Skip to content
Macksofy Technologies
Continuous Assurance · Quarterly Cadence · Single Retainer

Annual Security Programmes in India & UAE.

Bundle your pentest, VAPT, code review, configuration audits and tabletop exercises into a single 12-month program with a quarterly cadence — at a 25–35% discount to one-off pricing. Audit-evidence-ready, board-reportable, regulator-defensible.

25–35%
below one-off pricing
Quarterly
execution cadence
One
consolidated register
Unlimited
retests in-window
In short

What is an annual security program?

An annual security program bundles recurring VAPT, audits, and advisory into one governed calendar so security and compliance stay continuous rather than a yearly scramble. Macksofy structures programs around your regulator's cadence — RBI, SEBI, CERT-In, ISO 27001 — with quarterly testing and a named point of contact.

The case for one contract

Replace the panic cycle with a calendar.

Most security spend in regulated Indian firms is reactive — an engagement bought six weeks before an audit, then another one after an incident. The same money spent on a plan buys more assurance and less scrambling.

25–35% below one-off pricing

The same scope, bought once for the year. The discount is real because the scheduling, scoping and onboarding overhead only happens once.

Unlimited retests in-window

Closure validation stops being a line item you hesitate over. Fix it, we re-test it, the register updates.

Remediation chased between quarters

The gap where one-off engagements fail. Findings do not sit until someone remembers them at audit time.

Evidence before the auditor asks

The cadence is sequenced against your regulatory calendar, so the year-end pack is assembled rather than scrambled.

The year

Four quarters, one scope, one price.

The split below is a template. Your CISO re-balances it during scoping against regulatory deadlines, the product roadmap and where the last cycle found weakness. The total scope is what gets contracted, not the exact mix.

  • 25–35% lower spend vs. one-off engagement pricing across the same scope
  • Single risk register across pentest + audit + code review + tabletop findings
  • Regulator-defensible evidence package — no last-minute scramble before audit
  • Continuous remediation chasing (we don't just hand over a PDF and disappear)
  • Quarterly board / risk-committee deck produced for you
Twelve-month cadence · template, then re-balanced with your CISO
Sequenced around your deadlines
Q1Establish the baseline
  • External + internal penetration test
  • Cloud configuration audit against CIS and the Macksofy hardening pack
  • Identity hygiene and privileged-access review
Q2Go after the build
  • Web and API VAPT across the releases that shipped since Q1
  • Source code review on crown-jewel modules
  • Tabletop exercise — incident response and business continuity
Q3Test the assumptions
  • Assumed-breach red team exercise
  • Mobile and thick-client testing
  • Vendor and third-party risk spot-checks
Q4Close and evidence
  • Re-test of remediated findings — closure validation
  • ISO 27001 and SOC 2 readiness sweep
  • Annual maturity assessment and next-year planning
Mapped against the calendar that actually sets the dates
RBI System AuditSEBI CSCRFCERT-In annual VAPTISO 27001 surveillanceSOC 2 Type II windowPCI-DSS assessment

The point of the cadence is that evidence exists before the auditor asks for it. Which of these bind you — and when — is the first thing scoping establishes.

Why it compounds

One register instead of eleven PDFs.

The discount is the smaller half of the argument. The real return is that findings from five different assessment types land in one place, with one severity scale and one owner each.

Findings flow · five assessment types, one register
Pentest & red team
Configuration audits
Source code review
Web & API VAPT
Tabletop exercises
One risk register
  • Severity and ownership assigned once, not per-report
  • Duplicates across assessment types collapsed rather than double-counted
  • Remediation chased between quarters, not handed over and forgotten
  • Unlimited free retests inside the contract window
  • One trend chart for the board instead of a stack of PDFs

The alternative · the same scope bought as separate engagements produces eleven disconnected reports, three severity scales and nobody chasing anything between them.

How the year runs

Scoped once, governed continuously.

