Bienvenidos, San Antonio · 25% off all cybersecurity services, now through December 31, 2026. See what qualifies →

Services & Products

Security services built around your business.

Focused assessments, ongoing vulnerability management, compliance readiness, and AI security — scoped to what you actually run. Every engagement is delivered by the practitioner who scoped it.

Platform AgnosticFrom maximizing your current tech stack and deploying our proprietary tools, to implementing enterprise-grade solutions, we build a plan tailored to all your needs in any budget.

Plain languageReports your board and your insurer can read, and a queue your engineers can work.

Senior deliveryThe engineer who scopes your work is the one who delivers it. No handoff to a junior, no account manager in between. English or Español.

Category 01

Vulnerability Management

Our core practice, built on VM3 — our own published maturity model. For teams that scan but can’t prove risk is going down.

VM3 Maturity Assessment

We score your vulnerability-management program across five levels and five operational dimensions, then hand you a ranked roadmap to the next level.

Best forTeams with a scanner and no program

From $4,500

Book an assessment

VM Program Buildout

We stand up the whole loop: asset coverage, scan cadence, triage rules, SLAs, exception handling, and reporting that survives an audit.

Best for25–250 staff, post-assessment

From $9,500

Request a quote

Managed Vulnerability Management

First month free

We run the scan-to-fix loop on your existing tooling every cycle: triage, prioritized queue, remediation validation, and a VM3 re-score. We are not a SOC and this is not 24/7 monitoring — it is a program, run properly.

Best forOrganizations with no internal security staff

From $1,500/mo

First month free on 6 months

Compare plans

Category 02

Assessments & Testing

Where most engagements start. Find out what you’re actually exposed to, in language you can take to a board or an insurer.

Small Business Security Risk Assessment

A full picture of your security posture: cloud and identity configuration review, external exposure scan, interviews, and a prioritized remediation plan with a plain-language readout.

Best forFirst-time buyers, 10–200 staff, insurer or customer driven

From $3,500

Get a quote

Cloud Security Review

Configuration and identity review across Microsoft 365, Entra ID, AWS, or GCP: privileged access, conditional access, logging coverage, external sharing, and misconfiguration remediation.

Best forCloud-first teams that grew faster than their config review

From $4,500

Get a quote

Application Security Test

Hands-on testing of a web or mobile application: authenticated and unauthenticated testing, access-control and business-logic flaws, API surface, and a report you can hand to a customer. Mobile testing available as an add-on.

Best forSaaS and product teams facing a customer security review

From $6,500

Scope your test

We do not offer internal network penetration testing or red-team engagements. When an engagement needs them, we say so and refer you to a vetted partner rather than stretching to cover it.

Category 03

Compliance & Advisory

For when a customer, an auditor, or a prime contractor is asking questions you can’t answer yet.

SOC 2 Readiness

End-to-end Type I readiness: system description, Trust Services Criteria mapping, the full policy suite, evidence collection, vendor carve-outs, and auditor liaison. We take you to the audit, we don’t perform it.

Best forB2B SaaS with enterprise deals stalled on a report

From $12,000

Book a discovery call

CMMC / NIST 800-171 Gap Assessment

Scope your CUI boundary, assess against NIST SP 800-171, calculate your SPRS score, and leave with an SSP outline and a POA&M. Led by a CyberAB Registered Practitioner.

Best forDefense subcontractors under DFARS pressure

From $6,500

Check eligibility

PCI DSS Readiness Assessment

We scope your cardholder data environment, assess it against PCI DSS v4.0, and hand you a gap report, a prioritized remediation plan, and support completing your SAQ. Our founder has run three full PCI DSS audit cycles across 300+ controls, so you get someone who has been through it rather than someone reading the standard for the first time. We prepare you for your assessment. We are not a QSA, we do not perform certified assessments, and we do not issue an Attestation of Compliance.

Best forMerchants and service providers facing an acquirer deadline or an annual SAQ

From $6,500

Get a quote

vCISO / Fractional Security Leadership

First month free

Senior security ownership without a full-time hire: roadmap, policy upkeep, vendor reviews, customer questionnaires, and a quarterly summary your board can read.

Best for25–250 staff making security decisions with nobody qualified to make them

From $2,500/mo

First month free on 6 months

Compare plans

Also available — usually added to an engagement rather than bought alone

  • Policy & Documentation PackageThe policy suite an auditor or client questionnaire expects, mapped to your framework and written for your actual environment — not templates with your logo on top.From $2,500
  • Incident Response ReadinessThe plan, playbooks, roles and a tabletop that satisfy a control such as PCI DSS 12.10. Preparation and documentation.From $3,500
  • Security Awareness TrainingA live session built for your staff and your risks, with materials and a knowledge check you keep as evidence. Available in English or Spanish.From $1,500
Ask about add-ons

Category 04

AI Security & Enablement

Two different problems. Securing the AI you’ve already switched on, and finding where AI would actually pay for itself. We do both, because we build agentic tooling ourselves — with containment boundaries and audit logging — and then we secure it.

AI Security Readiness Review

You turned on Copilot, a chatbot, or an agent. We inventory where your data actually flows, review it against the OWASP LLM Top 10 and NIST AI RMF, check guardrails and audit logging, and tell you what to fix first.

