UMBRA measures the distance between the capability you're paying for and the protection you're actually getting. Then puts a defensible dollar figure on closing it.

Flat-fee, vendor-independent security stack assessments. No commissions. No conflicts. Every dollar figure we produce is citable, defensible, and yours to act on — a report your CISO can act on and your CFO can understand.
Every tool resolves to the specific security functions it performs — 675 of them across 18 security axes — evaluated where each axis meets each of your environments.
Formula-priced, vendor-independent security stack assessments: tier base × your asset count × your tool count. Every dollar figure we produce is citable, defensible, and yours to act on.
Assets = managed endpoints + servers + cloud workloads (users, network devices, IoT, and ephemeral compute excluded). A tool is each distinct licensed product — bundled platforms count each product separately. Tier 1 engagements start at $12,750 (minimum size and stack). Above 25,000 assets — or for multi-entity, global, regulated, or OT environments — scoping is bespoke; see Enterprise and custom scoping below.
The published formula scales cleanly to 25,000 managed assets. Past that threshold, or into multi-entity, global, regulated, or OT/ICS estates, an engagement stops being a larger version of the same assessment and becomes a program, scoped to the estate rather than to a formula. Enterprise engagements begin at $200,000.
That calculator ceiling of $199,500 is the floor of the enterprise conversation, not its limit. Bespoke engagements carry no published upper bound; they are priced to the complexity of the estate, not the size of the invoice.
A company with 75,000 assets, 130 tools, four operating companies, three clouds, and OT is not a larger version of a $75,000 engagement. It is several interconnected assessments and a transformation program, and it is scoped as one.