Secure it · Cybersecurity

The offering everything else is built on.

Posture assessments, governance and GRC, compliance mapping, and risk work — led by a CISSP-certified practitioner. This is the anchor practice, and for most clients it's where the relationship starts.

What we do here

Six things, one lens.

Security work in the mid-market usually arrives as a deadline — an audit, a questionnaire, a board question, an incident. The job is to answer that credibly and leave you with something that keeps answering it.

Posture

Security assessments

Current-state review against your actual threat profile, with findings ranked by exploitability rather than by how alarming they sound.

GRC

AI governance frameworks

Policy architecture, risk tiering, decision rights, and oversight processes — built from your business model, not a downloaded template.

Compliance

Control mapping & evidence

NIST AI RMF, ISO 42001, the EU AI Act, SOC 2, HIPAA, GDPR — mapped to your controls with the gaps named rather than glossed.

Risk

AI-specific assessments

Prompt injection, data exfiltration through model outputs, over-permissioned agents, training-data exposure — the failure modes conventional threat models miss.

Architecture

Security design review

Review of a system before it ships, or of one already running that nobody has looked at hard. Access model, data flow, logging, blast radius.

Advisory

Fractional CISO

Standing security leadership for organizations that need the function but not the salary. Board reporting, vendor review, incident readiness.

A governance engagement, concretely

The most requested piece of this practice is a full AI governance framework. It runs about ten weeks on a fixed rhythm, so you always know what week you're in and what has to be true to move on.

PhaseWeeksWhat happens
Discovery1–2Stakeholder interviews, AI and system inventory, maturity assessment, gap analysis
Design3–6Principles, risk tiering model, roles and RACI, review gates, compliance mapping
Validation7–9Framework piloted against 3–5 real systems, stakeholder review, refinement
Handoff10Documentation, training, implementation playbook, measurement baseline

Shorter engagements — a single system assessment, a compliance gap review — are scoped independently.

What usually triggers the call

  • A customer's due-diligence questionnaire arrived with security or AI questions on it
  • The board or an investor asked how risk is managed and the answer was thin
  • EU AI Act, SOC 2, or a sector regulator brought a real deadline
  • Shadow AI is spreading and nobody owns the decision rights
  • A near-miss made the exposure concrete
  • A new CTO or CISO arrived with expectations from a prior role

What it isn't

It isn't a checklist, and it isn't a deck of recommendations. The output is something your team operates without us, and the methodology behind it belongs to you.

Where it leads

Security work surfaces the next two questions fairly reliably: something needs to be built or fixed, which is Development, and something needs an owner going forward, which is Managed Services.

Next step

Bring us the deadline you're staring at.

A 45-minute call, no cost and no deck. We'll tell you honestly what it would take, and whether you need us to do it.

Book a discovery call