Service catalog · 8 offerings
What we deliver.
Engagements range from one-time assessments to multi-year virtual CISO retainers. Each is led by a senior practitioner — not relegated to the kickoff slide.
S01
Virtual CISO
Security program leadership on retainer.
A senior, certified practitioner embedded with your leadership team — strategy, board reporting, vendor management, and the harder calls that come with the role.
- Program strategy & roadmap
- Board & audit committee reporting
- Risk register ownership
- Incident leadership
S02
Framework readiness & gap assessment
HIPAA · PCI DSS · SOC 2 · ISO 27001 · NIST CSF · HITRUST CSF.
Honest gap assessments against the framework you actually have to meet — written so leaders can act on them and auditors can rely on them.
- Control mapping & evidence walkthrough
- Prioritized remediation plan
- Audit-ready artifacts
- Cross-framework crosswalks
S03
Risk assessment
NIST 800-30, FAIR, and client-tailored methodologies.
Quantitative or qualitative — whatever the audience needs. We translate threats and likelihoods into language a CFO and a CISO can both defend.
- Threat & likelihood analysis
- Residual risk modeling
- Treatment recommendations
- Annual refresh cadence
S04
Policy program development
Turnkey or tailored — we ghost-write what your team will actually use.
Policies that read like a person wrote them, mapped to the frameworks you operate in, and updated on a cadence the program can sustain.
- Policy library buildout
- Standards & procedures
- Lifecycle & exception management
- Annual review & training plan
S05
Vendor & third-party risk
Program design and ongoing operation.
Set up the program once, then operate it — questionnaires, due-diligence cadence, contract clauses, and a tier model you can actually scale.
- Tier model & questionnaire library
- Contract risk language
- Continuous monitoring
- Critical vendor deep-dives
S06
Data & privacy program
Asset analysis, data flow mapping, privacy program support.
Know what data you have, where it lives, and what obligations attach to it — across HIPAA, GLBA, FERPA, state privacy laws, and contract requirements.
- Data inventory & classification
- Data flow diagrams
- DPIA & privacy impact reviews
- Records-of-processing artifacts
S07
Security awareness
Program design and content — written for humans.
Awareness content that respects your team's time, ties to real threats they face, and produces evidence the auditor will accept.
- Annual program design
- Role-based training tracks
- Phishing simulation strategy
- Metrics & reporting
S08
Incident readiness
Tabletop exercises, runbooks, business continuity planning.
Plans you've actually rehearsed beat plans that look great on paper. Tabletops, runbooks, and BC/DR work designed for the team that has to execute it.
- IR plan & runbooks
- Executive & technical tabletops
- Business impact analysis
- BC/DR plan validation