Skip to main content
Cost comparison · Published prices only

Six licences, six renewals, and about four times the price.

Assembling comparable coverage from the point tools that publish a price costs US$100,778 a year at the conservative floor, against a ShadowMap entry licence published at from US$25,000. At the transaction medians buyers actually paid, the same stack is US$214,296.

Every figure below is a vendor’s own published list price or a Vendr transaction median, with its source printed on the row. Add the column up yourself.

Assembled stack, conservative floor

US$100,778

Six products, every one priced at the lowest figure we can source.

ShadowMap, published entry licence

from US$25,000

One licence, one renewal. A floor, not a fixed price: larger estates quote above it.

The difference, at the floor

4.0×

The conservative figure: it assumes every vendor discounts to their floor at once.

At transaction medians, which record what buyers on Vendr actually paid rather than what vendors advertise, the same stack is US$214,296, or 8.6×. Nobody negotiates six contracts to the floor simultaneously, so the real figure for most buyers sits between the two, and both are above four times the published ShadowMap floor.

The stack

Six products, priced one row at a time

One row per capability, each priced against a vendor that publishes something we can point at. The note under every row says where its two figures came from and how large the sample was. A published list price and a transaction median are not the same kind of number.

Annual cost of assembling comparable coverage from vendors that publish a price
CapabilityVendor pricedConservative floorTransaction median
External attack surface Intruder US$3,588 US$3,588
Published list, from US$299/mo. Known gap: no reliable enterprise-grade external-attack-surface median exists in our research, so this row prices an SMB-tier tool and the same published figure carries into both columns. It understates what an enterprise would pay, so the floor below is conservative.
Ratings + third-party risk UpGuard US$21,000 US$34,874
Published list (Standard, 50 vendor slots); median from 69 Vendr purchases. The only vendor here publishing a hard annual list price, not a “from” rate. A buyer can open the vendor’s own pricing page and check it.
Brand protection + takedowns ZeroFox US$19,790 US$45,604
Vendr, 38 purchases. Priority takedowns and legal are add-ons at 20-40% of annual.. The add-ons named here are not in either column. They would push both totals up.
Identity / stealer-log exposure SpyCloud US$10,800 US$41,342
Vendr; reported minimum US$15,000-25,000. The floor is the lowest observed transaction, which sits below the vendor’s own reported minimum; we have carried the lower figure.
Threat intelligence Recorded Future US$27,000 US$70,288
Vendr, 46 purchases, February 2026. The widest gap between floor and median of any row here.
Adversarial validation Horizon3 NodeZero US$18,600 US$18,600
Vendr median; secondary source. A single median with no separately published floor, so the same figure carries into both columns and this row does not move between them.
Assembled stack, annual Six licences, six renewals US$100,778 US$214,296
The sum of the rows above and nothing else. One-off implementation, priority takedown and legal add-ons are all outside these totals; the methodology below says what that omission is worth.

Annual cost of assembling comparable coverage from vendors that publish a price

External attack surface

Vendor priced
Intruder
Conservative floor
US$3,588
Transaction median
US$3,588

Published list, from US$299/mo. Known gap: no reliable enterprise-grade external-attack-surface median exists in our research, so this row prices an SMB-tier tool and the same published figure carries into both columns. It understates what an enterprise would pay, so the floor below is conservative.

Ratings + third-party risk

Vendor priced
UpGuard
Conservative floor
US$21,000
Transaction median
US$34,874

Published list (Standard, 50 vendor slots); median from 69 Vendr purchases. The only vendor here publishing a hard annual list price, not a “from” rate. A buyer can open the vendor’s own pricing page and check it.

Brand protection + takedowns

Vendor priced
ZeroFox
Conservative floor
US$19,790
Transaction median
US$45,604

Vendr, 38 purchases. Priority takedowns and legal are add-ons at 20-40% of annual.. The add-ons named here are not in either column. They would push both totals up.

Identity / stealer-log exposure

Vendor priced
SpyCloud
Conservative floor
US$10,800
Transaction median
US$41,342

Vendr; reported minimum US$15,000-25,000. The floor is the lowest observed transaction, which sits below the vendor’s own reported minimum; we have carried the lower figure.

Threat intelligence

Vendor priced
Recorded Future
Conservative floor
US$27,000
Transaction median
US$70,288

Vendr, 46 purchases, February 2026. The widest gap between floor and median of any row here.

Adversarial validation

Vendor priced
Horizon3 NodeZero
Conservative floor
US$18,600
Transaction median
US$18,600

Vendr median; secondary source. A single median with no separately published floor, so the same figure carries into both columns and this row does not move between them.