Stage 1
Annual scoping & roadmap
  • Regulatory calendar mapping (RBI · SEBI · CERT-In · ISO · SOC 2 · PCI-DSS)
  • Asset + product roadmap intake
  • 12-month assessment cadence designed jointly with your CISO
  • Risk-register baseline established
Stage 2
Quarter 1 execution
  • Baseline external + internal pentest
  • Cloud configuration audit (CIS / Macksofy hardening pack)
  • Identity hygiene + privileged access review
Stage 3
Quarter 2 execution
  • Web + API VAPT across new releases
  • Source code review on crown-jewel modules
  • Tabletop exercise (incident response + business continuity)
Stage 4
Quarter 3 execution
  • Red team / assumed-breach exercise (assumed-breach scope)
  • Mobile + thick-client testing
  • Vendor / third-party risk spot-checks
Stage 5
Quarter 4 execution
  • Re-pentest of remediated findings (closure validation)
  • ISO 27001 / SOC 2 readiness sweep
  • Annual maturity assessment + next-year planning
Stage 6
Continuous governance
  • Single risk register updated quarterly
  • Unlimited free retests within the contract window
  • Quarterly business review with security leadership
  • Year-end board pack + auditor evidence package
Programme snapshots

What a full year actually returned.

Listed Insurance MNC (Mumbai BKC)

Scope · 12-month program: 4 pentests + 2 code reviews + 1 red team + 4 audits

Result · Consolidated savings of ₹68 L vs. one-off pricing; closed 91% of High/Critical findings inside the contract window

Material — passed IRDAI System Audit + ISO 27001 surveillance with zero major non-conformities

Risk severity · High
LMHC
Regulated Fintech (Bengaluru)

Scope · 12-month program for SEBI CSCRF + RBI master direction readiness

Result · Found 3 Critical issues in pre-prod that would have triggered SEBI CSCRF non-conformity; remediated before go-live

High — avoided regulatory delay of new investment platform launch

Risk severity · Critical
LMHC
Often bought together

One designs the programme. This one executes it.

The annual programme is execution-heavy — we run the assessments. A vCISO is leadership-heavy — they sit in your governance forums, set policy and own the risk register the findings land in. Most regulated mid-market clients buy both, in that order.

Virtual CISO

Fractional CISO leadership — board reporting, regulator engagement, policy and incident command, one to four days a week.

See the vCISO service
Delivery stack

Every discipline under one register.

The tooling spans the whole cadence — offensive, configuration, code and tabletop — because a programme that outsources half of it to a second vendor stops being one register very quickly.

Tools we operate
Macksofy proprietary risk-register platformTenable / Qualys / Rapid7 InsightVM (configuration audits)Burp Suite Pro · Nuclei · Custom tooling (pentest cadence)Semgrep · CodeQL · Snyk (code review cadence)TheHive + Cortex (tabletop exercise infrastructure)
12-month programme — bespoke scope

One contract. Twelve months of assurance.

Annual program pricing runs ₹40 L–₹2.5 Cr per year depending on asset count, product portfolio and regulatory footprint — at a 25–35% discount vs. one-off engagement pricing. Quote within 5 working days of scoping.

What's included

What the program covers

  • 12-month assessment roadmap aligned to your regulatory calendar
  • Quarterly execution: pentest · VAPT · code review · audit · tabletop
  • Single consolidated risk register (Macksofy platform)
  • Quarterly business review + board-ready trend chart
  • Unlimited free retests within the contract window
  • Year-end auditor evidence package (CERT-In · RBI · SEBI · ISO · SOC 2)
  • Annual maturity assessment (NIST CSF + ISO 27001 alignment)
Industries

Sectors we operate in

Banking & Financial ServicesFintech & PaymentsInsurance & InsurTechHealthcare & HealthTechGovernment & PSUSaaS & Product CompaniesManufacturing & Energy
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

What finance asks before signing for a year.

Yes — the cadence above is a template. We sit with your CISO during scoping and re-balance based on your regulatory deadlines, product roadmap and where past assessments found weaknesses. The total scope, not the exact split, is what's contracted.
Scope adjustments are handled via change-orders at the discounted retainer rate, not at one-off pricing. The annual program is designed to flex.
No — it's outcomes-based. The deliverables list above is contractually committed. Hours are tracked for transparency but the contract is for the assessments + deliverables, not a bucket of consulting time.
The annual program is execution-heavy (we run the assessments). The vCISO is leadership-heavy (we sit in your governance forums, set policy, advise on architecture). Most regulated mid-market clients buy both — the vCISO designs the program, this contract executes it.
Ranges from ₹40 L to ₹2.5 Cr depending on asset count, product portfolio and regulatory footprint. Fixed price for the year, billed quarterly. Quote within 5 working days of scoping.
Delivery footprint

Where Macksofy delivers Annual Program.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements