Annual Security Programmes in India & UAE.
Bundle your pentest, VAPT, code review, configuration audits and tabletop exercises into a single 12-month program with a quarterly cadence — at a 25–35% discount to one-off pricing. Audit-evidence-ready, board-reportable, regulator-defensible.
What is an annual security program?
An annual security program bundles recurring VAPT, audits, and advisory into one governed calendar so security and compliance stay continuous rather than a yearly scramble. Macksofy structures programs around your regulator's cadence — RBI, SEBI, CERT-In, ISO 27001 — with quarterly testing and a named point of contact.
Replace the panic cycle with a calendar.
Most security spend in regulated Indian firms is reactive — an engagement bought six weeks before an audit, then another one after an incident. The same money spent on a plan buys more assurance and less scrambling.
The same scope, bought once for the year. The discount is real because the scheduling, scoping and onboarding overhead only happens once.
Closure validation stops being a line item you hesitate over. Fix it, we re-test it, the register updates.
The gap where one-off engagements fail. Findings do not sit until someone remembers them at audit time.
The cadence is sequenced against your regulatory calendar, so the year-end pack is assembled rather than scrambled.
Four quarters, one scope, one price.
The split below is a template. Your CISO re-balances it during scoping against regulatory deadlines, the product roadmap and where the last cycle found weakness. The total scope is what gets contracted, not the exact mix.
- 25–35% lower spend vs. one-off engagement pricing across the same scope
- Single risk register across pentest + audit + code review + tabletop findings
- Regulator-defensible evidence package — no last-minute scramble before audit
- Continuous remediation chasing (we don't just hand over a PDF and disappear)
- Quarterly board / risk-committee deck produced for you
- ▸External + internal penetration test
- ▸Cloud configuration audit against CIS and the Macksofy hardening pack
- ▸Identity hygiene and privileged-access review
- ▸Web and API VAPT across the releases that shipped since Q1
- ▸Source code review on crown-jewel modules
- ▸Tabletop exercise — incident response and business continuity
- ▸Assumed-breach red team exercise
- ▸Mobile and thick-client testing
- ▸Vendor and third-party risk spot-checks
- ▸Re-test of remediated findings — closure validation
- ▸ISO 27001 and SOC 2 readiness sweep
- ▸Annual maturity assessment and next-year planning
The point of the cadence is that evidence exists before the auditor asks for it. Which of these bind you — and when — is the first thing scoping establishes.
One register instead of eleven PDFs.
The discount is the smaller half of the argument. The real return is that findings from five different assessment types land in one place, with one severity scale and one owner each.
- ▸Severity and ownership assigned once, not per-report
- ▸Duplicates across assessment types collapsed rather than double-counted
- ▸Remediation chased between quarters, not handed over and forgotten
- ▸Unlimited free retests inside the contract window
- ▸One trend chart for the board instead of a stack of PDFs
The alternative · the same scope bought as separate engagements produces eleven disconnected reports, three severity scales and nobody chasing anything between them.
Scoped once, governed continuously.
- ▸Regulatory calendar mapping (RBI · SEBI · CERT-In · ISO · SOC 2 · PCI-DSS)
- ▸Asset + product roadmap intake
- ▸12-month assessment cadence designed jointly with your CISO
- ▸Risk-register baseline established
- ▸Baseline external + internal pentest
- ▸Cloud configuration audit (CIS / Macksofy hardening pack)
- ▸Identity hygiene + privileged access review
- ▸Web + API VAPT across new releases
- ▸Source code review on crown-jewel modules
- ▸Tabletop exercise (incident response + business continuity)
- ▸Red team / assumed-breach exercise (assumed-breach scope)
- ▸Mobile + thick-client testing
- ▸Vendor / third-party risk spot-checks
- ▸Re-pentest of remediated findings (closure validation)
- ▸ISO 27001 / SOC 2 readiness sweep
- ▸Annual maturity assessment + next-year planning
- ▸Single risk register updated quarterly
- ▸Unlimited free retests within the contract window
- ▸Quarterly business review with security leadership
- ▸Year-end board pack + auditor evidence package
What a full year actually returned.
Scope · 12-month program: 4 pentests + 2 code reviews + 1 red team + 4 audits
Result · Consolidated savings of ₹68 L vs. one-off pricing; closed 91% of High/Critical findings inside the contract window
Material — passed IRDAI System Audit + ISO 27001 surveillance with zero major non-conformities
Scope · 12-month program for SEBI CSCRF + RBI master direction readiness
Result · Found 3 Critical issues in pre-prod that would have triggered SEBI CSCRF non-conformity; remediated before go-live
High — avoided regulatory delay of new investment platform launch
One designs the programme. This one executes it.
The annual programme is execution-heavy — we run the assessments. A vCISO is leadership-heavy — they sit in your governance forums, set policy and own the risk register the findings land in. Most regulated mid-market clients buy both, in that order.
Virtual CISO
Fractional CISO leadership — board reporting, regulator engagement, policy and incident command, one to four days a week.
See the vCISO serviceEvery discipline under one register.
The tooling spans the whole cadence — offensive, configuration, code and tabletop — because a programme that outsources half of it to a second vendor stops being one register very quickly.
One contract. Twelve months of assurance.
Annual program pricing runs ₹40 L–₹2.5 Cr per year depending on asset count, product portfolio and regulatory footprint — at a 25–35% discount vs. one-off engagement pricing. Quote within 5 working days of scoping.
What the program covers
- 12-month assessment roadmap aligned to your regulatory calendar
- Quarterly execution: pentest · VAPT · code review · audit · tabletop
- Single consolidated risk register (Macksofy platform)
- Quarterly business review + board-ready trend chart
- Unlimited free retests within the contract window
- Year-end auditor evidence package (CERT-In · RBI · SEBI · ISO · SOC 2)
- Annual maturity assessment (NIST CSF + ISO 27001 alignment)
Sectors we operate in
Empanelled by CERT-In. Accredited by EC-Council.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
What finance asks before signing for a year.
Where Macksofy delivers Annual Program.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
