(01)STACK BUILDER · DESIGN MODE

Three priced stacks, before you spend a dollar.

Tell the engine your industry and size. It answers with Lean, Balanced and Advanced — real products at list prices, the architecture they form, and the order to deploy them. What you see below is the engine on a sample company; the app runs it on your answers and your uploaded configs.

INDUSTRY
COMPANY SIZE

Sample profile: a 200-person Fintech / Payments company reporting against SOC 2, PCI DSS v4, ISO 27001. Your run starts from your answers and reads your uploaded configs — this one starts from a fixture.

LEAN

Lean Beacon

The minimum a defensible program needs.

$99,265/yr · list · modeled
posture 31/100 modeledcoverage 73% of tier targets18 person-weeks
  • Semgrep CloudAppSec$38,400
  • Microsoft Entra ID P1Identity$14,400
  • Microsoft Defender for Office 365 P1Email$4,800
  • Microsoft SentinelSIEM$5,475
  • Microsoft Defender for Endpoint P1Endpoint$7,200
  • AWS GuardDuty + Security HubCloud-native security$4,800
  • Tenable Nessus ProfessionalVulnerability management$4,990
  • Datto SIRIS CloudBackup$4,800
  • Bitwarden EnterprisePassword management$14,400
LEFT OPEN
  • · Cardholder Data Environment (CDE) network segmentation
  • · File-integrity monitoring on CDE systems
  • · Documented cardholder-data key management
  • · CHD tokenization for non-payment-processor use

Lean does not include MDR — incident response is your team plus best-effort hours.

9 PRODUCTS · LIST PRICES AS OF 2026-05-06
BALANCED · RECOMMENDED

Balanced Beacon

What most companies of this shape run.

$169,275/yr · list · modeled
posture 69/100 modeledcoverage 86% of tier targets28 person-weeks
  • Microsoft SentinelSIEM$5,475
  • Snyk TeamAppSec$24,000
  • Cloudflare One Zero TrustZTNA$16,800
  • Huntress Managed EDR + MDR for Microsoft 365MDR$21,000
  • Nightfall AIDLP$19,200
  • Microsoft Entra ID P2Identity$21,600
  • Microsoft Defender for Office 365 P2Email$12,000
  • Datto SIRIS CloudBackup$4,800
  • Tenable Vulnerability ManagementVulnerability management$18,000
  • Microsoft Defender for Cloud (CSPM + CWPP plans)Cloud-native security$12,000
  • Bitwarden EnterprisePassword management$14,400
LEFT OPEN
  • · Cardholder Data Environment (CDE) network segmentation
  • · File-integrity monitoring on CDE systems
  • · Documented cardholder-data key management
  • · CHD tokenization for non-payment-processor use

Balanced does not include cross-cloud CSPM — native cloud tooling only.

11 PRODUCTS · LIST PRICES AS OF 2026-05-06
ADVANCED

Hardened Beacon

Defence in depth for a mature program.

$204,975/yr · list · modeled
posture 74/100 modeledcoverage 84% of tier targets35 person-weeks
  • Microsoft Entra SuiteIdentity$28,800
  • Microsoft SentinelSIEM$5,475
  • Snyk TeamAppSec$24,000
  • CrowdStrike Falcon CompleteMDR$67,500
  • Microsoft Defender for Office 365 P2Email$12,000
  • Microsoft Defender for Cloud (CSPM + CWPP plans)Cloud-native security$12,000
  • Veeam Data Platform FoundationBackup$6,000
  • Tenable Vulnerability ManagementVulnerability management$18,000
  • Microsoft Purview Information Protection + DLPDLP$16,800
  • Bitwarden EnterprisePassword management$14,400
LEFT OPEN
  • · Offsite restore drills run at least quarterly
  • · Cardholder Data Environment (CDE) network segmentation
  • · File-integrity monitoring on CDE systems
  • · Documented cardholder-data key management

Advanced significantly increases vendor count — expect non-trivial integration ops load.

10 PRODUCTS · LIST PRICES AS OF 2026-05-06
ARCHITECTURE · WHERE EACH PRODUCT SITS

The Balanced stack, as a system

Edge / PerimeterNOT IN THIS TIERIdentity3 PRODUCTSCloudflare Cloudflare One Zero Trust · $16,800/yr (list, 2026-04-27)Cloudflare One ZeroTrustMicrosoft Microsoft Entra ID P2 · $21,600/yr (list, 2026-04-27)Microsoft Entra ID P2Bitwarden Bitwarden Enterprise · $14,400/yr (list, 2026-04-27)Bitwarden EnterpriseEndpointNOT IN THIS TIEREmail & Collab1 PRODUCTMicrosoft Defender for Office 365 P2 · $12,000/yr (list, 2026-04-27)Defender for Office 365P2Apps & Cloud3 PRODUCTSSnyk Snyk Team · $24,000/yr (list, 2026-04-27)Snyk TeamTenable Tenable Vulnerability Management · $18,000/yr (list, 2026-04-27)Tenable VulnerabilityManagementMicrosoft Defender for Cloud (CSPM + CWPP plans) · $12,000/yr (list, 2026-04-27)Defender for Cloud(CSPM + CWPP plans)Data1 PRODUCTNightfall Nightfall AI · $19,200/yr (list, 2026-04-27)Nightfall AIDetection & Response2 PRODUCTSMicrosoft Microsoft Sentinel · $5,475/yr (list, 2026-04-27)Microsoft SentinelHuntress Huntress Managed EDR + MDR for Microsoft 365 · $21,000/yr (list, 2026-04-27)Huntress Managed EDR +MDR for Microsoft 365Recovery1 PRODUCTDatto SIRIS Cloud · $4,800/yr (list, 2026-04-27)SIRIS CloudTELEMETRY INTO DETECTIONBACKUP PATHMODELED FROM THE SAMPLE PROFILE · NOT A SCAN

Every product docks into the zone it defends; the thin lines are telemetry into detection and response and the backup path out of Data. Empty zones are gaps this tier leaves open — named, not hidden.

