The Cyber Governance GroupSecurity · Risk · Compliance
[ Services ]

Find the gaps. Close them for good.

Whether you need a clear starting point, a full program or someone to keep it moving, each service is built around one goal: a stronger security posture that your people can sustain.

01

Risk & compliance assessments

  • HIPAA
  • PCI DSS
  • NIST CSF 2.0
  • NCUA / ACET
  • FTC Safeguards
  • FERPA
  • ITP-SEC023

An advisor-led assessment of how your organization actually manages security risk, measured against the frameworks you answer to and validated hands-on rather than by questionnaire.

Scope

  • Governance and risk management: leadership oversight, policies, risk analysis, vendor management and incident readiness, established through interviews, evidence review and walkthroughs.
  • Technical validation: network vulnerability scanning, Microsoft 365 and cloud configuration review, Active Directory review and an external exposure assessment, always under your written authorization.
  • Traceable evidence: each finding records how it was established (interview, inspection, observation or test) and the requirement it relates to.
  • Self-assessment where it belongs: when a framework builds one in, such as PCI DSS questionnaires or NCUA's ACET, we incorporate it and reconcile it against our findings.

Deliverables

Findings in each framework's own terms, a risk register, a plan of action and milestones with owners and dates, an executive report and briefing for leadership, and regulator-format artifacts such as a HIPAA Security Rule risk analysis or a NIST CSF current profile.

02

Fractional CISO

  • Strategy
  • Board reporting
  • Risk decisions

A named security executive who knows your organization, participates in the decisions that matter and is accountable for the program between audits.

  • Strategy and roadmap: priorities and budget recommendations tied to risk, not trends.
  • Governance: policy ownership, annual reviews and risk acceptance decisions documented properly.
  • Board and committee reporting: quarterly or as needed, in language directors can act on.
  • Stakeholder engagement: examiners, auditors, insurers and customers who ask hard questions.
  • Incident leadership: decision support and regulatory notification governance when something goes wrong.
03

Remediation management

  • Tracking
  • Verification
  • Monitoring

Findings only matter once they're closed. We manage remediation from the first finding to verified closure, so progress is visible and every fix holds up to scrutiny.

  • A prioritized roadmap with owners, deadlines and escalation when work stalls.
  • Implementation guidance specific to the technology you run: Microsoft 365, Google Workspace, firewalls, backup platforms and line-of-business systems.
  • Verification: "done" is a claim; "verified" means we've reviewed the evidence. Every closed item keeps its evidence on file for your next exam or audit.
  • Ongoing monitoring: newly exploited vulnerabilities matched to the products in your environment, regulatory changes that affect your obligations, and deadlines before they're missed.

Your IT team or provider makes the changes; we guide, track and verify them, so every fix is confirmed rather than assumed.

04

Security program documentation

  • Policies
  • Plans
  • SSP
  • POA&M

Policies, standards, plans and records developed from assessed reality: specific to your systems, roles and vendors, and mapped to the requirements they satisfy.

Includes the information security policy set, incident response and contingency plans, risk register and plan of action and milestones, vendor register, system security plan and board reporting, plus sector documents such as HIPAA Notice of Privacy Practices review and FERPA data sharing agreements.

Program documentation
05

Incident readiness & response governance

  • IR plans
  • Notification
  • Decision support

The notification clock starts at discovery. Your plan should already know which deadlines apply, who must be told and who decides.

We build response plans mapped to your actual obligations, including HIPAA's 60-day outer limit, Pennsylvania's breach notification law, NCUA's 72-hour cyber incident rule, the FTC Safeguards Rule and card-brand requirements. During an incident we provide decision support and notification governance alongside your forensics provider and counsel.

06

Third-party risk

  • Due diligence
  • BAAs & DSAs
  • Questionnaires

Many breaches start at a vendor. Know who holds your data, what they've committed to, and when to look again.

Risk-tiered due diligence, tracking of business associate agreements, FERPA data sharing agreements, PCI attestations and SOC reports, and a vendor register with review dates. When your own customers send a security questionnaire, we help you answer it from the program you actually run.

07

Examination & audit readiness

  • NCUA exams
  • Insurers
  • Commonwealth

When an examiner, auditor or insurer asks, the evidence should already exist and be easy to find.

  • Exam preparation: document requests assembled and reviewed before the examiner arrives.
  • Cyber insurance renewals: questionnaire answers you can stand behind, with evidence to support them.
  • Independent assessments for organizations supporting Commonwealth agencies under Pennsylvania's ITP-SEC023.
08

Framework overlap

  • Separate assessments
  • Shared head start

If you answer to HIPAA and PCI DSS, or NCUA and NIST CSF, you shouldn't pay for the same work twice.

Each framework is assessed on its own terms. A finished assessment can then give the next one a head start: answers carry over only where requirements genuinely match, partial overlaps are flagged for a fresh look, and every carried-over answer is reviewed before it counts.

See how it works
Engagement models

Begin with what you need. Add as you grow.

Each engagement is fixed-fee and scoped before work begins, and each one builds on the one before it, so nothing you've already done goes to waste.

Assess

Security Baseline Assessment

A focused assessment of your core controls and external exposure: a fast, defensible view of where you stand.

Typical duration2–4 weeks
  • Risk-rated findings across core control areas
  • External exposure and Microsoft 365 review
  • Prioritized 90-day action plan
  • Executive briefing
Request an assessment
Build

Program Assessment & Development

A full, advisor-led assessment against the frameworks you answer to, and the program foundation that follows from it.

Typical duration8–12 weeks
  • Framework assessment with technical validation
  • Risk register and plan of action
  • Core policies, plans and standards
  • Board-ready report and briefing
Discuss scope
Lead

Fractional CISO

Ongoing executive leadership, with remediation managed to verified closure and the program kept current.

EngagementMonthly retainer
  • A named security executive
  • Remediation management and verification
  • Board, examiner and insurer engagement
  • Threat and regulatory monitoring
Explore a retainer
Focus

Targeted engagements

Defined projects for a specific deadline, requirement or stakeholder request.

ScopeProject-based
  • Incident response plan
  • Vendor risk program
  • Exam, audit or questionnaire readiness
  • ITP-SEC023 independent assessment
Discuss a project

Find the right starting point.

Tell us what's driving the timing, whether an exam, an audit, a board question, an insurance renewal or an incident, and we'll recommend where to begin.