The Cyber Governance GroupSecurity · Risk · Compliance
[ Approach ]

Risk-led. Evidence-based. Built to last.

Compliance is one outcome of a well-run security program, not the goal. We start with the risks that matter to your operations, verify what's actually in place, and lead the work through to results that hold.

01 — Principles

How we work.

Four commitments that shape every engagement, from a two-week baseline to a multi-year fractional CISO relationship.

P-01

Risk before checklists

Priorities follow what could actually disrupt your operations or harm the people you serve. Framework requirements are mapped to that picture, not the other way around.

P-02

Verified, not assumed

Every finding and every fix is backed by evidence: interviews, inspection, observation and technical testing, recorded so it can be traced later.

P-03

People first

Behind every control is someone doing a demanding job. We work alongside your team, explain the why, and build around how your organization actually operates.

P-04

Proportionate

Controls sized to your organization, budget and risk tolerance. The goal is a program your people can run, not one that only exists on paper.

02 — The engagement

From first conversation to sustained program.

Five stages. Most engagements begin at the first and continue as far as you need; each stage produces something you can use on its own.

01 · Discover

Understand the context

Your obligations, operations, technology and what's driving the timing: an exam, an audit, a board question, an insurance renewal or an incident.

02 · Assess

Establish the facts

Governance, technical and compliance assessment, on-site where it matters and remote where it doesn't. Where a framework calls for a self-assessment, we reconcile it against our findings.

03 · Prioritize

Decide what matters

Risk-rated findings become a sequenced roadmap with owners, dates and effort, plus an executive report leadership can act on.

04 · Remediate

Close the gaps

Implementation guidance, progress tracking and verification of each fix, with evidence kept for the next examination.

05 · Govern

Sustain the program

Fractional CISO leadership, board reporting, policy upkeep, monitoring of new threats and regulatory change, and annual reassessment.

03 — What we assess

The whole program, not just the paperwork.

Every assessment covers governance and technology together, because examiners, insurers and attackers look at both.

S-01

Governance & risk

Leadership oversight, roles, policies, risk analysis and risk acceptance.

S-02

Identity & access

MFA coverage, privileged access, joiner-mover-leaver controls and directory hygiene.

S-03

Endpoints & infrastructure

Patching, vulnerability exposure, endpoint protection, network segmentation and firewalls.

S-04

Cloud & collaboration

Microsoft 365 and Google Workspace configuration, email security and data sharing.

S-05

Data protection

Where sensitive data lives, encryption, retention and disposal.

S-06

Resilience

Backup integrity, restore testing, contingency planning and ransomware recovery.

S-07

Third parties

Vendor due diligence, agreements and ongoing oversight.

S-08

Detection & response

Logging, monitoring, incident response and notification readiness.

04 — Framework overlap

Each framework on its own terms. No work done twice.

Most organizations answer to more than one set of requirements. Each is assessed separately, in its own language, so nothing gets glossed over. Where they genuinely overlap, a finished assessment gives the next one a head start, and every carried-over answer is reviewed before it counts. Pick a topic to see where it shows up.

Frameworks guide
One topic
Risk analysis
AssessmentSeparate for each framework
Head startOverlap carried over, then reviewed

Illustrative citations. Overlap is confirmed requirement by requirement, never assumed.

See where you stand.

Start with the readiness check, or go straight to a conversation.