Services
Assurance that starts with a clear picture and keeps it current.
We do not sell tools or replace your IT provider. We give leadership an independent, evidence-backed view of cybersecurity risk, and we stay with you until the gaps are closed and the proof is on file.
How clients usually move through our services
A clear path from first look to lasting assurance.
Fit call
A short conversation about your business, deadlines, and how technology is managed today.
Baseline
An independent review that shows where you stand and what matters most.
Remediation
Owned, dated, re-tested work that closes the most important gaps.
Ongoing assurance
Regular validation and governance so you stay ready, not just get ready.
The Baseline is a focused engagement that independently evaluates your cybersecurity program, validates key controls, and turns the results into something leadership can act on. It is not a scan report. It is a clear account of your risk, who owns each piece of it, and what to do first.
We work with the people who run your technology, whether that is an MSP or an internal team, and we keep the time we ask of your staff to a minimum.
Discover
Confirm scope, priorities, systems, data, providers, and existing documentation.
Validate
Review evidence and perform approved technical validation on defined systems.
Prioritize
Translate findings into business risk, ownership, and a sensible order of work.
Present
Walk leadership through the results and the decisions they need to make.
What we evaluate
- Security governance, ownership, policies, and risk decisions
- Identity, privileged access, remote access, and user lifecycle
- Network, endpoint, cloud, Microsoft 365, backup, and recovery
- Vulnerabilities, external exposure, logging, and incident response
- Third-party and vendor oversight
- Existing documentation and evidence against the framework that applies to you
What you receive
- Executive risk briefing focused on business impact and required decisions
- Prioritized risk register with severity, owner, target date, and status
- 12-month improvement roadmap sequenced by urgency and effort
- Evidence-readiness index showing what exists, what is missing, and what to keep
- Technical findings appendix for your IT team or MSP
- Findings review meeting and a recommended next-step plan
Findings do not fix themselves, and a report on a shelf changes nothing. Remediation Governance gives your remediation effort an independent owner: someone who keeps every item assigned, dated, and moving, checks the work when it is done, and records the evidence as each item closes.
Your MSP or IT team does the hands-on work. We make sure it gets done, verify it, and keep leadership informed.
What is included
- A remediation plan built from your Baseline or existing findings
- Owners, target dates, and status for every item
- Regular working sessions with your MSP or IT team
- Re-testing of completed items before they are marked closed
- Evidence captured and filed as work is completed
- Documented risk acceptance for anything leadership chooses not to fix
What you end up with
- Your highest-priority risks closed and verified
- A clean record of what was fixed, when, and by whom
- An updated risk register and roadmap
- A clear decision on whether ongoing assurance makes sense for you
Examiners, insurers, and clients increasingly want to see that security is governed continuously, not reviewed once a year. Continuous Cyber Assurance keeps an independent eye on your environment, validates that controls keep working, and maintains the evidence trail as you go.
Every program includes
- Continuous visibility of your external exposure
- Monthly risk and remediation governance with your MSP and leadership
- Periodic control validation on an agreed schedule
- An executive report and an evidence register that stays current
- Agreed re-testing of fixes before they are closed
- An annual risk refresh and a tabletop exercise
Essential Assurance
For a smaller practice with a straightforward environment and an established IT provider.
- Everything in the core program
- Focused on one office, one cloud workspace, and a defined network
- Organized evidence for exams, renewals, and client requests
Assurance Plus
Most commonFor growing firms with more locations, cloud workloads, or governance demands.
- Everything in Essential
- Expanded cloud, identity, and internal control validation
- Quarterly executive strategy sessions
- Vendor risk reviews and policy lifecycle support
- Help with insurer questionnaires
Executive Assurance
For firms that need security leadership, not just assurance.
- Everything in Assurance Plus
- Fractional security leadership (see below)
- Board, audit, and examination support
- Architecture review and incident governance
Some firms need more than validation. They need someone to own the security program at the leadership level: set direction, plan the budget, speak to the board, and stand next to leadership when an examiner or auditor asks hard questions. A full-time CISO is rarely practical at your size. Fractional leadership gives you that experience for the hours you actually need.
What we take on
- Security strategy and a multi-year roadmap
- Security budget planning and prioritization
- Board and leadership reporting
- Audit, examination, and insurer support
- Architecture and major change review
- Incident governance and tabletop exercises
How it works
- A named senior advisor who knows your environment
- A regular leadership meeting rhythm you agree up front
- Direct coordination with your MSP, auditors, and counsel
- Clear, agreed limits on scope and time, so nothing is ambiguous
When you need more depth
Specialist testing, coordinated for you.
Some situations call for formal testing. We scope it, bring in vetted specialists, review the quality of the work, and translate the results for leadership, so you have one accountable partner instead of another vendor to manage.
Available as separately scoped work
- Formal network penetration testing
- Web application and API testing
- Cloud configuration testing
- Incident response and forensic support through qualified partners
All active testing is performed only under written authorization, with an agreed target list, testing windows, rules of engagement, and emergency contacts.
Clear boundaries
What we are, and what we are not.
Not a replacement for your MSP
Your IT provider keeps running and fixing your environment. We make their work visible and verifiable.
Not a tool reseller
We have nothing to sell you but our judgment. Recommendations are based on your risk, not a product catalog.
Not a legal opinion
We provide cybersecurity evidence and governance. Regulatory interpretation stays with your compliance counsel.
Every engagement is scoped to your environment: people, devices, locations, cloud services, applications, and the level of leadership support you need. We confirm scope after a short environment review, so there are no surprises later.