Kestrel Founding client pricing

Vulnerability management, run for you

You bought the scanner. We run the program.

Kestrel operates full vulnerability management programs for mid-market companies — on the Rapid7 or Tenable platform you already own. Scanning, prioritization, remediation coordination, and executive reporting, handled by a named analyst. At a price we publish.

See the pricing Managed programs from $3,950/mo — less than half the cost of one in-house analyst.

The problem

The tool isn't the program.

Most mid-market companies own a capable vulnerability scanner. Very few have someone whose actual job is to run it — so the backlog grows, the auditors circle, and the one IT generalist who "owns security" drowns in CVE noise.

The backlog nobody owns

Thousands of findings, no prioritization, no owner. Critical vulnerabilities age for months because everything is urgent, so nothing is.

Scans without a rhythm

Coverage gaps, failed authentications, and stale asset inventories quietly rot scan data — and every decision built on it.

Nothing to show the board

Cyber insurance, auditors, and executives all ask the same question: is risk going down? A raw scan export is not an answer.

The service ladder

Start with a diagnosis. Stay for the program.

Every engagement starts with a fixed-price health check. If the findings make the case, most clients graduate into the managed program — but the health check stands on its own either way.

Step 1 · One-time

VM Health Check

$12,500 · 2–3 weeks

  • Scan coverage vs. real attack surface
  • Authenticated-scan success audit
  • Platform configuration & integration review
  • Risk-ranked findings with quick wins
  • 90-day remediation plan
  • Executive readout, in plain English

Fixed price. Yours to keep, whoever runs the plan.

Step 2 · Monthly program

Managed VM Program

from $3,950/mo · 12-month term

Up to 1,000 assets$3,950
1,001 – 2,500$5,450
2,501 – 5,000$7,450
5,000+Custom
  • Named analyst who knows your environment
  • Scan operations, tuning & asset hygiene
  • Risk-based prioritization with threat intel
  • Remediation coordination with your IT team
  • Exception & SLA workflow management
  • Monthly executive report + program metrics
  • Zero-day response on your actual exposure

Delivered on your Rapid7 or Tenable platform.

Step 3 · Add-ons

Extensions

Priced per scope

  • External attack surface watch (CTEM)
  • Patch orchestration with your tooling
  • Compliance reporting pack (PCI, HIPAA, SOC 2, CMMC)
  • Platform deployment or migration projects
  • Advisory hours for audits & board prep

Added to any managed program, when you're ready.

Yes, real prices on a services website. These are founding-client rates and final scope always gets a conversation — but you shouldn't need three discovery calls to learn what a program costs.

Why Kestrel

Built differently, on purpose.

Your platform, not ours

We run the Rapid7 or Tenable investment you already made. No rip-and-replace, no bundled MDR you didn't ask for.

A program, not a PDF

Metrics, SLAs, exception workflows, and remediation follow-through — not a scan export lobbed over the wall.

Published pricing

Every competitor makes you call sales to hear a number. Ours is on the page.

AI-native delivery

Reporting and triage automation means your dashboard reflects this week, not last quarter — and you don't pay for report-assembly hours.

A named analyst

Background-checked, insured, least-privilege access. One person who knows your network, backed by a bench.

The operating rhythm

What a month looks like.

Week 1

Scan & triage

Full-cycle scans, auth verification, new-asset onboarding, risk-ranked triage of everything found.

Week 2

Remediation push

Prioritized fix list to your IT owners with clear instructions, tickets filed in your system, blockers escalated.

Week 3

Verify & tune

Verification scans confirm what's actually fixed. False positives cleared, exceptions documented.

Week 4

Report & review

Executive report with trending metrics, SLA scorecard, and a working session on next month's priorities.

Always on: zero-day watch against your actual asset inventory, scanner health monitoring, and a human who answers when you call about the CVE in the headlines.

Who's behind this

Operator-led, enterprise-trained.

Kestrel was founded by a vulnerability management practitioner who spent years running VM programs inside a national cybersecurity consultancy — operating programs for Fortune 500 hospitality, banking, and financial-exchange clients across Rapid7 and Tenable estates of 100,000+ assets.

The playbook that ran those programs — the metrics framework, the SLA model, the remediation workflows — is the same one Kestrel runs for mid-market clients, at mid-market prices.

Delivery standards

  • Rapid7 & Tenable partner-program aligned delivery
  • Tech E&O and cyber liability insured
  • Background-checked analysts, least-privilege access
  • Documented runbooks & response SLAs
  • Metrics framework: executive, operational, threat & business tiers

Fair questions

Asked and answered.

Do we have to switch scanning tools?

No — that's the point. We operate your existing Rapid7 or Tenable deployment. If your licensing is a mess or you've outgrown your platform, we can fix that too, but it's never a condition of working together.

We don't have a scanner yet. Can you still help?

Yes. Through our vendor partnerships we'll license, deploy, and configure the right platform for your environment, then run it — one monthly price, no separate procurement saga.

Who actually applies the patches?

Your IT team executes changes in your environment — nobody wants an outsider pushing patches blind. We do everything around it: prioritize what matters, file the tickets, provide fix guidance, chase the blockers, and verify the result. If you want deeper automation, patch orchestration is an add-on.

What does access look like?

Least-privilege, logged, and boring: named accounts on your identity provider, MFA everywhere, scoped to the VM platform and ticketing integration. Analysts are background-checked and the firm carries technology E&O and cyber liability coverage.

What's the commitment?

Health checks are one-time and fixed-price. Managed programs run on 12-month terms, billed monthly. If we're not showing measurable risk reduction by the quarterly review, you should fire us — and the metrics will make it obvious either way.

Find out what your scanner has been trying to tell you.

Start with the $12,500 health check: two to three weeks, a risk-ranked view of your real exposure, and a 90-day plan — whether or not you ever hire us again. Tell us a little about your environment and we'll set up a scoping call.

No newsletter, no drip campaign. A human reads this and replies.