Getting or staying compliant with regulations can be difficult. Doing it in-house can be very costly, time-intensive, and require much greater effort for companies.
Various managed services and managed security services (MSP/MSSP) we can offer to help reduce internal effort, reduce risk, and increase compliance.
Get our CMMC Technology Bundle via our Shopify store.
Get our ISO27001 Technology Bundle via our Shopify store.
Get our SOC2 Technology Bundle via our Shopify store.
Pricing is per device/user/email, whichever applies based on the technology.
Access our Shopify store for our subcription products (excluding PenTest and vulnerability assessment as a service).
Please reach out for pricing, discounts can apply and are based on:
1. number of devices (starting at 51),
2. number of different services subscribed to (starting at 2),
3. number of years committing to (starting at 2). Fixed prices will be listed on this page.
These solutions can be in several forms:
Endpoint Security Bundle - A bundle package of multiple technologies to support your Windows or Macintosh machines to help secure them better from multiple viewpoints, such as misconfigurations, patching, antivirus, and the harmful aspects of user errors that lead to much greater risk to your company. Pricing is per endpoint. Custom bundle creation is also possible if you have specific needs—one pager on our Endpoint Security Bundle here.
Internet Security Bundle - An expansion of our Endpoint Security Bundle, this add-on bundle can be purchased separately or included in our other bundles. Several overlay technologies to help reduce the potential harmful effects on your company from users with unlimited Internet access or, even worse, from those who can access or execute programs from phishing emails. Pricing is per device/email.
Compliance Bundle - Arrakis offers numerous bundles to help your company get compliant with CMMC, ISO27001, GDPR/CCPA, SOC2, and other cybersecurity or privacy frameworks your company may be required to be compliant with. Pricing is per device/email.
Email Security Bundle - This bundle combines email security tools to help your company achieve better results against email-related threats. One-pager here.
Patching - All regulatory environments require devices to be patched and not end of life (EOL) or end of support (EOS). Arrakis can help your company stay in compliance by ensuring that the latest Operating System (OS) and third-party software patches are installed. This greatly reduces the risk of a bad actor injecting malicious code or exploiting vulnerabilities. As part of this, we can also perform hardware and software inventory to identify which hardware needs to be upgraded, keep track of your software licensing so you don't run afoul of the SPA, and run custom scripts to reduce the need to touch each computer in your environment. Pricing is based on the number of devices to be patched and the device count—one pager on patching here.
Gn0s!s Cybersecurity Awareness Training (CSAT) - Gnosis - Greek for "Knowledge". Provide reliable cybersecurity training that meets regulatory requirements. Lower cost than other platforms, automated training and phishing, ability to upload custom content, domain and company risk scoring, policy trust center, breach monitoring, and automated reporting. Time equals money; let's reduce the time you have to spend on CSAT. Start your free risk report here—one-pager on CSAT here.
Enterprise Anti-Virus - All regulatory environments require a solid antivirus and antimalware solution. Having a single pane of glass for visibility certainly helps, too. The Arrakis solution also supports risk profiling, misconfiguration detection, policy enforcement, and integration with our SOC solution mentioned below. Pricing is based on device count. As a bonus, you also have the option of adding in ransomware detection and EDR (both discussed below) for a slightly higher cost—one pager on Enterprise Anti-Virus here.
Security Operations Center (SOC) - Our 24x7x365 USA-based SOC team will help detect issues when you aren't looking. A majority of our other services also tie into the SOC, providing increased visibility across the board with less effort. Cloud environments and local on-prem hardware can also be monitored. This is a great solution for mobile hybrid or remote workforces. Pricing is based on device count. One-pager on SOC here.
URL Filtering - the new ISO27001:2022 specifically requires this; several other frameworks also either require or strongly suggest it. This service helps local or remote users avoid access to potentially hostile locations and provides security personnel with greater insight into the internet locations they visit. Pricing is based on device count.
Vulnerability Assessment - All companies should have a complete understanding of their vulnerabilities and the ability to track and demonstrate improvement. All frameworks require vulnerability assessments to be performed by an internal group, as well as at least an annual 3rd-party vulnerability assessment. Using industry-recognized tools, our professionals will capture and categorize your vulnerabilities for in-scope devices and IP addresses. All regulatory environments require this, and pricing is based on routable site locations. For example, if you have one site that can route to multiple other locations, it counts as one site. If you have more than one site, however, and they can't route to each other, then it counts as multiple sites. Pricing is $9,000 per site, per year, with unlimited IP addresses per site and manual review of the outcome to allow our security professionals to help determine risk to your company. Vulnerability Assessments are suggested to be no more than weekly but no less than monthly. One-pager on VulnaaS here.
