We offer a wide variety of services to help businesses of all stages achieve extraordinary results
Whether the requirement comes from a DoD contract, a banking examiner, a healthcare partner, or a customer’s security questionnaire, the path is the same: understand what binds you, find the gaps, close them, and prove it. We run that path with you across CMMC, NIST 800-171, NIST CSF, GLBA, FFIEC, and HIPAA, and we build it so the compliance outcome rests on a security program that actually operates.
Small and medium organizations facing a framework for the first time: defense contractors and subcontractors, community banks and credit unions, healthcare practices and their business associates, colleges and K-12 districts handling regulated data, and any business whose customers have started asking hard questions. Also the teams that attempted compliance internally and stalled, and the ones whose last assessment produced findings that never quite got closed. If you are not sure which framework even applies, that is a normal starting point and the first thing we resolve.
Frameworks are written in control language, not business language. Internal teams burn months interpreting requirements, guessing at scope, and producing documentation that does not survive first contact with an assessor. Meanwhile the contract clock or the exam date keeps moving, and the quiet cost compounds: the deal that went to a certified competitor, the finding that becomes a repeat finding, the questionnaire that stalls a sale. The failure mode is almost never effort. It is effort pointed at the wrong gaps, documented the wrong way.
Q. We do not know which framework applies to us. Can you still help?
Yes, and this is one of the most common starting points. The first working session maps your contracts, industry, data types, and customer commitments to the frameworks that actually bind you. The honest answer is often narrower than feared, and knowing your real obligations is itself a cost-saving outcome.
Q. How long does readiness take?
It depends on your starting posture and scope. A focused gap assessment runs weeks; full remediation for a first-time program typically runs months. The roadmap gives you the honest timeline up front, and every engagement is fixed-scope, so the calendar and the cost are known before we start.
Q. Can you work with our existing IT provider?
Yes, and we usually should. Most of our clients have a managed service provider running day-to-day IT. We define the controls and documentation, coordinate the technical implementation with your MSP, and verify the result. The division of labor is clean, and your MSP usually appreciates having requirements in writing.
Q. We already failed an assessment or exam. Is that harder to fix?
Usually easier. A findings list is a head start: the gaps are named, the pressure is real, and leadership is paying attention. We triage the findings, fix them in the order that matters, and build the evidence trail that shows the examiner or assessor a program that responded.
Who this is for
Organizations at every maturity level. First-timers formalizing what has lived in people’s heads. Established programs that need an independent, annual, or post-change assessment: new systems, acquisitions, cloud migrations, new facilities, or a significant incident. Regulated businesses whose framework mandates periodic risk assessment, which is nearly all of them: NIST 800-171, GLBA, FFIEC, HIPAA, and ISO 27001 each demand it. Companies pursuing or maintaining ISO 27001 certification, where the risk assessment is the engine of the entire management system. Institutions and districts holding student data with no one formally accountable for it. And leadership teams that want an outside set of eyes before committing budget, because internal assessments have a way of finding what is comfortable.
The problem
Most organizations sit at one of two failure points. The immature ones manage risk by anecdote: the last incident, the loudest vendor, the scariest headline, which produces spending on the wrong things and silence on the real exposures. The mature ones often have the opposite disease: an aging register that gets rolled forward every year, scored by the same people who own the risks, drifting further from the actual environment with each cycle. Regulators, certifying bodies, and insurers require risk assessments precisely because unexamined and self-examined risk is where breaches live. Either way, the test is the same: an assessment that does not change a decision was not an assessment. It was a receipt.
What is included
What you walk away with
FAQs
Q. Which methodology will you use for us?
The one your obligations point to. NIST SP 800-30 for defense and NIST-based programs, ISO 27005 for ISO 27001 environments, FFIEC guidance for banks and credit unions, HIPAA Security Rule risk analysis for healthcare, CIS RAM where a control-driven approach fits. If you face multiple frameworks, we run one assessment structured to satisfy all of them, which is cheaper than three assessments and more coherent than one forced fit.
Q. We already have a risk register. Do we start over?
No. An existing register is an asset, and an independent refresh is often more valuable than a rebuild: we validate the scoring, retire what no longer reflects the environment, add what has emerged, and challenge the assumptions that got inherited year over year. You keep continuity; the register regains credibility.
Q. How often should we do this?
Annually is the cadence most frameworks and certification bodies expect, plus after major changes: new systems, acquisitions, facility moves, or significant incidents. The first assessment is the heavy lift; refreshes are faster because the register already exists.
Q. Is this a penetration test?
No. A penetration test attacks your systems to find technical weaknesses; a risk assessment evaluates your whole exposure, including the administrative and physical controls a pen test never touches. Many clients do both, and the risk assessment tells you whether a pen test is even the priority yet.
Policies your team will follow and your assessor will accept
Every framework demands documented policies, and every assessor reads them first, then tests you against your own words. We write right-sized policy sets mapped to your framework and your actual operations, so the documents describe what you really do and the assessor can verify it.
Organizations with no formal policies. Companies running on templates downloaded years ago that no longer match reality. Businesses whose assessment, exam, or customer due diligence flagged documentation gaps. And increasingly, firms facing acquirers and enterprise customers who ask to see policies before signing; a credible set answers that request in one attachment.
The two classic failure modes are opposites. No policies is an automatic finding under every framework. But the 400-page template pack describing an enterprise you are not is worse, because assessors test you against your own policies: every control your documents claim and your operations lack is a finding you manufactured yourself. The goal is a lean set that says what you actually do, says it in framework language, and can be maintained by a business your size without a compliance department.
Q. Can you just sell us templates?
We do not, because templates are what create findings. Everything we deliver is drafted for your environment, which takes modestly longer and survives assessment. If budget is the constraint, we would rather scope a smaller accurate set than a large generic one.
