Cybersecurity pricing

Custom pricing with the cost logic made clear

Clear priorities. Practical protection. A partner accountable for the next step.

Outfaze does not publish a one-size-fits-all price because the operating commitment changes with your environment. We document the inputs, assumptions, responsibilities, and boundaries before providing a proposal.

01 / Ways to engage

Choose the operating model before the package.

The same security objective can require very different work depending on which tools and people are already in place. These models establish how delivery and ownership will work.

01

Assessment or project

Defined-scope work with an agreed start, finish, deliverables, assumptions, and acceptance criteria. Typical examples include vulnerability assessments, penetration tests, readiness reviews, architecture work, and incident-response planning.

Best for: A specific decision, risk question, or time-bound objective.

02

Managed service

Recurring operation of a defined capability with documented coverage, responsibilities, escalation paths, service reviews, and reporting. The recurring fee reflects the environment and operating commitment rather than a generic feature tier.

Best for: Continuous monitoring, administration, investigation, or control operation.

03

Co-managed program

Shared delivery that extends an internal team while preserving the tools, authority, and responsibilities it needs to retain. The scope identifies what Outfaze operates, what your team owns, and where decisions are shared.

Best for: Teams that have a security foundation but need added capacity or coverage.

04

MSP or MSSP partnership

Partner-led, co-branded, or white-label delivery across multiple customer environments. Pricing considers tenant count, service consistency, onboarding volume, support boundaries, reporting, and the commercial relationship.

Best for: Service providers expanding cybersecurity capability without building every function alone.

02 / Cost drivers

What changes the price?

A useful proposal should show which inputs materially affect cost. It should also make clear what would trigger a scope or fee change later.

Environment size

Users, endpoints, workloads, applications, locations, cloud accounts, and other assets included in scope.

Data and integrations

The number and type of telemetry sources, existing tools, API access, retention needs, and engineering required to establish reliable coverage.

Coverage and service levels

Operating hours, response expectations, escalation paths, review cadence, support needs, and any after-hours authority.

Risk and complexity

Internet exposure, regulated data, technology diversity, business-critical systems, legacy constraints, and the depth of validation required.

Responsibility split

Which activities Outfaze performs, which remain with your team, which require approval, and what falls outside the recurring service.

Onboarding and transition

Discovery, deployment, migration, tuning, documentation, training, and any work needed to reach a stable operating state.

03 / Example scopes

Compare the work that sits behind the quote.

These examples illustrate scope components, not fixed bundles or guaranteed inclusions. Final coverage depends on discovery and the written agreement.

Focused risk assessment

  • Written asset and testing scope
  • Access and safety prerequisites
  • Validated findings with risk context
  • Technical and executive reporting
  • Optional remediation retesting
Vulnerability assessment

Managed detection coverage

  • Agreed endpoint and connected telemetry
  • Coverage-health validation
  • Analyst-led triage and investigation
  • Documented escalation and response authority
  • Recurring operational review
Managed detection and response

Security operations partnership

  • Telemetry and workflow design
  • Detection and investigation processes
  • Case, escalation, and communication model
  • Service reporting and improvement backlog
  • Explicit customer and provider ownership
SOC as a Service

04 / Procurement

A clear path from question to scope.

  1. 01

    Share the objective

    Describe the business outcome, current environment, constraints, and timing. A finished technical scope is not required.

  2. 02

    Confirm discovery inputs

    Outfaze identifies the asset, telemetry, access, stakeholder, service-level, and responsibility details needed to price the work responsibly.

  3. 03

    Review scope and assumptions

    The proposed inclusions, exclusions, dependencies, deliverables, operating model, and change process are documented before commercial approval.

  4. 04

    Approve and onboard

    After agreement, both teams confirm contacts, access, milestones, validation checks, and the conditions for moving into ongoing delivery.

Get a useful estimate

Start with the environment, outcome, and responsibility split.

Outfaze will identify any missing scoping inputs and explain the assumptions behind the proposal. You do not need to know the final service design before the first conversation.

Discuss your scope