Arrakis generates custom products and/or services that you can purchase online for a faster level of compliance or a template to help you understand more about what documentary references you need to help you become compliant more easily and less confusingly.
For managed services, Arrakis offers discounts based on device/user quantity (starting at 51), number of concurrent MSP/MSSP services subscribed to (starting at 2), and number of years committed (starting at 2).
Arrakis partners with several 3rd-party companies to provide a variety of hosting services.
- Email Hosting
- DNS Hosting
- Website Hosting
- Virtual Machine Hosting (please get in touch with us for scoping if you have unique requirements)
- Cloud hosting (please get in touch with us for scoping)
Read our one-pager on scalable Cloud Hosting.
We perform weekly vulnerability assessments against your environment to comply with regulatory environments that require at least monthly scans. Additionally, contractual requirements often force a company to conduct monthly scans. Unlimited IP addresses provided there is connectivity to all devices via a VPN or similar routed connection. Requires either a VM or a computer (old desktop/laptop is fine) to run our scanning software. Remediation of vulnerabilities is not included. Pricing is annually.
$9,000.00
Similar to VULNaaS, PENTESTaaS requires a computer with connectivity to your devices. Up to 250 devices can be pentested simultaneously. We'll pentest your environment monthly. This will allow your company to be regulatory-compliant with a pentest at least once a year. Our pricing is much lower than that of other companies; however, it meets regulatory and contractual requirements. For educational information relating to penetration testing, please click here. Pricing is annual; reduced pricing may be found in the store if specials are running—one pager on Penetration Testing as a Service here.
$36,000.00
Most companies are either fully in the cloud or in a hybrid situation. Regardless, if you are using Office 365 in a company environment with Microsoft Azure or Azure AD as the underlying technology, this solution is ideal for increasing visibility into your cloud environment. We'll review your cloud environment to assess your security posture and other settings and identify areas for improvement. One-pager on Cloud Assessments here.
$10,200.00
Arrakis has built over several months numerous platforms that can help reduce risk. Read more here and those platforms are listed below.
- Compliance Chatbot - a free chatbot relating to compliance, cybersecurity, and privacy.
- Prosikon - A feature rich vendor due diligence platform to help increase visibility and provide more information for safer decisions. Read more here.
- PolicyForge - Build out your policies based on the regulatory environment you care about. Policy and Procedure Templates are included as well as control mapping. Read more here.
- Fortuna Risk Compass - Feature rich risk assessment platform that helps you visualize risk and cost better. Numerous graphical displays and ability to export risks to Prothesis. Read more here.
- Prothesis PoAM Builder - Build your PoAMs to prove you are mitigating risk and demonstrating maturity. Expands on Fortuna risks and demonstrates the "why" on the need for PoAMs. Read more here.
- Mutina SecurePath - Construct your SSPs to meet CMMC, or other frameworks, to provide assurance to external parties. SSPs are required for CMMC compliance. Read more here.
- CyberPrep Test Engine - A subscription based practice test platform covering 50+ certifications. Designed to be more difficult than the actual test to increase certification chances.
Regardless of the platforms, Arrakis suggests contracting professional consultation when seeking certification or compliance.
Policies are the foundation of any regulatory environment and how companies are run. A lack of policies can lead to mismanagement and much more serious regulatory or contractual issues.
With years of experience and our staff being active, current auditors in numerous regulatory environments, Arrakis has a set of policies that have passed audits from the IRS, FFIEC, NIST 800.171/CMMC, GDPR, PCI, CCPA, ISO27001, SOC2, and others.
We'll adjust our policies to reflect your company name, logo, and other customizations that better align with your company. Examples of just some of the documents that will be provided are: overarching security charter, security policy, network security policy, environmental security policy, cybersecurity policy, information security policy, physical security policy, personnel security policy, as well as policies around personnel, encryption, acceptable use, access control, vendor management, and asset management. Additionally, where possible, we have some procedures that can be used generically, which will also be provided—a one-pager on Policies here.
For a low-cost subscription fee, policy upgrades are available to previous purchasers as their policies mature, to better align with other regulatory environments or future regulatory environments.