Governance, Risk, and Compliance (GRC) - Arrakis has partnered with numerous GRC tool vendors to offer a highly customized GRC instance to support your company. Pricing varies by tool; however, it starts at $25K. Regardless of the tool you select (we'll give you multiple options), all tools will come with a high level of Arrakis support and configuration when coupled with our consultative services. We partner with numerous GRC vendors, including OneTrust (formerly known as Tugboat Logic), Vanta, Drata, Apptega, Secureframe, and RSA. Each offers numerous solutions with varying pros and cons based on your company's unique needs. One-pager on GRC here.
Anti-SPAM with Artificial Intelligence filtering - This solution filters emails BEFORE they reach the user and goes beyond the static prefilters offered in current email server solutions. We use this internally at Arrakis, and the increase in employee productivity was immediately noticed, as was the reduced risk. As the solution runs, it learns your environment and what is "good," and when fully activated, less and less SPAM reaches inboxes and intrudes on your employees' productivity. Pricing is per email address, and additional discounts are available when the Arrakis anti-SPAM package is purchased. This package includes numerous technologies, including anti-SPAM with AI—one pager on Anti-SPAM here.
Network and Cloud Security Assessments - Routine assessments of your local or cloud-based environments for possible detection of areas of improvement. This is a key factor in network and security architecture reviews and improvement. Pricing can vary: some services bill by the hour for a senior-level security and network consultant, while others charge a one-time fee of $10,200 per occurrence, based on the complexity of your network. However, if a significant amount of other services are subscribed to, then it isn't uncommon for Arrakis to offer this service at no charge. One-pager on Cloud Security Assessments here. One-pager on Network Security Assessments here.
Contract Management - We just introduced our new platform to help you manage your contracts, with a special emphasis on IT-based contracts. As is common with companies of all sizes, software or technology is purchased and then forgotten about or not implemented at all. We call that "shelfware". Then recurring payments start, and the company continues to pay for something that really isn't needed or used, or that duplicates another technology package in use. Even worse are contract stipulations that prevent cancellation without adequate notice to the vendor. All of this costs money. Our platform helps you visualize expenditures and provides notifications of contract renewals so you can cancel if needed. 12-month annual subscription: flat monthly fee of $166.66, unlimited contracts!!! One-pager on Contract Management here.
Penetration Testing - Taking our vulnerability assessment one step further, if you wish to make active attempts to penetrate your network, Arrakis personnel can demonstrate how a vulnerability can be exploited to gain access to the network and potentially sensitive information. Penetration testing can be performed externally (from a hacker's perspective) or internally (from an insider threat perspective), and it can demonstrate how easily data can be exfiltrated to an external destination. Pricing is $35,000 per year for up to 250 IP addresses. Arrakis suggests monthly penetration testing at a minimum, and no more than quarterly, to ensure compliance with regulatory environments. Read more about Penetration Testing here—one-pager on Penetration Testing as a Service here.
Security Information and Event Monitoring (SIEM) - Logging and monitoring are required in all regulatory frameworks, and a single pane of glass for this information provides a clearer picture of what is happening in your network. Arrakis can monitor hostile activity, illegal attempts to gain access, O365 environments, GitHub environments, etc., and help reduce time to respond to potential incidents and increase threat intelligence and insights into bad actor tactics. Pricing is per device, per month. One-pager on SIEM here.
Web Filtering - Our internet-based extension loads into your browser to act as a pre-filter before accessing possibly hostile websites. This extension, when combined with our Anti-SPAM with AI and URL filtering, really helps prevent successful phishing attacks! Pricing is per computer.
Data Loss Protection (DLP) is increasingly in demand among companies of all sizes. Our solution operates at the workstation level and doesn't depend on Azure or G Suite to function; it looks for suspicious activity on the end user's workstation. We'll track remote destinations and potential hostile activity by the device/user. Arrakis always recommends monitoring activity for 3-4 months before turning on blocking to uncover any unknown activity. DLP is also a new requirement for ISO27001:2022 and helps reduce the risk of a compromised device being used to exfiltrate data. Pricing is per device, per month—one pager on DLP here.
Privileged Access Management (PAM) reduces administrative privileges for both normal users and administrators while still allowing them to perform the functions they need with minimal interaction. Our solution allows certain functions to be approved, but then creates a rule that auto-approves future requests of the same type. This meets regulatory requirements and is priced per device, per month—one pager on PAM here.
