Compliance & Audit Readiness
Ready for the audit, not just papered for it.
Read the scopeRetained advisory
Ongoing advisory for organizations that need senior security input on architecture, tooling and risk without hiring a full-time security leader.
Service
InfoSec Consulting
Engagement
Retained advisory
Retainer
8, 16 or 32 hours a month
The problem
Below a certain size there is no security function. Decisions get made by whoever is closest. A vendor recommends a tool, an engineer picks a default, a questionnaire gets answered optimistically. None of it is wrong on purpose. It is just unowned, and the gaps only become visible in an incident or an audit.
Scope
Anything outside this list is quoted separately rather than absorbed quietly.
Deliverables
Every item here is an artifact you own, in your systems, readable by someone who was not in the room.
Maintained, prioritized, and reviewed on a cadence. Not a one-time spreadsheet.
Written findings on each system reviewed, with the decision recorded either way.
What you can currently detect, what you cannot, and what it would take to close the difference.
Rehearsed in a tabletop with your team, not filed unread.
Retainer: 8, 16 or 32 hours a month
Three-month minimum. The first month is assessment. Every tier includes a monthly review call, a maintained risk register and a reply within one business day. The fee is quoted against your scope.
Fit
We would rather lose the engagement at this paragraph than three weeks in.
A good fit if
Not a fit if
Questions
Functionally that is what it is, and most buyers searching for a vCISO are describing this engagement. We avoid the title because it promises an officer of the company, and a retained advisor is not that. What you get is senior security judgment on a defined cadence, with the decisions written down and a risk register that stays current. What you do not get is someone who will sit in every meeting or carry a pager.
No, and you should be cautious of anyone who both designs your controls and tests them. We will scope the test, help you select an independent firm, and then own remediation of what they find.
Usually yes, and it is a common way engagements start. Be aware that answering the questionnaire honestly often surfaces work you had not planned. We would rather find that now than during the customer audit.
Often paired with
These are the combinations that come up most often, not an upsell list.
Ready for the audit, not just papered for it.
Read the scopeClose the gaps, and prove they are closed.
Read the scopeAn estate you can rebuild from source.
Read the scopeInfoSec Consulting
Tell us what the environment looks like today. We will tell you what we would change first, and whether this is the right engagement for it.