THE PLAN · BALANCED TIER

11 steps, in the order that works

Identity before the tools that depend on it; logging before the tools that feed it. About 28 person-weeks end to end. 5 of the 11 steps ship with a CyberTwin playbook — configuration, prerequisites, validation, compliance side-effects; the rest link the vendor's own setup docs.

  1. 01Bitwarden EnterpriseBitwarden · Password management
    1wVENDOR DOCS
  2. 02Microsoft Entra ID P2Microsoft · Identity
    3wPLAYBOOK
  3. 03Cloudflare One Zero TrustCloudflare · ZTNA
    2wPLAYBOOK
  4. 04Defender for Office 365 P2Microsoft · Email
    2wPLAYBOOK
  5. 05Nightfall AINightfall · DLP
    2wVENDOR DOCS
  6. 06Tenable Vulnerability ManagementTenable · Vulnerability management
    3wVENDOR DOCS
  7. 07Snyk TeamSnyk · AppSec
    2wPLAYBOOK
  8. 08Defender for Cloud (CSPM + CWPP plans)Microsoft · Cloud-native security
    3wVENDOR DOCS
  9. + 3 more in the full plan
LEFT AS IS · MODELED
Expected annual loss for this profile without a stack: $3.1M–$26.7M (p10–p90, p50 $9.2M; modeled from headcount)
against $169,275/yr for the Balanced stack

Prices are vendor list prices, each verified on the date it carries (newest 2026-05-06) — an estimate for budgeting, not a quote. Posture and dollars are modeled from the sample profile. Nothing here scanned anything: the app runs the same engine on your answers and the configs you upload. Coverage is scored against each tier's own target set — a richer tier aims at a broader one — so compare tiers on posture, the single ruler applied to all three.

(02)HOW IT DECIDES

Capabilities first. Products second. Prices last — and dated.

01 · REQUIRED

Your shape sets the requirements

Industry, headcount and the frameworks you report against decide which capabilities are must-have, should-have and nice-to-have — MFA on every admin account, managed detection, immutable backups. The tier is the depth you buy, not a different opinion.

02 · CATALOG

99 products, each with a sourced list price

Every product carries its price source and the date it was verified (newest 2026-05-06), the capabilities it satisfies, and the alternatives that were considered. The engine picks for fit and ecosystem — a Microsoft 365 company gets Entra and Defender, not a parallel identity stack.

03 · STATED

What each tier leaves open is printed

Unmet capabilities, the trade-off of every pick, the assumed products you already run, and a posture score with its confidence band — all labeled modeled, all in the report. 24 frameworks are scored from the same profile, no second questionnaire.

(03)FROM STACK TO RUNNING

The plan is the product, not a PDF of logos.

Every stack comes with its deployment plan: the steps in dependency order, an effort estimate per step, and — where CyberTwin has authored one — a playbook with the exact configuration, prerequisites, validation checks and the compliance controls each step satisfies. Steps without a playbook link the vendor's own setup docs and say so.

Then you upload the real config and the same engine grades what you actually deployed — the loop that turns a recommendation into proof.

ONE PLAYBOOK STEP · AS DELIVERED
02Microsoft Entra ID P2 — Conditional Access baseline3 person-weeks
  • Prerequisites: P2 licences in scope, MFA enrolled, hybrid or Entra join, device compliance feeding Intune
  • Policies: block legacy authentication; require MFA for all users; require compliant device for admins; named locations
  • Validation: pilot group first — conditional-access misconfigurations lock people out
  • Satisfies: SOC 2 CC6.1 · CC6.3 — noted on the step and rolled into the compliance scorecard

Excerpt from the sample deployment plan (Balanced tier). Per-step compliance annotations ship on Operate and above; the plan itself on every plan.

(04)WHO BUILDS A STACK HERE

Four moments when the stack is the decision.

The first program

A startup hiring its first security lead, or a founder doing it themselves: a defensible baseline priced out in an afternoon, with the order to deploy it.

The rebuild

After an incident, a renewal shock or a failed audit — the current stack scored next to three alternatives, with what each one closes and what it leaves open.

The integration

Two companies, two stacks, one budget. Model the combined estate and see which tools survive the merge and which are paying twice for one capability.

The new CISO

Ninety days to a plan the board will fund. Three tiers, dollars attached, the roadmap sequenced — and a re-check every time a config changes.

Build yours from your answers, not a fixture.

Assess includes the full intake, all three stacks, the architecture, the deployment plan and the report. No call required.

Build your security stack — three priced options from one profile · CyberTwin