StingPoint Security

StingPoint Programmatic Tiers

Programmatic cybersecurity offerings structured as continuous evaluation cycles to align threat validation with organization maturity.

Tier 1 · Entry

Ghost Recon

Zero-access required. Maps external boundary exposures exactly what an outside attacker already scans.

PASA
WASA
DIRA
EMTA
4 Assessments Included
Tier 2 · Core

Sentinel

Validates active security enforcement controls across perimeter targets, configurations, and core endpoints.

PASA
WASA
AVRA
SGCA
DIRA
EMTA
EESA
FNRA
8 Assessments Included
Most Popular
Tier 3 · Advanced

Vanguard

Full-program coverage — testing every primary digital interface, operational boundary, and human vector.

PASA
WASA
AVRA
SGCA
WARA
CIRA
PSRA
DIRA
EMTA
EESA
FNRA
PESA
IRRA
13 Assessments Included
Tier 4 · Ultimate

Operator Zero

Complete consulting deployment catalog. Comprehensive mapping across all vectors with zero blind spots.

PASA
WASA
AVRA
SGCA
WARA
CIRA
PSRA
AITA
DIRA
EMTA
EESA
FNRA
PESA
IRRA
14 Assessments · Full Spectrum

Specialty Add-On Packages

Skyfall

For cloud-native and containerized environments. Auditing IAM privilege creep, Kubernetes configuration drift, and cloud perimeter rules.

CIRACKSAAVRAFNRA

Codebreaker

Engineered for SaaS properties and application builders. Fuzzing service logic, exposed APIs, autonomous models, and dependency chains.

WARAAITAAVRASCRA

Social Vector

Human layer perimeter analysis auditing social susceptibility, phishing loops, and adjacent physical gaps.

PESAPSRAEMTADIRA

Audit Armor

Audit readiness generation. Compiling structural data packages for compliance reviews, framework mappings, and insurance renewals.

SGCAAVRAPASAEMTASCRA

Identity Strike

Full-spectrum identity attack path coverage from on-premises Active Directory through Entra ID — mapping every hop from standard user to Domain Admin to tenant takeover.

ADRAAAPRCIRAEMTA
CIRA Add-On

AAPR

Azure Adversarial Posture Review. Read-only Entra ID identity attack path analysis — service principals, managed identities, PIM gaps, kill chain mapping.

CIRAEntra IDAzureRM

Package Architecture Deep Dives

Ghost Recon Overview

Ghost Recon is StingPoint's entry-level engagement and the natural first step for any organization that has never had a formal security assessment. It requires nothing from the client beyond a list of corporate domains — no network access, no agent installation, no site visit. Every assessment in this package is passive or intelligence-driven, meaning it can be initiated immediately and delivers findings within days of kickoff.

Sentinel Overview

Sentinel expands Ghost Recon's external intelligence picture into a full internal controls validation. Where Ghost Recon answers what attackers already know, Sentinel answers whether the defenses you've built would actually stop them. This tier adds vulnerability scanning with business-contextualized risk scoring, firewall and network architecture review, endpoint EDR coverage validation, and a CIS v8 governance gap assessment.

Vanguard Overview

Vanguard is StingPoint's flagship package and the most comprehensive security program available short of the full fourteen-assessment catalog. It covers every major attack surface — external perimeter, wireless, dark web, email, endpoints, network, cloud, web applications, physical security, governance, human layer, and incident response — producing a complete, scored baseline across the entire security program.

Operator Zero Overview

Operator Zero is the full StingPoint assessment program — all fourteen engagements, every attack surface, zero exclusions. It includes everything in Vanguard plus the Artificial Intelligence Threat Assessment (AITA), making it the appropriate package for any organization that has deployed LLMs, AI agents, or machine learning systems in production environments where a compromise would carry business or regulatory consequences.

