Risk-led. Evidence-based. Built to last.
Compliance is one outcome of a well-run security program, not the goal. We start with the risks that matter to your operations, verify what's actually in place, and lead the work through to results that hold.
How we work.
Four commitments that shape every engagement, from a two-week baseline to a multi-year fractional CISO relationship.
Risk before checklists
Priorities follow what could actually disrupt your operations or harm the people you serve. Framework requirements are mapped to that picture, not the other way around.
Verified, not assumed
Every finding and every fix is backed by evidence: interviews, inspection, observation and technical testing, recorded so it can be traced later.
People first
Behind every control is someone doing a demanding job. We work alongside your team, explain the why, and build around how your organization actually operates.
Proportionate
Controls sized to your organization, budget and risk tolerance. The goal is a program your people can run, not one that only exists on paper.
From first conversation to sustained program.
Five stages. Most engagements begin at the first and continue as far as you need; each stage produces something you can use on its own.
Understand the context
Your obligations, operations, technology and what's driving the timing: an exam, an audit, a board question, an insurance renewal or an incident.
Establish the facts
Governance, technical and compliance assessment, on-site where it matters and remote where it doesn't. Where a framework calls for a self-assessment, we reconcile it against our findings.
Decide what matters
Risk-rated findings become a sequenced roadmap with owners, dates and effort, plus an executive report leadership can act on.
Close the gaps
Implementation guidance, progress tracking and verification of each fix, with evidence kept for the next examination.
Sustain the program
Fractional CISO leadership, board reporting, policy upkeep, monitoring of new threats and regulatory change, and annual reassessment.
The whole program, not just the paperwork.
Every assessment covers governance and technology together, because examiners, insurers and attackers look at both.
Governance & risk
Leadership oversight, roles, policies, risk analysis and risk acceptance.
Identity & access
MFA coverage, privileged access, joiner-mover-leaver controls and directory hygiene.
Endpoints & infrastructure
Patching, vulnerability exposure, endpoint protection, network segmentation and firewalls.
Cloud & collaboration
Microsoft 365 and Google Workspace configuration, email security and data sharing.
Data protection
Where sensitive data lives, encryption, retention and disposal.
Resilience
Backup integrity, restore testing, contingency planning and ransomware recovery.
Third parties
Vendor due diligence, agreements and ongoing oversight.
Detection & response
Logging, monitoring, incident response and notification readiness.
Each framework on its own terms. No work done twice.
Most organizations answer to more than one set of requirements. Each is assessed separately, in its own language, so nothing gets glossed over. Where they genuinely overlap, a finished assessment gives the next one a head start, and every carried-over answer is reviewed before it counts. Pick a topic to see where it shows up.
Frameworks guideIllustrative citations. Overlap is confirmed requirement by requirement, never assumed.
See where you stand.
Start with the readiness check, or go straight to a conversation.