: a 200-person SaaS / Software company reporting against SOC 2. Your run starts from your answers and reads your uploaded configs — this one starts from a fixture.

LEAN

Lean Beacon

The minimum a defensible program needs.

$95,475/yr · list · modeled
posture 35/100 modeledcoverage 91% of tier targets17 person-weeks
  • Microsoft Entra ID P1Identity$14,400
  • Microsoft Defender for Office 365 P1Email$4,800
  • Microsoft SentinelSIEM$5,475
  • Microsoft Defender for Endpoint P1Endpoint$7,200
  • AWS Inspector + ConfigCloud-native security$6,000
  • Datto SIRIS CloudBackup$4,800
  • Bitwarden EnterprisePassword management$14,400
  • Semgrep CloudAppSec$38,400
LEFT OPEN
  • · Native cloud security posture monitoring

Lean does not include MDR — incident response is your team plus best-effort hours.

8 PRODUCTS · LIST PRICES AS OF 2026-05-06
BALANCED · RECOMMENDED

Balanced Beacon

What most companies of this shape run.

$144,075/yr · list · modeled
posture 66/100 modeledcoverage 95% of tier targets25 person-weeks
  • Huntress Managed EDR + MDR for Microsoft 365MDR$21,000
  • Microsoft Entra ID P2Identity$21,600
  • Microsoft SentinelSIEM$5,475
  • Microsoft Defender for Office 365 P2Email$12,000
  • Datto SIRIS CloudBackup$4,800
  • AWS Inspector + ConfigCloud-native security$6,000
  • Bitwarden EnterprisePassword management$14,400
  • Cloudflare WAF (Pro / Business / Enterprise)AppSec$2,400
  • Tailscale BusinessZTNA$14,400
  • Tenable Vulnerability ManagementVulnerability management$18,000
  • Snyk TeamAppSec$24,000
LEFT OPEN
  • · Native cloud security posture monitoring

Balanced does not include cross-cloud CSPM — native cloud tooling only.

11 PRODUCTS · LIST PRICES AS OF 2026-05-06
ADVANCED

Hardened Beacon

Defence in depth for a mature program.

$216,975/yr · list · modeled
posture 90/100 modeledcoverage 96% of tier targets35 person-weeks
  • Microsoft Entra ID P2Identity$21,600
  • CrowdStrike Falcon CompleteMDR$67,500
  • Microsoft SentinelSIEM$5,475
  • Microsoft Defender for Office 365 P2Email$12,000
  • Veeam Data Platform FoundationBackup$6,000
  • Microsoft Defender for Cloud (CSPM + CWPP plans)Cloud-native security$12,000
  • Bitwarden EnterprisePassword management$14,400
  • Tenable Vulnerability ManagementVulnerability management$18,000
  • Cloudflare WAF (Pro / Business / Enterprise)AppSec$2,400
  • Microsoft Purview Information Protection + DLPDLP$16,800
  • Cloudflare One Zero TrustZTNA$16,800
  • Snyk TeamAppSec$24,000
LEFT OPEN
  • · Offsite restore drills run at least quarterly

Advanced significantly increases vendor count — expect non-trivial integration ops load.

12 PRODUCTS · LIST PRICES AS OF 2026-05-06
ARCHITECTURE · WHERE EACH PRODUCT SITS

The Balanced stack, as a system

Edge / PerimeterNOT IN THIS TIERIdentity3 PRODUCTSMicrosoft Microsoft Entra ID P2 · $21,600/yr (list, 2026-04-27)Microsoft Entra ID P2Bitwarden Bitwarden Enterprise · $14,400/yr (list, 2026-04-27)Bitwarden EnterpriseTailscale Tailscale Business · $14,400/yr (list, 2026-04-27)Tailscale BusinessEndpointNOT IN THIS TIEREmail & Collab1 PRODUCTMicrosoft Defender for Office 365 P2 · $12,000/yr (list, 2026-04-27)Defender for Office 365P2Apps & Cloud4 PRODUCTSAWS Inspector + Config · $6,000/yr (list, 2026-04-27)Inspector + ConfigCloudflare WAF (Pro / Business / Enterprise) · $2,400/yr (list, 2026-04-27)WAF (Pro / Business /Enterprise)Tenable Tenable Vulnerability Management · $18,000/yr (list, 2026-04-27)Tenable VulnerabilityManagementSnyk Snyk Team · $24,000/yr (list, 2026-04-27)Snyk TeamDataNOT IN THIS TIERDetection & Response2 PRODUCTSHuntress Huntress Managed EDR + MDR for Microsoft 365 · $21,000/yr (list, 2026-04-27)Huntress Managed EDR +MDR for Microsoft 365Microsoft Microsoft Sentinel · $5,475/yr (list, 2026-04-27)Microsoft SentinelRecovery1 PRODUCTDatto SIRIS Cloud · $4,800/yr (list, 2026-04-27)SIRIS CloudTELEMETRY INTO DETECTIONBACKUP PATHMODELED FROM THE SAMPLE PROFILE · NOT A SCAN

Every product docks into the zone it defends; the thin lines are telemetry into detection and response and the backup path out of Data. Empty zones are gaps this tier leaves open — named, not hidden.