Assembled stack, annual

Vendor priced
Six licences, six renewals
Conservative floor
US$100,778
Transaction median
US$214,296

The sum of the rows above and nothing else. One-off implementation, priority takedown and legal add-ons are all outside these totals; the methodology below says what that omission is worth.

Against that, the ShadowMap side of the comparison is a single line: one licence published at from US$25,000 a year, priced on asset-surface size, not per product. The rows above are what a security team ends up holding when each capability is bought where it is strongest.

Methodology

Where these numbers came from, and what is missing

Three of the vendors we meet in competitive deals are not in this arithmetic at all, because they publish nothing we could cite and we would rather exclude them than estimate on their behalf. The exclusion is about pricing only: two of the three are broad digital-risk platforms and the third is a ratings vendor, none of them is a point tool, and their absence here says nothing about what they cover.

How this arithmetic was built As of August 2026
  • Every figure is either a vendor’s own published list price or a Vendr transaction median drawn from real purchases. None of it is our estimate of what a vendor charges.
  • Published list prices come from the vendor’s pricing page: Intruder from US$299 a month, UpGuard US$21,000 a year for Standard with fifty vendor slots. Both are checkable in a browser tab.
  • Transaction medians come from Vendr, and where the sample size is published we carry it on the row: sixty-nine UpGuard purchases, thirty-eight ZeroFox, and forty-six Recorded Future purchases as at February 2026, the one row our source dates.
  • Where a vendor publishes one figure and no separate median exists, that figure carries into both columns. Intruder and Horizon3 NodeZero are priced that way here, so neither row moves between the floor and the median.
  • No enterprise-grade external-attack-surface median is published, so that row prices an SMB-tier tool. It understates the enterprise floor, which makes the lower multiple the conservative one.
  • The ShadowMap side is the published entry licence, from US$25,000 a year. It is a floor and not a fixed price: larger estates and vendor portfolios quote above it, which is stated on the pricing page.
  • We have not scored how much of what ShadowMap does these six products cover, or how much of what they do ShadowMap covers. This page is arithmetic on price, not a capability claim.

Deliberately excluded

  • The arithmetic uses vendors with published pricing. Cyble, CloudSEK and RiskRecon publish none.
  • One-off implementation is not in the totals: ratings vendors quote US$5,000-25,000 each, and professional services typically run 10-20% of contract value.
  • Priority takedown and legal add-ons are not in the totals either: ZeroFox prices them at 20-40% of annual contract value.

Every cost we have left out moves the assembled total in the same direction: up. That covers implementation, professional services, priority takedown and legal escalation. Leaving out the three vendors who publish nothing moves it neither way, because we have not substituted a guess for them in either column.

The limits of the argument

What a price comparison does not settle

A cost table is one input to a decision. Two things sit outside it: one that makes the assembled stack more expensive than the total suggests, and one that is a genuine argument for buying it anyway.

01 Understated by the table

A licence is the cheapest part of owning six products

The operating overhead
Six licences means six renewal negotiations a year, six onboardings, six support relationships to keep warm, and six integration projects to build and then maintain against six roadmaps. None of that appears in a price column, and all of it lands on the same small team.
The correlation problem
The products do not correlate with each other. A leaked credential in one console and the exposed host it opens in another are the same finding, and joining them is manual work that has to happen every time. That is the cost most stacks discover in month four, not at signature.
What that means for the totals
Implementation fees, priority takedown add-ons and legal escalation are all excluded from the figures above, and every one of them is a real line on a real invoice. The assembled stack is more expensive than this page says, not less.
02 Argues the other way

Best-of-breed is a legitimate strategy, and sometimes the right one

Depth in a single lane
A point tool that does one thing is frequently better at that one thing. A dedicated threat-intelligence platform gives an analyst team a depth of finished intelligence that a broader platform does not, and a dedicated autonomous-testing product goes further into offensive tooling than our validation does.
The concession price cannot buy back
CloudSEK was first to market on exposed AI infrastructure with AIVigil: MCP servers, leaked AI credentials, vector databases, shadow AI. This page does not price that requirement. If it is on your list, evaluate it separately; no total here is the deciding number for it.
When the stack is the right answer
Sometimes one capability is the centre of your programme: brand protection or vendor risk is what the board asks about every quarter. Buying the deepest product in that category and accepting the overhead elsewhere is then a defensible decision, and price is not the variable you should optimise.
Where this page applies
The comparison holds when you need all six of these capabilities and no single one dominates. That is the common case, and it is the case in which paying 4.0× to 8.6× to cover the same six lines is hard to justify to a finance team.

Price the stack you would otherwise assemble.

A 30-minute scoping call maps your apex domain live and ends in a written pricing letter. Bring the quotes you already hold and we will do the comparison against your numbers, not ours.