Cloud Sentry
Diagnostic

See where the exposure compounds when security waits.

A short, private diagnostic. It does not guess at your losses or quote a price. It takes a few facts you already know and shows where leaving security half-configured tends to cost you more than once.

A diagnostic, not a forecast.

Most security spending never gets tested until the day it matters, and by then the question is not what a tool costs but what waiting cost you. This is a calmer way to look at it: not a forecast, and not a scare, just a clear read on where the gaps tend to compound.

The calculator below asks for headcount, your primary stack, whether you sell to enterprise buyers, and whether a compliance deadline is coming. From those, it shows three faces of the same exposure. Every number on screen is either yours or a labeled assumption you can see, and nothing you enter leaves your browser.

See where the exposure compounds

Give a few facts you already know. The three cards below are built entirely from your own numbers and the assumptions shown, so you can see the shape of the exposure without anyone guessing at a figure for you.

Prefilled with an example. Change any field to match your situation.

Everything here runs in your browser. Nothing you type is sent to us, stored, or shared.

A round total is fine; you do not need an exact number.

What is your primary stack?
Are you selling to enterprise buyers?

Enterprise buyers tend to run a security review before they sign.

If a review stalls, how long does it set a deal back?

An assumption you set. See the note under the results.

Do you have a compliance deadline in the next year?
Which framework?

Your exposure, three ways

Deal-cycle exposure

The pipeline waiting on a security answer

You told us 3 enterprise deals are in review. Before most enterprise deals close, a security questionnaire or a vendor-risk review stands in the way.

Assumption you set: you expect a stalled review to set a deal back by about a month. That is a planning range, not a Cloud Sentry statistic and not a prediction about your deals.

With 3 deals behind that same gate, the delay stops being one deal's problem. Your enterprise pipeline moves at the speed of your slowest security answer.

More buyers now ask for SOC 2 evidence by name, so your SOC 2 deadline and these reviews are really the same gate.

Illustrative estimate, based on your inputs and the assumptions shown. Not a prediction or a quote.

Paying, but unconfigured

The security you already pay for

You have 25 people. Business-grade Microsoft 365 plans bundle identity and endpoint security: conditional access and enforced multifactor authentication through Microsoft Entra ID, and threat protection through Microsoft Defender for Business. If that capability is licensed but sitting unconfigured, you are paying for 25 seats of protection that is switched off.

Your SOC 2 work expects these same foundations (enforced multifactor authentication, access reviews, audit logging). Configuring what you already pay for is progress toward the deadline, not a separate project.

See what Microsoft 365 hardening covers

Illustrative estimate, based on your inputs and the assumptions shown. Not a prediction or a quote.

Incident exposure

A bounded cost against an open-ended one

Prevention here is mostly configuration: switching on controls you already own, and keeping them on. That cost is bounded and largely known in advance.

An incident runs the other way. The size of the bill is set by someone else, and it tends to arrive all at once.

External anchor: Verizon's 2025 Data Breach Investigations Report puts the median ransomware demand at roughly US$115,000, and reports ransomware present in a large share of breaches at smaller organizations. (Verizon 2025 DBIR).

We are not going to turn that into a figure for your business. The point is the asymmetry: a known, bounded cost to configure what you already own, set against an open-ended one you do not control.

Illustrative estimate, based on your inputs and the assumptions shown. Not a prediction or a quote.

Where it compounds. The controls that unstick an enterprise review, the capability already bundled into your Microsoft 365 plan, and the defenses that blunt an incident are largely the same work. Leave it half-done and one gap shows up in all three places at once. That is how the exposure compounds, and it is also why closing it pays back in more than one place.

On the deal-review delay: Commonly reported ranges for enterprise security and vendor-risk reviews. Adjust to your own sales motion. This is a planning assumption, not a Cloud Sentry statistic.

Sources and assumptions: The “security you already pay for” framing counts your own headcount against security capabilities bundled into business-grade plans (Microsoft 365 via Microsoft Entra ID and Microsoft Defender for Business; AWS via IAM, GuardDuty, and Security Hub). Exactly what is included depends on your specific plan. Framework references are to public structures: the AICPA Trust Services Criteria (SOC 2), ISO/IEC 27001:2022 Annex A, and the HIPAA Security Rule (45 CFR Part 164, Subpart C). The one external figure is from Verizon’s 2025 Data Breach Investigations Report (median ransomware demand around US$115,000; ransomware present in a large share of breaches at smaller organizations), verizon.com/business/resources/reports/dbir. Nothing here is a prediction, a benchmark for your business, or a quote.

This is a diagnostic, not a quote. Published plan structure lives on the plans page.

Turn the read into a next step.

Start with a focused look at your Microsoft 365 tenant, or bring your own numbers and we will walk the exposure with you.

A focused read on what your Microsoft 365 tenant already has switched on, and what is licensed but sitting unconfigured.

Bring the numbers you just saw and we will walk where the exposure compounds for you, with no obligation.