No defensible risk picture
Leadership cannot answer what the top five risks are or what is being done about them. We produce a ranked register tied to business impact, with owners and dates, short enough that it is actually read.
Security advice from someone who has carried the pager. Architecture reviews, risk assessments, and incident response plans written to be executed under pressure, not filed.

There is a large market in security deliverables that nobody uses. A 90-page assessment with a heat map, a policy set copied from a template, an incident response plan whose first step is to call a phone number that was disconnected two reorganizations ago. It satisfies an auditor once and then rots.
This practice produces the opposite: a small number of decisions, each with an owner, a deadline, and a way to verify it happened. We work from your actual architecture, your actual identity provider, and your actual change process. If a recommendation cannot be implemented by your team with the budget and headcount you have, it does not go in the report.
The engagement is led by a CISSP- and CISM-certified consultant with more than thirty years across corporate, private, and individual security work. That range matters more than it sounds. The controls that protect a 4,000-seat enterprise will bankrupt a 30-person company, and the controls that fit a 30-person company will fail an enterprise audit. Knowing which set applies to you is most of the value.
Increasingly, the work is also about AI. Teams are wiring language models into systems of record without a permission model, and the resulting exposure is genuinely new: retrieval corpora that ignore row-level access, agents with write credentials that were never scoped, prompts containing regulated data landing in third-party logs. We assess that surface as a first-class part of the review rather than an appendix.
Leadership cannot answer what the top five risks are or what is being done about them. We produce a ranked register tied to business impact, with owners and dates, short enough that it is actually read.
Orphaned accounts, standing admin rights, service accounts with credentials in code, and no review cadence. Identity is where most real incidents begin, so it is where we start.
A plan exists but has never been exercised. We run a tabletop against a realistic scenario and rewrite the plan based on where it actually broke.
A customer or insurer is demanding SOC 2, ISO 27001, or a security questionnaire response you cannot honestly complete. We close the real gaps and prepare the evidence.
Models now read from systems of record and write into them. We assess retrieval permissions, tool-call scope, prompt retention, and injection paths against the same standard as any other integration.
Critical processes depend on suppliers nobody has assessed. We inventory the dependencies, tier them by impact, and build a proportionate review process you can sustain.
One or two sessions to establish what the business actually cannot afford to lose: revenue-bearing systems, regulated records, contractual obligations, and the specific pressures driving the engagement, whether that is an insurer, a customer, an incident, or a board question. Security work without this context defaults to generic best practice, which is how organizations end up spending money on the wrong controls.
We walk the environment: network and cloud topology, identity provider configuration and conditional access, privileged access paths, endpoint posture, backup and recovery design, logging and detection coverage, and the change process that governs all of it. Findings are recorded with evidence, not assertion, so nothing in the final report is arguable.
Findings become a ranked register scored on likelihood and business impact, then filtered through what your team can realistically execute this quarter. Each item carries a named owner, a target date, and a definition of done. Items we recommend deferring are listed as deferred, deliberately, rather than quietly dropped.
We write or rewrite the response plan around your real escalation chain, then exercise it against a scenario drawn from your environment, commonly ransomware on a file server or a compromised administrative identity. The exercise reliably exposes gaps that no document review finds: missing offline contact lists, backups nobody has restored from, unclear authority to disconnect production.
You get a phased roadmap across the next two to four quarters, the evidence package that supports audit and questionnaire responses, and a recommended review cadence. Where a client wants continuity, we serve as a fractional security advisor on a defined monthly commitment for architecture review, vendor assessment, and board reporting.
Findings scored on impact and likelihood, each with an owner, a target date, and a verification method. Short by design, so it gets used in operating reviews.
Documented current-state topology across network, cloud, identity, endpoint, and backup, with specific gaps called out against a stated target state.
A plan built around your real escalation chain, plus the written results of a tabletop exercise showing what broke and what changed as a result.
The control narratives, diagrams, and artifacts that SOC 2, ISO 27001, insurer questionnaires, and enterprise procurement reviews ask for.
Assessment of model access to systems of record, retrieval permission boundaries, tool-call scope, prompt retention, and injection paths, with mitigations.
Two to four quarters of sequenced work with effort estimates, so budget conversations are grounded in something concrete.
Organizations between 50 and 1,000 employees where security is a part-time responsibility of an IT director who needs senior backup and a defensible plan.
An enterprise customer, insurer, or investor is requiring evidence of a security program on a deadline, and the current answer would not survive scrutiny.
Where models have been given access to customer, financial, or health-adjacent records and nobody has assessed what that access actually permits.
Tell us what is driving the question, whether that is an audit, an insurer, an incident, or an AI deployment nobody has reviewed yet.
Start a conversation