Posture assessments, governance and GRC, compliance mapping, and risk work — led by a CISSP-certified practitioner. This is the anchor practice, and for most clients it's where the relationship starts.
Security work in the mid-market usually arrives as a deadline — an audit, a questionnaire, a board question, an incident. The job is to answer that credibly and leave you with something that keeps answering it.
Current-state review against your actual threat profile, with findings ranked by exploitability rather than by how alarming they sound.
Policy architecture, risk tiering, decision rights, and oversight processes — built from your business model, not a downloaded template.
NIST AI RMF, ISO 42001, the EU AI Act, SOC 2, HIPAA, GDPR — mapped to your controls with the gaps named rather than glossed.
Prompt injection, data exfiltration through model outputs, over-permissioned agents, training-data exposure — the failure modes conventional threat models miss.
Review of a system before it ships, or of one already running that nobody has looked at hard. Access model, data flow, logging, blast radius.
Standing security leadership for organizations that need the function but not the salary. Board reporting, vendor review, incident readiness.
The most requested piece of this practice is a full AI governance framework. It runs about ten weeks on a fixed rhythm, so you always know what week you're in and what has to be true to move on.
| Phase | Weeks | What happens |
|---|---|---|
| Discovery | 1–2 | Stakeholder interviews, AI and system inventory, maturity assessment, gap analysis |
| Design | 3–6 | Principles, risk tiering model, roles and RACI, review gates, compliance mapping |
| Validation | 7–9 | Framework piloted against 3–5 real systems, stakeholder review, refinement |
| Handoff | 10 | Documentation, training, implementation playbook, measurement baseline |
Shorter engagements — a single system assessment, a compliance gap review — are scoped independently.
It isn't a checklist, and it isn't a deck of recommendations. The output is something your team operates without us, and the methodology behind it belongs to you.
Security work surfaces the next two questions fairly reliably: something needs to be built or fixed, which is Development, and something needs an owner going forward, which is Managed Services.
A 45-minute call, no cost and no deck. We'll tell you honestly what it would take, and whether you need us to do it.
Book a discovery call