The Pricing Tiers
Three stages, priced by scope: a one-time Posture Assessment (₹90,000–₹2,80,000) benchmarks your environment against CIS Controls and DPDP requirements. A Remediation & Hardening Sprint (₹3,50,000–₹12,00,000) fixes what the assessment finds — exposed storage, over-permissioned IAM roles, unencrypted data, open network rules. Continuous CSPM + Managed Monitoring (₹75,000–₹4,50,000/month) keeps it that way with ongoing drift detection and quarterly compliance reporting. Multi-cloud or regulated-industry programs (healthcare, fintech) run ₹4,00,000–₹9,50,000+/month.
Why the Risk Is Bigger Than It Looks
15% of breaches start with a misconfiguration — the 3rd most common initial attack vector (IBM). 65% of cloud security issues trace to user error, not attacker sophistication (Palo Alto Networks). Gartner projected that through 2025, 99% of cloud security failures would be the customer's fault, not the cloud provider's — a reminder that AWS, Azure and GCP secure the infrastructure, but everything configured on top is on you.
What Actually Drives the Cost Up or Down
Three variables move the price within each tier: how many cloud accounts and services are in scope, whether the environment is single-cloud or multi-cloud, and whether a named compliance framework (DPDP, SOC 2, ISO 27001, healthcare-specific rules) needs to be mapped against findings rather than a generic best-practices pass. A single-account startup sits at the low end of every tier; a multi-cloud, regulated-data business sits at the top for genuine scope reasons, not markup.
How to Decide If You Need This Now
Score two or more "yes" answers below and a one-time assessment is overdue: (1) You process regulated or sensitive data at meaningful volume. (2) You run on more than one cloud provider, or plan to within a year. (3) A client, investor or auditor has already asked about your cloud security monitoring. (4) Nobody owns cloud security as an explicit responsibility. (5) Your infrastructure has grown meaningfully since it was last reviewed. A regulated-data, multi-cloud business should plan straight for continuous monitoring, not just the assessment.