Best forAnyone who adopted AI faster than they reviewed it

From $5,500

Book a review

AI Opportunity Map

A time inventory of what your team repeats, scored on impact, confidence, and ease, and returned as a ranked automation roadmap. You find out what to automate first — and what to leave alone.

Best forOps-heavy small businesses; the buyer here is usually the owner, not IT

Secure AI Automation Build

We build the workflow you picked from the map, with the security engineering baked in: explicit containment boundaries, human intervention points, least-privilege access, and append-only audit logging. Automation you can show an auditor.

Best forClients ready to build after an Opportunity Map

From $6,500

Custom quoted

Request a quote

Category 05

Packages & pricing

Fixed scope, fixed price, no surprises. Tiers differ by what’s actually in scope — users, systems, cadence, depth — not by features invented to justify a bigger number.

Security Assessment — the front door

Essential

$3,500

$2,625 during launch

  • Up to 25 users
  • 1 cloud tenant, no on-prem
  • Baseline config review
  • External exposure scan
  • Findings + prioritized plan
  • 60-minute readout
Get a quote

Professional

$6,500

$4,875 during launch

  • Up to 75 users
  • 2 platforms + code repo
  • Config deep-dive
  • Mapped to 1 named framework
  • Risk register
  • 90-minute executive readout
Get a quote

Advanced

$11,500

$8,625 during launch

  • Up to 200 users
  • Multi-tenant / hybrid
  • Config deep-dive + drift
  • App-layer testing, 1 web app
  • Vendor review, up to 5
  • Board-ready report + 30/60/90
Get a quote

Monthly plans — 6-month minimum

Managed VM — Essential

$1,500/mo

First month free

  • Up to 50 assets
  • Monthly scan cycle
  • Triage + prioritized queue
  • Monthly VM3 score
Talk to us

vCISO — Essential

$2,500/mo

First month free

  • About 8 hours per month
  • Monthly leadership session
  • Roadmap ownership
  • Policy upkeep
Talk to us

vCISO — Professional

$4,500/mo

First month free

  • About 16 hours per month
  • Bi-weekly cadence
  • Vendor reviews + questionnaires
  • Quarterly board summary
Talk to us

Advanced monthly tiers are available. Managed VM runs on your existing scanner — we don’t resell tooling. What moves a price: number of users, endpoints and locations; on-prem or hybrid; how many cloud platforms; testing depth; whether you need mapping to a named framework; reporting depth; regulated data such as CUI, PHI or cardholder data; and how fast you need it.

Launch offer

Bienvenidos to San Antonio.

Celebrate our San Antonio launch with 25% off eligible cybersecurity services. Qualified engagements may also receive complimentary add-on services based on scope and availability. We deliver engagements in English or Spanish, year-round.

What’s discounted

  • 25% off eligible one-time services — assessments, testing, packages
  • Monthly plans: first month free on a 6-month commitment, so your rate never rises later
  • New clients, first engagement

Add-ons you may qualify for

  • Policy template bundle
  • Basic external exposure scan
  • Follow-up consultation
  • Executive security briefing — Professional and above
  • Phishing-awareness session — Professional and above
  • 30-day remediation review — Professional and above
  • Security roadmap summary — Advanced and retainers

Add-ons are not automatic. They are subject to scope, eligibility, scheduling and availability, and we’ll tell you which apply before you sign. Eligible services and plans only; not combinable with other offers. Excludes third-party and pass-through costs such as audit fees, tooling and licences. Engagements must be signed by December 31, 2026. Invictus may decline or re-scope engagements that fall outside stated assumptions.

Questions

Frequently asked

Do you do network penetration testing or red-teaming?

No. We test applications — web, mobile and API. Internal network penetration testing and red-team engagements are a different discipline and we don’t staff them. If your engagement needs one, we’ll say so and refer you to a vetted partner. We’d rather lose the work than deliver it thinly.

Do you provide 24/7 monitoring or emergency incident response?

No. We are not a SOC and we don’t hold an incident response retainer. What we do is build and run vulnerability management programs, and prepare you for incidents — plans, playbooks and tabletop exercises that satisfy compliance controls like PCI DSS 12.10.

Do you resell security tools?

No, and we take no vendor commissions. We run programs on the tools you already own. If you genuinely need a tool you don’t have, we’ll tell you what to look for and leave the buying to you.

What if we have no security staff at all?

That’s our typical client. Most of our work is with organizations where security is somebody’s third job. We write for that reader, and we hand your engineers a queue rather than a PDF.

Remote or on-site?

Both. We’re based in San Antonio and work on-site across the metro. Everything we deliver is remote-capable, and we work with clients outside Texas.

¿Ofrecen servicios en español?

Sí. Podemos realizar la evaluación, la capacitación y los informes en español. No es parte de la promoción — es algo que siempre ofrecemos. / Yes. Assessments, training and reporting are available in Spanish year-round, not as a limited-time offer.

How fast can you start?

Usually within two days of a signed scope. We take on a limited number of engagements at a time deliberately — the person who scopes your work is the person who does it.

Are you insured? Will you sign an NDA?

Yes to both. We carry errors and omissions, professional liability and general liability coverage, and we sign NDAs before scoping conversations as a matter of course.

Not sure which one you need?

That’s normal, and it’s the conversation we’re best at. Tell us what’s driving the work — an auditor, an insurer, a customer questionnaire, or a feeling that something’s been missed — and we’ll tell you honestly what you need, including when it isn’t us.