Service 01 · Fixed scope, fixed fee, fixed end date

Security Program Deployment

You end with a documented security program, tailored to your organization, operating in your business rather than filed, staffed by people trained to run it, and backed by evidence that the controls work.

Framework
NIST CSF 2.0
Scope
123 or 242 controls
Ends with
Report, roadmap, briefing
Fee basis
Fixed on agreed scope

Who this is for

Somebody outside the business has asked for proof

This is the engagement to buy when a customer has sent a security questionnaire, an insurer is asking for specifics at renewal, a board wants to know what protects the business, or you have inherited a set of policies describing an organization you are not.

01

You have nothing documented

Security happens, mostly, but none of it is written down and nobody could evidence it to a third party.

02

You have templates

Policies downloaded years ago that reference systems you do not own. Worse than nothing in front of an assessor.

03

You have a report that went nowhere

Somebody assessed you once, the findings were filed, and nobody can say what was actually closed.

The five stages

What we actually do

1

Assess

We establish what is actually in place, against evidence rather than assertion. Where the scale allows we inspect complete populations rather than samples: privileged accounts, leavers, mailbox rules and authentication records are all small enough in an organization of your size to review entirely, and a full population stands up far better when a customer audits you.

Where evidence cannot be produced we record the control as unproven and report it as a finding. That is not a criticism of anyone, it is the standard we apply everywhere.

  • Control assessment against the selected set
  • Evidence register with dates, populations and limitations
  • Prioritized risk register with named owners
2

Document

We deploy a documentation set and tailor every document to your industry, your regulatory position, your risk profile and your technology stack. Not a template with your logo on it.

You receive editable files. There is no platform to stay subscribed to just to keep your own policies, and updates are included.

3

Implement

We work with your IT provider or internal team to turn documents into operating controls, with an owner and a date against each action. We specify precisely what needs doing; they carry it out.

We do not configure your systems. If we found the problem and then sold you the fix, our findings would be worth less to you and to anyone you showed them to.

4

Train

Your staff take the courses relevant to their role, across governance, incident response and security operations, with hands-on labs and recorded completion. Documentation proves the program exists; training builds the capability to run it.

5

Verify

We confirm each agreed action is genuinely closed against the verification criterion set at assessment. A message saying the work is done is not sufficient.

This is the stage most engagements leave out, and it is the reason roadmaps decay.

Scope options

Two sizes

Foundation

123 core controls. The set selected for what most often fails and most often matters. Suited to an organization building a program from nothing, or establishing a baseline before deciding how far to go.

123 controlsOne verification roundGovernance and awareness training
Fixed fee, quoted on scopeGet a quote →

Full Program

All 242 controls, complete framework coverage, plus the framework-specific documentation for the standard you are being judged against. Suited to an organization with a board, an internal IT or security function, or a specific standard to meet.

242 controlsVerification through 90 daysRole-based training paths
Fixed fee, quoted on scopeGet a quote →

Both are quoted as a fixed fee against an agreed scope: one legal entity, one primary email and file platform, and a defined number of sites and applications settled before we begin. Nothing is billed hourly and the scope does not move without your written agreement. Additional entities, sites or applications are quoted separately.

What you receive

Six documents you can show anyone

Scope and limitations

What was assessed and what was not, written so a customer or regulator knows exactly what the report covers.

Evidence register

Every item examined, with its date, source, the population it covered and any limitation on it.

Control assessment

Each control rated against the evidence rather than against an opinion.

Risk register

Findings expressed as business consequences, ranked, each with a named owner.

Ninety-day roadmap

Actions, owners, dates, and the criterion that says how each will be verified as done.

Executive briefing

What was found, what it means commercially, and what needs a decision from you.

Boundaries

What is not included

Implementation

We do not configure systems, deploy software or make changes. Your IT provider or internal team does the work.

Penetration testing

Testing, code review and red teaming are separate specialties. We scope the brief, review the report and drive findings to closure.

Monitoring and response

We are not a monitoring service and we do not provide out-of-hours incident response.

Legal advice is also excluded. Where an obligation needs interpreting, that is a matter for your attorney, and we will identify where advice is needed.

Before you buy anything

Score where you stand first. It costs nothing.

Take the free readiness assessment, send us the result, and we will spend forty-five minutes going through it with you at no charge. If our honest view is that you do not need this engagement yet, we will say so.