You end with a documented security program, tailored to your organization, operating in your business rather than filed, staffed by people trained to run it, and backed by evidence that the controls work.
Who this is for
This is the engagement to buy when a customer has sent a security questionnaire, an insurer is asking for specifics at renewal, a board wants to know what protects the business, or you have inherited a set of policies describing an organization you are not.
01
Security happens, mostly, but none of it is written down and nobody could evidence it to a third party.
02
Policies downloaded years ago that reference systems you do not own. Worse than nothing in front of an assessor.
03
Somebody assessed you once, the findings were filed, and nobody can say what was actually closed.
The five stages
We establish what is actually in place, against evidence rather than assertion. Where the scale allows we inspect complete populations rather than samples: privileged accounts, leavers, mailbox rules and authentication records are all small enough in an organization of your size to review entirely, and a full population stands up far better when a customer audits you.
Where evidence cannot be produced we record the control as unproven and report it as a finding. That is not a criticism of anyone, it is the standard we apply everywhere.
We deploy a documentation set and tailor every document to your industry, your regulatory position, your risk profile and your technology stack. Not a template with your logo on it.
You receive editable files. There is no platform to stay subscribed to just to keep your own policies, and updates are included.
We work with your IT provider or internal team to turn documents into operating controls, with an owner and a date against each action. We specify precisely what needs doing; they carry it out.
We do not configure your systems. If we found the problem and then sold you the fix, our findings would be worth less to you and to anyone you showed them to.
Your staff take the courses relevant to their role, across governance, incident response and security operations, with hands-on labs and recorded completion. Documentation proves the program exists; training builds the capability to run it.
We confirm each agreed action is genuinely closed against the verification criterion set at assessment. A message saying the work is done is not sufficient.
This is the stage most engagements leave out, and it is the reason roadmaps decay.
Scope options
123 core controls. The set selected for what most often fails and most often matters. Suited to an organization building a program from nothing, or establishing a baseline before deciding how far to go.
All 242 controls, complete framework coverage, plus the framework-specific documentation for the standard you are being judged against. Suited to an organization with a board, an internal IT or security function, or a specific standard to meet.
Both are quoted as a fixed fee against an agreed scope: one legal entity, one primary email and file platform, and a defined number of sites and applications settled before we begin. Nothing is billed hourly and the scope does not move without your written agreement. Additional entities, sites or applications are quoted separately.
What you receive
What was assessed and what was not, written so a customer or regulator knows exactly what the report covers.
Every item examined, with its date, source, the population it covered and any limitation on it.
Each control rated against the evidence rather than against an opinion.
Findings expressed as business consequences, ranked, each with a named owner.
Actions, owners, dates, and the criterion that says how each will be verified as done.
What was found, what it means commercially, and what needs a decision from you.
Boundaries
We do not configure systems, deploy software or make changes. Your IT provider or internal team does the work.
Testing, code review and red teaming are separate specialties. We scope the brief, review the report and drive findings to closure.
We are not a monitoring service and we do not provide out-of-hours incident response.
Legal advice is also excluded. Where an obligation needs interpreting, that is a matter for your attorney, and we will identify where advice is needed.
Before you buy anything
Take the free readiness assessment, send us the result, and we will spend forty-five minutes going through it with you at no charge. If our honest view is that you do not need this engagement yet, we will say so.