Q. How long does a full policy set take?
For a typical SMB, a few weeks including your review cycles. The pacing is usually set by how quickly your leadership can review drafts, and we structure the reviews to respect your calendar.
Q. Our framework changed, or a new one was added. Do we start over?
Rarely. Well-built policies map to control families that overlap heavily across frameworks. Adding HIPAA to a NIST-based set, or extending toward a new customer requirement, is an update exercise, not a rebuild.
Ready before the bad day
When an incident hits, the plan is the difference between a controlled response and an expensive improvisation. We build incident response plans and playbooks sized to your organization, then pressure-test them with your team in facilitated tabletop exercises, because an untested plan is a theory.
Businesses with no written incident response plan. Organizations whose framework requires one plus periodic testing: CMMC, GLBA, FFIEC, and HIPAA all do. Companies whose cyber insurance now demands documented response capability at renewal. Schools and districts that would face parents and press within hours of an incident. And teams with a plan on paper that has never once been rehearsed, which describes most plans.
In a real incident the questions arrive faster than answers: who declares it, who calls the insurer and the lawyer, when do notification clocks start, who is authorized to take systems offline, who speaks to customers, and who decides about ransom. Organizations answering those questions for the first time during the incident pay for the delay in downtime, legal exposure, and trust. Defense contractors carry an extra layer: DoD incident reporting obligations with tight timelines that most subcontractors discover too late, and regulated industries carry notification duties with real deadlines. The plan costs a fraction of the improvisation.
Q. What does a tabletop exercise look like?
A facilitated session, typically two to three hours, walking your team through a realistic scenario in stages while we inject complications as it unfolds. No systems are touched. The value is watching your actual people make actual decisions and finding the gaps safely.
Q. We are small. Do we really need playbooks?
Small organizations need them more, because the same three people wear every hat during an incident. A playbook means the person handling it at 2 a.m. follows a checklist instead of reconstructing one.
Q. Can you help during a real incident? Our focus is preparation, and vCISO clients get priority advisory support when something happens. For hands-on forensic response we help you pre-select and pre-contract a response firm before you need one, which is itself a step in the plan, because incident-day procurement is the most expensive kind.
A security executive in your corner, at a fraction of the cost
A full-time CISO costs more than most SMBs can justify. The need for one does not care. Our vCISO retainers give you an experienced, certified security leader who owns your program: strategy, risk, compliance posture, vendor oversight, and the credibility to face your customers, examiners, and board.
Businesses that finished the initial compliance push and need someone to own the program going forward. Organizations whose customers, regulators, or insurers expect a named security leader. Companies making security-relevant decisions, cloud moves, new vendors, acquisitions, new markets, without an expert at the table. Districts and colleges where security accountability currently lives with whoever has the least room to refuse it. And any firm tired of security falling into the gap between the IT provider and the owner.
Security is a posture, not a project. After the assessment ends and the policies are signed, someone has to keep controls operating, review the vendors, answer the questionnaires, brief leadership, watch the threat picture, and adjust as the business changes. In most SMBs that someone is nobody, and the posture decays quietly until the next audit, incident, or renewal rediscovers everything at once. The alternatives are a full-time hire the budget cannot carry, or an MSP whose incentives stop at the infrastructure it manages. Neither is governance.
Q. How is this different from our MSP?
Your MSP operates infrastructure; a vCISO governs risk. The MSP answers to tickets, the vCISO answers to your business, and often oversees the MSP: setting requirements, reviewing controls, and verifying the security you assume you are getting. The roles complement rather than compete, and the separation is itself good governance.
Q. What does a retainer include?
Retainers are scoped to your size and obligations: a set cadence of working sessions, defined program responsibilities, and advisory access in between, fixed in the engagement letter so the boundaries are clear on both sides. We scope it in the first conversation.
Q. Can the vCISO represent us to customers and examiners?
Yes, and it is often the most immediately valuable part: a certified security leader answering your customers’ questionnaires, joining their vendor calls, and sitting beside you through exams and assessments.
The human layer and the physical layer, handled
Two control families get neglected in every SMB security program: the people and the premises. Both are required by every framework you are likely to face, both are where assessors look early, and both are areas where we go past advice to delivery: training your workforce, and installing the physical controls the framework demands.
Organizations whose framework requires awareness training and physical protections, which is all of them: NIST 800-171, CMMC, GLBA, FFIEC, and HIPAA include both. Businesses that failed, or fear failing, these control families in assessment. Schools and offices where the server closet doubles as storage and nobody owns the camera system. And companies opening or refitting facilities that want cameras, access control, and endpoints specified right the first time instead of retrofitted after a finding.
Awareness training is usually a checkbox: an annual video nobody remembers, purchased to generate a completion report, while phishing remains the front door for most breaches. Physical security has the opposite problem: it is concrete and visible, but it sits in a gap, too security for the electrician and too physical for the IT provider, so cameras point the wrong way, badge lists never get reviewed, server rooms stay unlocked, and the assessor writes it up during the walkthrough. Both layers deserve the same rigor as the firewall, because attackers do not respect the org chart that neglected them.
Q. Why does a compliance firm install cameras?
Because physical protection is a control family, not a side errand. When the firm that maps your requirements also specifies and installs the controls, nothing is lost in translation between the framework language and the hardware, and the assessor sees one coherent story.
Q. How often does training need to happen?
Most frameworks expect training at onboarding and at least annually, with records retained. We recommend lighter, more frequent touchpoints over one annual marathon, because the goal is recognition under pressure, not attendance.
Q. Do you resell specific hardware brands?
We specify what fits your environment, budget, and compliance requirements, and we are not locked to a vendor. Where we install, we quote transparently; where you have a preferred supplier, we work with them.