Recommended Programmatic Annual Cadence

QuarterEngagementFocus AreaStrategic Deliverable Output
Q1Ghost ReconRefresh external boundaries posture — domains, dark web, wireless, emailUpdated exposure baseline, credential rotation trigger list
Q2Skyfall or CodebreakerDeep-dive tracking on highest-risk domain (cloud environment or software file layer)Domain-specific security findings registry with prioritized mitigation roadmap
Q3Social Vector or Audit ArmorHuman layer performance review or framework compliance evidence alignment cyclePhishing baseline penetration update metrics or audit-ready evidence package assets
Q4Vanguard or Operator ZeroFull spectrum assessment sweep for end-of-year leadership performance auditsComplete risk posture profile report, board-ready executive dashboard summary, trend analysis

Commercial Package Specifications & Sell Sheets

Tier 1 — Entry Portfolio

Ghost Recon

Zero access required. Maps what attackers already see — in days, not weeks.

Starting At
$14,500
Based on scope details
Why This Package
  • No network access, no agent installs, no site visit required — engagement starts immediately.
  • Findings delivered within 72 hours of kickoff on the PASA and DIRA components.
  • Every engagement includes executive summary, risk-scored findings, and remediation roadmap.
  • DIRA consistently surfaces credential exposures clients didn't know existed.
Package Targets & Delivery

Ideal For: First-time security assessment. Cyber insurance application or renewal. Any organization that wants to understand their external exposure before committing to a full program.

Included Deliverables: Executive summary · External asset inventory · Dark web exposure report · Email security posture · Lookalike domain register · Remediation roadmap.

Tier 2 — Core Portfolio

Sentinel

Validates your controls — not just your documentation.

Starting At
$35,000
Based on scope details
Why This Package
  • Covers external exposure AND internal control validation in a single engagement.
  • SGCA produces the CIS v8 gap matrix that auditors and insurers are directly asking for.
  • EESA and FNRA validate that deployed tools are actually enforcing policy — not just installed.
Package Targets & Delivery

Ideal For: Organizations preparing for SOC 2, CMMC, or cyber insurance renewal. Companies that have deployed security tools and want to validate coverage.

Tier 3 — Advanced ★ Most Popular

Vanguard

Full-program coverage. Every major attack surface. One engagement.

Starting At
$66,500
Based on scope details
Tier 4 — Ultimate Portfolio

Operator Zero

The complete catalog. Every assessment. No blind spots.

Starting At
$74,500
Based on scope details

Specialty Add-On Sheets

Specialty — Cloud Focus

Skyfall

Validates IAM configurations, network boundary posture, and workload exposures.

Starting At
$18,500
Why This Package
  • Covers the three primary cloud breach vectors: over-privileged IAM permissions, firewall configurations, and unpatched workloads.
  • CIS Cloud Benchmark scoring delivers a defensible compliance posture baseline.
Scope Alignment

Ideal For: Cloud-native startups, SaaS firms, and migrated properties.

Included Deliverables: Cloud risk summary · IAM risk register · CIS benchmark scorecard · Network architecture findings · Patch risk register.

Specialty — Application & AI

Codebreaker

Tests web apps, APIs, and AI models for exploitable security vulnerabilities.

Starting At
$25,000
Why This Package
  • The only specialty package that wraps AI threat assessment checks into code review lines.
  • WARA tests beyond basic automated scripts: handling manual session manipulation and business logic abuse.
Scope Alignment

Ideal For: SaaS operations, development units, and software groups where the product interface represents the primary vector of systemic business risk.

Specialty — Human Layer

Social Vector

Evaluates the full human perimeter — phishing, physical boundaries, and underground intelligence leaks.

Starting At
$19,000
Why This Package
  • Ties all four human-layer vectors together inside a single coordinated assessment engagement.
  • PESA delivers structured statistical telemetry sorted granularly by company department and operational roles.
Specialty — Compliance Cycle

Audit Armor

Compiles the technical evidence packages and gap registers that auditors explicitly review.

Starting At
$18,500

INITIATE AN ASSESSMENT

Ready to see what an attacker sees before they move?

Validate your technical control posture and map your external exposure before an attacker does it for you.

Select Assessment Target

Select the package tier or specialty configuration you are interested in evaluating.

Organizational Profile

Help us map the regulatory and compliance parameters surrounding your workspace operations.

Threat Validation Objectives

Select the primary vector drivers forcing this evaluation initiative.