UMBRA
CapabilitiesMethodologyEngagementsClient Login
UMBRA
Detect sprawl · Surface gaps · Optimize spend

Find out what your security spend is actually buying.

UMBRA measures the distance between the capability you're paying for and the protection you're actually getting. Then puts a defensible dollar figure on closing it.

View Methodology
Flat-fee  ·  No environment access  ·  No vendor ties
UMBRA
What you own × how it's actually running = what's actually protecting you
What we do

Most assessments inventory your tools. UMBRA measures what they deliver.

Flat-fee, vendor-independent security stack assessments. No commissions. No conflicts. Every dollar figure we produce is citable, defensible, and yours to act on — a report your CISO can act on and your CFO can understand.

No environment access
UMBRA operates on documented stack information only. No integrations, no credentials, no agents.
No telemetry ingested
UMBRA stores the engagement inputs and assessment outputs needed to perform and deliver the work, but does not ingest credentials, device-level inventory, alerts, or live environment telemetry.
No vendor relationships
Parallax Advisory Group holds no vendor partnerships or referral arrangements. Analysis is independent.
Platform capabilities

What UMBRA analyzes.

01
Coverage Matrix
Maps your entire security stack against 18 security axes across all environment zones — endpoint, perimeter, identity, LAN, server, cloud, and SaaS. See exactly where you have coverage and where you don't.
02
Overlap Detection
Identifies where tools are billing you for capabilities already covered elsewhere in your stack. Redundancy is quantified in dollar terms with cost-weighted consolidation paths modeled for each scenario.
03
Posture Scoring
Converts your configuration and deployment state into measurable coverage scores. Separates what you own from what you're actually getting — the gap most organizations never quantify.
04
Optimization Scenarios
Models platform tier-down and tool removal paths with validated gap analysis at every step. Every savings projection shows exactly what coverage changes — no assumptions left unstated.
Engagement methodology

How it works.

Every tool resolves to the specific security functions it performs — 675 of them across 18 security axes — evaluated where each axis meets each of your environments.

I
Stack Intake
We document your current security tooling, license tiers, vendor contracts, and deployment state. Engagement-scoped only — no access to your environment required.
II
Coverage Analysis
UMBRA maps your stack against your environment profile. What's covered, where you're paying twice, and where you have genuine exposure — across all 18 security axes.
III
Optimization Modeling
Consolidation and optimization paths are modeled with explicit gap validation at every step. Every savings projection shows exactly what coverage changes.
IV
Findings Delivery
A structured report your CISO can act on and your CFO can understand — with defensible savings figures, risk-rated gaps, and prioritized recommendations.
Engagements

Flat fee. No hourly billing. No retainers.

Formula-priced, vendor-independent security stack assessments: tier base × your asset count × your tool count. Every dollar figure we produce is citable, defensible, and yours to act on.

TIER 01
Sprawl
Stack Audit
$25,000
BASE PRICE
What we do
Full inventory of licensed security tools
Capability mapping across 18 security axes
Redundancy and overlap identification
Total annual spend baseline
You walk away with
Coverage map
Every tool scored across all 18 security axes
Mapped to all 16 environment zones
The vendor-independent picture of what your stack covers
Redundancy map
Every capability covered by two or more tools
Quantified by overlapping ATT&CK technique
Exactly where you pay twice
Dollar figure
The annual cost of that overlap
Named consolidation candidates
A savings figure your CFO can act on
TIER 02
Gaps
Gap Analysis
$50,000
BASE PRICE
Everything in Sprawl, plus
Coverage gap analysis by security function
Environment-level gap mapping
Weighted gap scoring by function criticality
Prioritized remediation roadmap
You walk away with
Ranked findings
Every coverage gap ranked Critical to Low
Pinned to the exact capability and environment
Each with vendor-defensible evidence
Blind-spot map
Every function with no credible tool coverage
Mapped by environment and weighted by criticality
The exposure you can't see today
Exposure figure
One risk index, 0 to 100, for the whole estate
Scaled by asset count, weighted by environment criticality
The exposure that turns each gap into a conscious business decision
MOST COMPREHENSIVE
TIER 03
Optimization
Architecture Consulting
$75,000
BASE PRICE
Everything in Gaps, plus
Severity-weighted configuration assessment per tool
License utilization + population coverage analysis
Alert routing + IR workflow status per tool
Full realized value score per tool
License waste quantified to the dollar
You walk away with
Value scorecard
A realized value score for every tool, on availability, visibility, and operationalization
What each product delivers versus what you pay
The controls you own that aren't fully running
Optimization roadmap
Modeled consolidation and downgrade scenarios
The coverage impact of each option, validated
A recommended architecture roadmap
Dollar figure
License waste, to the dollar
Consolidation savings quantified
Cited, sourced, and board-ready
How pricing works

Three published numbers. Compute your own price.

TIER BASE × SIZE MULTIPLIER × STACK MULTIPLIER
Size is your managed asset count. Stack is your licensed tool count. No scoping calls required to know your number.
Size multiplier — managed assets
XSUp to 2500.60×
S251 – 5000.75×
M501 – 1,0000.90×
L1,001 – 2,5001.00×
XL2,501 – 5,0001.25×
2XL5,001 – 10,0001.55×
3XL10,001 – 25,0001.90×
Stack multiplier — licensed tools
LeanUp to 20 tools0.85×
Standard21 – 45 tools1.00×
Heavy46 – 80 tools1.20×
Bloated81+ tools1.40×
Worked example
800 assets · 35 tools · Gaps (T2)
$50,000 × 0.90 × 1.00 = $45,000

Assets = managed endpoints + servers + cloud workloads (users, network devices, IoT, and ephemeral compute excluded). A tool is each distinct licensed product — bundled platforms count each product separately. Tier 1 engagements start at $12,750 (minimum size and stack). Above 25,000 assets — or for multi-entity, global, regulated, or OT environments — scoping is bespoke; see Enterprise and custom scoping below.

Enterprise and custom scoping

Beyond the published formula.

The published formula scales cleanly to 25,000 managed assets. Past that threshold, or into multi-entity, global, regulated, or OT/ICS estates, an engagement stops being a larger version of the same assessment and becomes a program, scoped to the estate rather than to a formula. Enterprise engagements begin at $200,000.

That calculator ceiling of $199,500 is the floor of the enterprise conversation, not its limit. Bespoke engagements carry no published upper bound; they are priced to the complexity of the estate, not the size of the invoice.

Enterprise engagement classes
Enterprise AssessmentFull stack coverage and gap assessment across a large, segmented, or multi-site estate.$200K – $300K
Enterprise OptimizationAssessment plus per-tool value scoring, consolidation modeling, and architecture consulting at scale.$300K – $500K
Multi-Entity / Global TransformationSeveral interconnected assessments plus a sequenced transformation program across subsidiaries, regions, and clouds.$500K – $750K+
What triggers custom scoping
More than 25,000 managed assets
Multiple subsidiaries or separately operated business units
Several independent security stacks
Global or highly segmented environments
Significant OT / ICS infrastructure
M&A consolidation analysis
Board or regulatory deliverables
Multiple architecture workshops and stakeholder groups
Detailed implementation sequencing or transformation planning
More than one final executive or technical deliverable package

A company with 75,000 assets, 130 tools, four operating companies, three clouds, and OT is not a larger version of a $75,000 engagement. It is several interconnected assessments and a transformation program, and it is scoped as one.

Ready to see what your stack is actually worth?

All engagements begin with an NDA. We don't ask about your environment until you're protected.

No environment accessNo telemetry ingestedNo vendor relationships