Security program development
Building a security program from whatever you have now: governance structure, policy, risk management process, and a roadmap that is sequenced by risk and budget rather than by what a framework happens to list first.
Engagement model
Not a separate service, but a different way to buy the ones above. Security leadership and specialist capacity, embedded in your team rather than delivered as a project.
Most organizations that need a Chief Information Security Officer do not need one five days a week, and cannot justify the salary to find out. The same applies to specialist skills you need continuously but not constantly: cloud engineering, compliance management, incident response.
This is an engagement model rather than a distinct capability. The work is the same work described elsewhere on this site. What differs is that it is delivered by someone embedded in your organization over time, who attends your meetings and knows your environment, rather than through a scoped project with a start and end date.
What we do
Building a security program from whatever you have now: governance structure, policy, risk management process, and a roadmap that is sequenced by risk and budget rather than by what a framework happens to list first.
Response planning, tabletop exercises, and leadership during an actual incident. The planning matters more than it appears to. Organizations that have rehearsed make materially better decisions in the first few hours, which is when most of the damage is determined.
Ongoing ownership of a compliance program rather than a point-in-time readiness project: maintaining evidence, tracking remediation, handling customer questionnaires, and keeping documentation current as the environment changes.
See also: Compliance Readiness
Training built for your organization and the specific obligations it carries, rather than a generic annual video. Required by most frameworks, and one of the few controls where doing it well is noticeably different from doing it at all.
Assessment of security risk across the organization, expressed in terms a board can act on (what the exposure is, what it would cost, and what reducing it requires) rather than as a list of technical findings.
Monitoring and interpretation of threats relevant to your sector and your organization specifically, filtered down to the small proportion that should actually change what you do.
Ongoing oversight of the environment rather than an annual look: watching for the conditions that matter, keeping control evidence current, and reporting at a cadence you can put in front of a prime or a board. Most compliance programs fail between assessments rather than during one.
The defensive side of the same question the testing practice asks. Whether the logging exists, whether anyone is watching it, and whether the response would work under time pressure. We assess and improve what you have rather than running your security operations for you.
See also: Penetration Testing
Vetted security, IT, and hardware specialists embedded in your team for the duration of a project or a gap. Sourced from the same network that supports our consulting work, which means candidates have been assessed by people who do the job rather than by a keyword match against a resume.
Process
Understand the current program, the obligations driving it, and the gap between them. Usually two to three weeks.
Agree the commitment: days per month, which meetings, what decisions sit with us and what stays with you.
A sequenced plan tied to risk and budget, so progress is visible to leadership and defensible to customers.
Ongoing delivery against the roadmap, with the deeper project work drawn from the practices described elsewhere on this site when it is needed.
Regular reporting written for your board and your customers, not for us.
Deliverables
Every engagement produces documentation you can hand to an auditor, a customer, or your own board without translating it first.
FAQ
Most organizations that need a Chief Information Security Officer do not need one five days a week, and cannot justify the salary to find out. This is the same work delivered by someone embedded in your organization over time, who attends your meetings and knows your environment.
It is an engagement model rather than a distinct capability. The work is the work described elsewhere on this site.
Agreed up front as part of defining the engagement: days per month, which meetings, what decisions sit with us and what stays with you. Writing that down is what stops a fractional arrangement becoming an ambiguous one.
You hire, and a functioning programme with a documented roadmap is a considerably easier thing to hand over than a set of assumptions.
Handover is a normal outcome rather than a failure of the arrangement.
Engagements typically run from a few days a month upward, depending on what is driving the need.