Whoever built your security program, and whether or not that was us, this establishes on an agreed cycle that it still operates within the boundaries it set for itself, and reports that to you rather than to whoever did the work.
The problem this solves
A program is defined once: controls in scope, thresholds, owners, review cadences, the actions agreed. Then work starts, some of it finishes, the environment moves, and the only person reporting on any of it is the person doing it. That is not a criticism of any team. It is what happens without somebody outside the work looking at it on a schedule.
Who buys this
A program exists, your team wrote it, and nobody outside has ever looked at whether it operates the way it is written. Often the honest answer is that most of it does, and knowing which part does not is the whole value.
A consultancy, an MSP or a fractional CISO delivered a program against stated objectives. This establishes whether what was delivered is what is running, and whether it still is a year later. We report to you, not to them.
Findings were raised, actions were agreed, and the assessment itself is now a document about the past. This picks up from the criteria that were set and confirms what has actually closed since.
A customer, an insurer or a board wants current evidence rather than a report with last year's date on it. A cycle produces a dated statement of what is operating and what is not.
What a cycle contains
A defined part of the program checked against the boundaries it set for itself: the controls in scope, the thresholds and review cadences your own policies commit to, and any actions agreed since. Recorded as operating, partially operating, or not evidenced, with the evidence behind each.
A working session with your sponsor and your IT provider or team. Decisions, blockers and next actions.
Risk register and action tracker kept current. Documentation updated as your business or the framework changes.
Progress, overdue items, what needs a decision from you, and next cycle's priorities.
Continuing access for your team, with completion recorded.
Every third cycle the session widens to cover the program as a whole rather than individual actions.
This is a scheduled service. We do not monitor your systems, we do not receive your alerts, and we do not provide out-of-hours response.
Commercial terms
Monthly suits an active roadmap with a lot moving. Quarterly suits a settled program where the question is whether anything has drifted. We agree which at scoping, in writing, and then it is fixed like everything else: the cycle does not change without your agreement, and neither does the fee.
Long enough to be worth starting, short enough that you are not committed to something you cannot judge yet.
We review at the end of the initial term so you can decide whether the work is worth the cost. Cycle by cycle after that, 30 days' notice.
We do not propose this where no program exists yet. A retainer with nothing to check is a meeting you are paying for, and if you are starting from nothing an assessment is the thing that helps.
When to buy this
You do not need to have worked with us before. If your program was written by your own team, by a consultancy or by a provider you already pay, this establishes whether it operates the way it is written and keeps establishing it. Where we did the original assessment, the criteria are already set and a cycle starts from them.