THE PLAN · BALANCED TIER

11 steps, in the order that works

Identity before the tools that depend on it; logging before the tools that feed it. About 25 person-weeks end to end. 4 of the 11 steps ship with a CyberTwin playbook — configuration, prerequisites, validation, compliance side-effects; the rest link the vendor's own setup docs.

  1. 01Bitwarden EnterpriseBitwarden · Password management
    1wVENDOR DOCS
  2. 02Microsoft Entra ID P2Microsoft · Identity
    3wPLAYBOOK
  3. 03Tailscale BusinessTailscale · ZTNA
    1wVENDOR DOCS
  4. 04Defender for Office 365 P2Microsoft · Email
    2wPLAYBOOK
  5. 05Tenable Vulnerability ManagementTenable · Vulnerability management
    3wVENDOR DOCS
  6. 06Snyk TeamSnyk · AppSec
    2wPLAYBOOK
  7. 07WAF (Pro / Business / Enterprise)Cloudflare · AppSec
    1wVENDOR DOCS
  8. 08Inspector + ConfigAWS · Cloud-native security
    2wVENDOR DOCS
  9. + 3 more in the full plan
LEFT AS IS · MODELED
Expected annual loss for this profile without a stack: $607K–$5.9M (p10–p90, p50 $1.9M; modeled from headcount)
against $144,075/yr for the Balanced stack

Prices are vendor list prices, each verified on the date it carries (newest 2026-05-06) — an estimate for budgeting, not a quote. Posture and dollars are modeled from the sample profile. Nothing here scanned anything: the app runs the same engine on your answers and the configs you upload. Coverage is scored against each tier's own target set — a richer tier aims at a broader one — so compare tiers on posture, the single ruler applied to all three.

(02)HOW IT DECIDES

Capabilities first. Products second. Prices last — and dated.

01 · REQUIRED

Your shape sets the requirements

Industry, headcount and the frameworks you report against decide which capabilities are must-have, should-have and nice-to-have — MFA on every admin account, managed detection, immutable backups. The tier is the depth you buy, not a different opinion.

02 · CATALOG

99 products, each with a sourced list price

Every product carries its price source and the date it was verified (newest 2026-05-06), the capabilities it satisfies, and the alternatives that were considered. The engine picks for fit and ecosystem — a Microsoft 365 company gets Entra and Defender, not a parallel identity stack.

03 · STATED

What each tier leaves open is printed

Unmet capabilities, the trade-off of every pick, the assumed products you already run, and a posture score with its confidence band — all labeled modeled, all in the report. 24 frameworks are scored from the same profile, no second questionnaire.

(03)FROM STACK TO RUNNING

The plan is the product, not a PDF of logos.

Every stack comes with its deployment plan: the steps in dependency order, an effort estimate per step, and — where CyberTwin has authored one — a playbook with the exact configuration, prerequisites, validation checks and the compliance controls each step satisfies. Steps without a playbook link the vendor's own setup docs and say so.

Then you upload the real config and the same engine grades what you actually deployed — the loop that turns a recommendation into proof.

ONE PLAYBOOK STEP · AS DELIVERED
02Microsoft Entra ID P2 — Conditional Access baseline3 person-weeks
  • Prerequisites: P2 licences in scope, MFA enrolled, hybrid or Entra join, device compliance feeding Intune
  • Policies: block legacy authentication; require MFA for all users; require compliant device for admins; named locations
  • Validation: pilot group first — conditional-access misconfigurations lock people out
  • Satisfies: SOC 2 CC6.1 · CC6.3 — noted on the step and rolled into the compliance scorecard

Excerpt from the sample deployment plan (Balanced tier). Per-step compliance annotations ship on Operate and above; the plan itself on every plan.

(04)WHO BUILDS A STACK HERE

Four moments when the stack is the decision.

The first program

A startup hiring its first security lead, or a founder doing it themselves: a defensible baseline priced out in an afternoon, with the order to deploy it.

The rebuild

After an incident, a renewal shock or a failed audit — the current stack scored next to three alternatives, with what each one closes and what it leaves open.

The integration

Two companies, two stacks, one budget. Model the combined estate and see which tools survive the merge and which are paying twice for one capability.

The new CISO

Ninety days to a plan the board will fund. Three tiers, dollars attached, the roadmap sequenced — and a re-check every time a config changes.

Build yours from your answers, not a fixture.

Assess includes the full intake, all three stacks, the architecture, the deployment plan and the report. No call required.

Build your security stack — three priced options from one profile · CyberTwin