IAM & PAM Security Consulting

Security Assessment Proposal

Active Directory & Identity Infrastructure

[CLIENT NAME]

Prepared by: Identity Bytes Consulting

Date: [DATE]

Valid Until: [DATE + 30 DAYS]

Confidential — For Intended Recipient Only
Customization Required: Replace all [BRACKETED] text with client-specific information before sending.

Executive Summary

[CLIENT NAME] has recognized the critical importance of securing its identity infrastructure against modern cyber threats. With [PERCENTAGE] of breaches involving compromised credentials, protecting Active Directory and privileged accounts is essential to business continuity.

Identity Bytes proposes a comprehensive security assessment to identify risks in your identity infrastructure before attackers can exploit them. Our assessment combines automated scanning with expert manual analysis to deliver actionable findings—not just a list of vulnerabilities.

Why This Matters Now

Active Directory is the backbone of enterprise identity. A single compromised privileged account can give attackers complete control of your environment within hours. Our assessment identifies these risks and provides a clear remediation roadmap.

Understanding Your Environment

Based on our discovery call, we understand [CLIENT NAME]'s environment includes:

[X]
Active Users
[X]
Domain Controllers
[X]
Domains
[X]
Trust Relationships

Key concerns identified during our initial conversation:

Proposed Approach

Our assessment methodology combines industry-standard tools with proprietary analysis techniques developed from years of enterprise IAM experience.

Privileged Account Discovery & Analysis

Complete inventory of all privileged accounts with tier classification and risk scoring.

  • Domain Admins, Enterprise Admins, Schema Admins enumeration
  • Nested group membership analysis (hidden privilege paths)
  • Service account discovery across multiple detection methods
  • Stale and orphaned account identification

Attack Path Mapping

Visualize how an attacker could move from initial access to domain dominance.

  • Shortest paths to Domain Admin identification
  • Kerberoastable account analysis with path context
  • Delegation abuse opportunities
  • GPO-based privilege escalation vectors

Security Configuration Review

Evaluate AD security settings against industry best practices and frameworks.

  • Password policy assessment (domain and fine-grained)
  • Kerberos security configuration (encryption, delegation)
  • AdminSDHolder and protected accounts audit
  • Trust relationship security analysis

Risk Quantification & Prioritization

Translate technical findings into business risk with clear remediation priorities.

  • Risk scoring aligned with MITRE ATT&CK framework
  • Business impact assessment for each finding
  • Prioritized remediation roadmap (Quick Wins Long-term)
  • Effort and cost estimates for remediation

Our Commitment: Least Privilege Assessment

We conduct our assessment using read-only access—no Domain Admin required. This minimizes risk to your environment while still providing comprehensive visibility into security gaps.

Deliverables

You will receive a comprehensive package of reports and data designed for both executive communication and technical remediation.

Deliverable Format Audience
Executive Summary Report
High-level findings, risk score, business impact
PDF C-Suite, Board
Technical Assessment Report
Detailed findings with evidence and remediation steps
PDF IT Security, Admins
Attack Path Diagrams
Visual representation of privilege escalation routes
PDF/PNG Security Team
Privileged Account Inventory
Complete list with tier classification and risk factors
Excel IT Operations
Service Account Inventory
All service accounts with SPN, delegation, password age
Excel IT Operations
Remediation Roadmap
Prioritized action plan with effort estimates
Excel Project Managers
Executive Presentation
Slide deck for leadership briefing
PowerPoint Leadership

Engagement Milestones

Phase 1: Kickoff & Access

Days 1-2

Kickoff meeting, access provisioning, environment documentation review

Phase 2: Discovery & Collection

Days 3-5

Automated data collection using assessment tools and custom scripts

Phase 3: Analysis & Attack Mapping

Days 6-8

Manual analysis, attack path identification, risk scoring

Phase 4: Report Development

Days 9-10

Comprehensive report writing and quality review

Phase 5: Delivery & Briefing

Days 11-14

Draft review, final delivery, executive presentation, Q&A session

Investment

Based on the scope of [CLIENT NAME]'s environment ([X] users, [X] domains), we recommend the following engagement:

AD Security Assessment

[ENVIRONMENT SIZE: Small/Medium/Large] Environment

$[PRICE]
  • Privileged account discovery and tiering
  • Service account risk assessment
  • Kerberos security analysis
  • Attack path mapping (BloodHound)
  • Password policy evaluation
  • Trust relationship review
  • Executive and technical reports
  • 90-minute executive briefing
  • 30-day post-delivery support for questions

Optional Add-Ons

Add-On Service Description Investment
Azure AD / Entra ID Assessment Cloud identity security review including MFA coverage, Conditional Access, privileged roles +$5,000
Multi-Forest Assessment Assessment of additional AD forests with trust analysis +$3,000/forest
Remediation Support 8 hours of hands-on assistance implementing priority remediations +$2,500
Quarterly Reassessment Ongoing monitoring with quarterly assessment and trend analysis $5,000/quarter

Payment Terms

Why Identity Bytes

Specialized Expertise

Unlike generalist security firms, we focus exclusively on Identity & Access Management and Privileged Access Management. This specialization means deeper expertise and more actionable findings.

Practitioner Background

Our team has hands-on experience implementing CyberArk, Okta, and enterprise IAM programs across Fortune 500 companies. We understand the operational realities you face.

Actionable Deliverables

We don't just identify problems—we provide clear remediation steps with effort estimates. Our reports are designed to be immediately actionable by your team.

Partnership Approach

We're not here to audit and disappear. We provide ongoing support and are available for questions long after the engagement concludes.

Credentials & Certifications

  • CyberArk Certified Delivery Engineer (CDE)
  • Okta Certified Administrator
  • AWS Solutions Architect Associate
  • 5+ years enterprise PAM/IAM implementation experience
  • Global program delivery across 47+ markets

Our Approach Difference

Traditional Assessments Identity Bytes Approach
Generic vulnerability scanner output Expert analysis with business context
Hundreds of findings without prioritization Risk-ranked findings with clear remediation paths
Technical jargon in reports Executive-ready and technical versions
Engagement ends at report delivery 30-day support + ongoing partnership
Requires Domain Admin access Least-privilege approach minimizes risk

Next Steps

We're ready to help [CLIENT NAME] secure its identity infrastructure. Here's how to move forward:

1. Review & Questions

Review this proposal and let us know if you have any questions or need clarification on scope.

2. Scope Confirmation

Confirm the engagement scope and any optional add-ons you'd like to include.

3. SOW Signature

Sign the Statement of Work to formalize the engagement. We'll send a detailed SOW upon approval.

4. Kickoff Scheduling

Schedule the kickoff meeting and coordinate access provisioning with your IT team.

Ready to Get Started?

Contact us to discuss your specific needs or to schedule the engagement.

Email: [EMAIL]

Phone: [PHONE]

Acceptance

By signing below, [CLIENT NAME] agrees to proceed with the engagement as outlined in this proposal, pending execution of a formal Statement of Work.

Identity Bytes Consulting

Signature
Name & Title
Date

[CLIENT NAME]

Signature
Name & Title
Date