Services
Security work you can hand to an auditor.
Here's what each engagement covers, and who it's built for.
Governance, Risk & Compliance
You need policies people actually follow. You also need evidence you can hand an auditor.
Who it's for
Companies facing a first audit, a customer security review, or a regulator.
What you get
- Policy and standards authoring
- Risk register design and upkeep
- Control mapping to NIST CSF, ISO 27001, SOC 2 and HIPAA
- Audit preparation and evidence collection
- Security awareness program design
Assessments & Advisory
Find out where you stand before a customer or an attacker tells you first.
Who it's for
Teams who suspect they have gaps but can't point at them yet.
What you get
- Security posture assessment
- Gap analysis against the framework you're held to
- Third-party and vendor risk review
- Tabletop exercises for your team
- A remediation roadmap ranked by real risk
Security Architecture & Design
Design it right the first time. Or fix what's already running in production.
Who it's for
Teams building something new, or rebuilding something fragile.
What you get
- Secure system and network design
- Cloud architecture review
- Zero-trust rollout planning
- Network segmentation
- Identity and access design
vCISO / Fractional CISO
You get security leadership without paying for a full-time hire.
Who it's for
Companies that need a security voice in the room, but not every day.
What you get
- Security strategy and roadmap
- Board and executive reporting
- Vendor and tool selection
- Incident response readiness
- Mentoring for your existing team
Not sure which one you need?
That's a normal place to start. Tell me the problem and I'll point you at the right work.