Identity and Access Management (IAM) helps greatly with integrating different technologies within a corporate environment. Additionally, our solution enables faster permission reviews for user reviews, as required by all regulatory environments. Pricing varies and must be scoped.
Zero Trust VPN - This will greatly help your remote or hybrid workforce, as it inspects devices before allowing connections to ensure safety and policy compliance. There are numerous ways to connect the device to the secure network. This also helps your company move to the cloud faster and eliminates the need for physical servers. Pricing is per device, per month. One-pager on Zero Trust VPN here.
Multi-Factor Authentication - Add something more than just a password to your security strategy. Required in most regulatory environments, our solution will help you get more secure. Pricing is per user, per month.
Backup with Cloud Recovery - Back up your local and remote devices to a secure cloud location. If you have a compromised device, you can use the last-known-good configuration in a virtual machine while recovering the hardware. Versioning lets you recover a document you liked before everyone else changed it. Price is per device, per month. One-pager on cloud-based backup here.
Ransomware Detection - Help improve your chances of recovering from ransomware by detecting it sooner. Great tool to have, and it is an add-on to one of our other services. Price is per device, per month.
Secure Remote Access - Our solution meets all regulatory requirements for remote access and requires multifactor authentication. Perfect for IT folks who need to manage remote machines. Price is per device, per month—one pager on Secure Remote Access here.
Endpoint Detection and Response (EDR) - A supporting function of our antivirus and antimalware solution mentioned above. Helps a company respond faster and more effectively to potential incidents or malicious actors, and increases confidence in its security posture. Price is per device, per month—one pager on EDR here.
Computer Warehousing - Acting as a "warehouse manager", Arrakis will order and configure devices before sending them to the user. This also allows Arrakis to configure a "golden image" with security controls already in place to support the client, as well as to provide scheduling to the company to help ensure that devices are ordered and on hand, available when needed. This service also enables clients to anticipate budgets and order devices in advance. Price is per device, per month.
Contract Tracking and Visibility - Through our custom platform, you can upload your contracts and contract details to determine monthly/annual spending as well as increase visibility and reduce the potential of stale contracts—one-pager on Contract Tracking and Visibility here.
Vendor Due Diligence - Required in all regulatory environments, Arrakis will investigate and vet the security posture of your clients to help ensure those vendors are safe and that risks have been accounted for. Price is per vendor, per review occurrence, and requires a separate contract. One-pager on Vendor Due Diligence here. Want to try vendor due diligence on your own? Sign up for usage of our Prosikon platform.
User Permission Reviews - Required in all regulatory environments, Arrakis will review your users to help you understand their permissions within your environment. Price is per user, per review—one-pager on User Permission Reviews here.
Enterprise Password Management - Help prevent areas of your network, or accounts, or sensitive files, or anything else from getting passworded by a user only to have that user leave the company. Our solution can generate complex passwords and is stored on our isolated in-house system. Price is per user, per month—one pager on Enterprise Password Management here.
Ticketing System - While not required in all regulatory environments, proving you completed the remediation work is required, and our cloud-based ticketing system is a good option to meet your needs. Allows for reporting and custom dashboards to visualize work effort more easily, anticipate support funding needs, and understand trouble areas within your company. Price is per user, per month. One-pager on Ticketing here.
Arrakis has built over several months numerous platforms that can help reduce risk. Read more here and those platforms are listed below.
- Compliance Chatbot - a free chatbot relating to compliance, cybersecurity, and privacy.
- Prosikon - A feature rich vendor due diligence platform to help increase visibility and provide more information for safer decisions. Read more here.
- PolicyForge - Build out your policies based on the regulatory environment you care about. Policy and Procedure Templates are included as well as control mapping. Read more here.
- Fortuna Risk Compass - Feature rich risk assessment platform that helps you visualize risk and cost better. Numerous graphical displays and ability to export risks to Prothesis. Read more here.
- Prothesis PoAM Builder - Build your PoAMs to prove you are mitigating risk and demonstrating maturity. Expands on Fortuna risks and demonstrates the "why" on the need for PoAMs. Read more here.
- Mutina SecurePath - Construct your SSPs to meet CMMC, or other frameworks, to provide assurance to external parties. SSPs are required for CMMC compliance. Read more here.
- CyberPrep Test Engine - A subscription based practice test platform covering 50+ certifications. Designed to be more difficult than the actual test to increase certification chances.
Regardless of the platforms, Arrakis suggests contracting professional consultation when seeking certification or compliance.