Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A one-time security assessment can be the starting point for recurring work when it leads to a defined plan: prioritize findings with the client, agree on follow-up services and responsibilities, then refresh the evidence on a schedule. It does not guarantee a retainer or a particular revenue outcome. The goal is to offer useful, scoped risk management—not to sell monitoring that the client does not need.

Start by turning findings into owned actions

Close out the assessment with a discussion that moves from observations to decisions. Confirm whether each finding still applies, establish its business context, and agree on priority, an owner, and a next step. A report without an agreed action plan is a weak basis for ongoing work: the client may not know what to address, and you have no clear way to show what changed.

  • Validate context: Check the affected asset, account, control, or process with the client before treating the finding as current.
  • Prioritize: Discuss risk and operational constraints with the client rather than presenting every issue as equally urgent.
  • Assign ownership: Record who is responsible for the action, what completion means, and when progress will be reviewed.
  • Separate advice from delivery: Make clear which recommendations you can implement, which you can independently verify, and which require the client or another provider.

This closeout can naturally lead to a scoped remediation engagement or an ongoing service, but those should be separate choices with explicit deliverables.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a recurring service around the client’s needs

Continuous monitoring and periodic assessment are program activities, not a standard commercial package. NIST’s SP 800-137A (May 2020) describes evaluating an information security continuous monitoring program through its strategies, policies, procedures, operations, and analysis of monitoring data. It provides an assessment approach and example criteria; it does not prescribe a consulting offer.

Remediation support

Offer implementation help or a remediation review when it fits your competence and the client’s needs. Define the systems and changes in scope, the client approvals required, how changes will be tested, and the evidence needed to accept the work. If you performed the original assessment, explain how you will preserve the distinction between implementing a control and independently evaluating it.

Recurring vulnerability and exposure monitoring

A monitoring service might track agreed internet-facing assets, scan them on a stated cadence, triage results, and issue reports or urgent alerts under defined criteria. CISA’s Cyber Hygiene service description offers a public example of continuing activity: monitoring internet-accessible assets, sending weekly vulnerability reports and urgent alerts, and scanning public web applications. CISA describes its own free government service; it is an example of possible deliverables, not commercial pricing or an endorsement of a private provider.

Be specific about the boundary between automated findings and human investigation. State what is scanned, how often, which alert severities trigger escalation, and whether your team merely reports issues or also helps remediate them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Asset, configuration, and control oversight

Where the client needs continuing visibility, scope a recurring inventory or review of agreed assets, configurations, identities, or security controls. The work should specify which sources are authoritative, how changes are reconciled, what exceptions are reported, and who resolves them. In an October 2019 project description, NIST identified asset management, risk assessment, identity management and access control, data security, and continuous monitoring as functions in an example MSP cybersecurity solution. The description also notes that compromise of an MSP can raise risk for the small and midsize businesses it supports; it is not a claim that every SMB needs an MSP or that any particular service meets those functions.

Periodic risk and control review

Schedule reviews to revisit material risks, changed systems, control performance, and unresolved actions. The cadence should follow the client’s operating context and the agreement, rather than an assumed universal interval. A periodic review can update the risk picture even when the client does not need continuous scanning or managed operations.

Referral or managed-service option

If you lack the staff, tools, or coverage to deliver a requested service, a qualified specialist may be a better fit than an improvised offer. Evaluate the provider’s capability, operational fit, and protection of the client’s systems and information. NIST’s older SP 800-35 (October 2003) lists service arrangement, provider qualifications and capability, operational requirements, provider viability, staff trustworthiness, and protective capacity as selection considerations. Treat these as durable questions, not as a current market standard.

Make the service boundary explicit

A recurring fee is only useful to both parties when the work and responsibility are clear. CISA’s customer guidance for managed service providers advises documenting service levels and distinguishing IT operations from security services; it also discusses incident roles, remediation acceptance, customer-data separation, and log and record handling. Use the agreement and operating procedures to answer the following:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Coverage: Which assets, accounts, locations, applications, and environments are included? How are additions and removals handled?
  • Cadence and service hours: When do scans, reviews, reports, and alert triage occur? What are the staffed hours and escalation commitments?
  • Severity and response: How are findings classified, who receives alerts, and what response is promised for each class? Avoid implying 24/7 monitoring unless it is actually staffed and contracted.
  • Roles and dependencies: Who grants access, approves changes, investigates incidents, communicates with affected parties, and makes risk-acceptance decisions?
  • Remediation and acceptance: Is remediation included or separately authorized? Define completion evidence, testing, and how exceptions are accepted.
  • Exclusions and extra work: Name excluded systems and activities, and identify events—such as new assets, incident response, or major remediation—that require a change order or separate scope.
  • Data and records: Specify access, retention, retrieval, client separation, and handling of logs and reports, including at termination or transition.
  • Exit and continuity: Define how access is revoked, records are transferred or retained, and responsibilities move to the client or another provider.

CISA’s detailed guidance is available in Risk Considerations for Managed Service Provider Customers. It is written for MSP customers, but its emphasis on clear responsibilities and service boundaries is relevant when shaping an ongoing security engagement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Refresh evidence instead of recycling the old report

A prior assessment is a useful baseline, not proof that the client remains in the same security state. Systems, accounts, configurations, threats, and control performance can change. A recurring engagement should identify what evidence is collected again, what changes trigger an out-of-cycle review, and when a fresh assessment is appropriate.

CMS policy provides an agency-specific caution: its Risk Management Handbook, Chapter 4 says reusing prior assessment documents can save time and resources, but may weaken test write-ups and the accuracy of risk identification. That is CMS policy context, not a universal assessment interval or rule. In practice, reuse prior material as context, and verify current conditions before relying on it.

Package and price only after defining the scope

There is no universal price, conversion rate, or standard recurring package established by the cited guidance. Build an offer around the actual assets, cadence, analysis, response hours, remediation responsibilities, reporting, and service levels the client requires. Then check that the delivery effort, tooling, staffing, and risk are sustainable for your business. A narrow reporting service and a staffed response service are not interchangeable simply because both recur monthly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A provider can present a small number of clearly bounded options—for example, a periodic review, scheduled monitoring with reports, or monitoring plus defined remediation support—if each option states its coverage and exclusions. Validate the commercial terms against delivery cost and client fit rather than using an unsupported market benchmark. A practitioner’s Reddit question, “How much do you charge to just run a one-off NIST-CSF risk assessment?”, illustrates one way buyers may phrase a pricing question; a single post is anecdotal and cannot establish typical demand or rates.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.