Vulnerability management, run for you
Kestrel operates full vulnerability management programs for mid-market companies — on the Rapid7 or Tenable platform you already own. Scanning, prioritization, remediation coordination, and executive reporting, handled by a named analyst. At a price we publish.
The problem
Most mid-market companies own a capable vulnerability scanner. Very few have someone whose actual job is to run it — so the backlog grows, the auditors circle, and the one IT generalist who "owns security" drowns in CVE noise.
Thousands of findings, no prioritization, no owner. Critical vulnerabilities age for months because everything is urgent, so nothing is.
Coverage gaps, failed authentications, and stale asset inventories quietly rot scan data — and every decision built on it.
Cyber insurance, auditors, and executives all ask the same question: is risk going down? A raw scan export is not an answer.
The service ladder
Every engagement starts with a fixed-price health check. If the findings make the case, most clients graduate into the managed program — but the health check stands on its own either way.
Step 1 · One-time
$12,500 · 2–3 weeks
Fixed price. Yours to keep, whoever runs the plan.
Step 2 · Monthly program
from $3,950/mo · 12-month term
| Up to 1,000 assets | $3,950 |
| 1,001 – 2,500 | $5,450 |
| 2,501 – 5,000 | $7,450 |
| 5,000+ | Custom |
Delivered on your Rapid7 or Tenable platform.
Step 3 · Add-ons
Priced per scope
Added to any managed program, when you're ready.
Yes, real prices on a services website. These are founding-client rates and final scope always gets a conversation — but you shouldn't need three discovery calls to learn what a program costs.
Why Kestrel
We run the Rapid7 or Tenable investment you already made. No rip-and-replace, no bundled MDR you didn't ask for.
Metrics, SLAs, exception workflows, and remediation follow-through — not a scan export lobbed over the wall.
Every competitor makes you call sales to hear a number. Ours is on the page.
Reporting and triage automation means your dashboard reflects this week, not last quarter — and you don't pay for report-assembly hours.
Background-checked, insured, least-privilege access. One person who knows your network, backed by a bench.
The operating rhythm
Full-cycle scans, auth verification, new-asset onboarding, risk-ranked triage of everything found.
Prioritized fix list to your IT owners with clear instructions, tickets filed in your system, blockers escalated.
Verification scans confirm what's actually fixed. False positives cleared, exceptions documented.
Executive report with trending metrics, SLA scorecard, and a working session on next month's priorities.
Always on: zero-day watch against your actual asset inventory, scanner health monitoring, and a human who answers when you call about the CVE in the headlines.
Who's behind this
Kestrel was founded by a vulnerability management practitioner who spent years running VM programs inside a national cybersecurity consultancy — operating programs for Fortune 500 hospitality, banking, and financial-exchange clients across Rapid7 and Tenable estates of 100,000+ assets.
The playbook that ran those programs — the metrics framework, the SLA model, the remediation workflows — is the same one Kestrel runs for mid-market clients, at mid-market prices.
Fair questions
No — that's the point. We operate your existing Rapid7 or Tenable deployment. If your licensing is a mess or you've outgrown your platform, we can fix that too, but it's never a condition of working together.
Yes. Through our vendor partnerships we'll license, deploy, and configure the right platform for your environment, then run it — one monthly price, no separate procurement saga.
Your IT team executes changes in your environment — nobody wants an outsider pushing patches blind. We do everything around it: prioritize what matters, file the tickets, provide fix guidance, chase the blockers, and verify the result. If you want deeper automation, patch orchestration is an add-on.
Least-privilege, logged, and boring: named accounts on your identity provider, MFA everywhere, scoped to the VM platform and ticketing integration. Analysts are background-checked and the firm carries technology E&O and cyber liability coverage.
Health checks are one-time and fixed-price. Managed programs run on 12-month terms, billed monthly. If we're not showing measurable risk reduction by the quarterly review, you should fire us — and the metrics will make it obvious either way.
Start with the $12,500 health check: two to three weeks, a risk-ranked view of your real exposure, and a 90-day plan — whether or not you ever hire us again. Tell us a little about your environment and we'll set up a scoping call.