Skip to content

Services

Security work you can hand to an auditor.

Here's what each engagement covers, and who it's built for.

Governance, Risk & Compliance

You need policies people actually follow. You also need evidence you can hand an auditor.

Who it's for

Companies facing a first audit, a customer security review, or a regulator.

What you get

  • Policy and standards authoring
  • Risk register design and upkeep
  • Control mapping to NIST CSF, ISO 27001, SOC 2 and HIPAA
  • Audit preparation and evidence collection
  • Security awareness program design

Assessments & Advisory

Find out where you stand before a customer or an attacker tells you first.

Who it's for

Teams who suspect they have gaps but can't point at them yet.

What you get

  • Security posture assessment
  • Gap analysis against the framework you're held to
  • Third-party and vendor risk review
  • Tabletop exercises for your team
  • A remediation roadmap ranked by real risk

Security Architecture & Design

Design it right the first time. Or fix what's already running in production.

Who it's for

Teams building something new, or rebuilding something fragile.

What you get

  • Secure system and network design
  • Cloud architecture review
  • Zero-trust rollout planning
  • Network segmentation
  • Identity and access design

vCISO / Fractional CISO

You get security leadership without paying for a full-time hire.

Who it's for

Companies that need a security voice in the room, but not every day.

What you get

  • Security strategy and roadmap
  • Board and executive reporting
  • Vendor and tool selection
  • Incident response readiness
  • Mentoring for your existing team

Not sure which one you need?

That's a normal place to start. Tell me the problem and I'll point you at the right work.