Pricing

Choose the level of cyber exposure management that fits your organisation.

BlackstoneOne gives you a continuous view of what is exposed, what is vulnerable, and what to prioritise next. Start with the capability you need most, combine scanning and attack surface visibility in one platform, or add the governance and intelligence layer needed to manage cyber risk at scale.
Pricing is tailored to your environment, priorities and required level of coverage, so you get the right fit for your organisation today, with room to scale over time.
Three plans, one platform
Each plan builds on the one before it.

Core covers a single capability. Essential combines both exposure domains into one view. Enterprise adds the Exposure Intelligence Center, the governance layer that turns technical findings into board-ready decisions.

Core
Choose the capability you need most
EVM · We scan ASM · We map
Core EVM continuously scans selected external assets for vulnerabilities, validates findings and supports prioritisation. Core ASM continuously maps your internet-facing assets and exposure points to improve visibility across your external attack surface. Pick whichever matches where you need visibility first.
Includes
  • Continuous vulnerability scanning or continuous asset discovery and mapping
  • Risk validation and prioritisation, or visibility into exposed assets and technologies
  • Actionable alerts and reporting
  • Guidance on findings and remediation context
  • Technical support
Optional add-on Internal Vulnerability Management (IVM)
Get started
Enterprise
Everything in Essential, plus the Exposure Intelligence Center
EVM ASM EIC · We analyse
Enterprise adds the Exposure Intelligence Center: the governance and intelligence layer that turns technical exposure data into structured, explainable and auditable risk insight for every level of your organisation.
Extended in Enterprise
Role- and level-based views with EIC
My Dashboard extends into purpose-built views for every level, from technical teams to governance and executive management.
What Enterprise adds
  • Exposure Overview and Signal Center
  • Risk Prioritisation and Executive Insights
  • Compliance Mapping and Evidence Vault
  • Governance Settings, Integrations and Exports
Optional add-on Internal Vulnerability Management (IVM)
Named security contact Named security contact included
Talk to sales
Add-ons

Extend any plan with these standalone services.

These sit alongside your plan rather than inside the EIC governance layer above, so you can add either one regardless of which plan you choose.

Internal Vulnerability Management (IVM)

Extends scanning and prioritisation to assets inside your network, not just the external perimeter. Available as an add-on on every plan, so internal coverage grows alongside external coverage rather than requiring a separate purchase later.
Add-on to any plan

Cyber Awareness Training & Phishing Simulation

A standalone BlackstoneOne service line: continuous employee training with just-in-time nudges and automated remedial courses, plus realistic phishing tests that measure how your organisation actually responds. Not part of EIC, and not tied to a specific plan.
Standalone service line
Included in every plan

The baseline that never changes.

Regional platform delivery
Delivered from regional data centers across Denmark, Norway, Sweden, Frankfurt and the US.
Named security contact
A dedicated BlackstoneOne contact who knows your account and setup.
Guidance on findings
Help understanding findings, exposure context and prioritisation.
Technical support
Support via portal, email and phone for platform and product questions.
Platform access & reporting
Continuous access to the BlackstoneOne SaaS platform, dashboards and alerts.
Which plan is right for you

Mapped to who typically starts where.

IT & Security Teams needing one scanning or mapping capability Core
Teams that need VM and ASM working as one view Essential
Management, Compliance and Public Sector needing governance, audit trails and board reporting Enterprise
Pricing tailored to your organisation

No two organisations pay the same price.

No two organisations have the same infrastructure, exposure landscape or security requirements. Some need focused visibility into a limited external footprint. Others need broader coverage across multiple environments, stricter governance requirements, or deeper scanning and prioritisation across a larger attack surface.

That’s why BlackstoneOne pricing is customised to reflect your environment, your priorities and the level of coverage you need. We take into account the plan and services you choose, the size and complexity of your environment, the required scan coverage and scan level, your security and governance requirements, and your current maturity and operating model.

This approach gives you a solution that is right-sized for your organisation today, with the flexibility to scale as your needs evolve.

Let's find the right fit
We'll help you scope the right plan, coverage level and pricing model based on your environment, priorities and current maturity.
Frequently asked
Common questions.
Can I start with Core and upgrade later?
Yes. Core, Essential and Enterprise are built to sit on the same underlying data, so upgrading adds capability without re-platforming or losing history.
Is Internal Vulnerability Management included in any plan?
No. IVM is an optional add-on available on every plan, so you can extend scanning inside your network whenever you're ready, on top of whichever plan you're on.
Are Cyber Awareness Training and Phishing Simulation part of Enterprise or EIC?
No. They're a separate BlackstoneOne service line, independent of Vulnerability Management, EASM and the Exposure Intelligence Center, and can be added to any plan.
Do you publish list prices?
Pricing is customised to your environment, size and coverage needs rather than published as a flat rate. Talk to us and we'll scope the right fit and a price to match.