Services
What we do, in detail
Every engagement is scoped to what you need and priced as a monthly retainer or a fixed project. No hourly surprises.
Leadership
Virtual CISO
A senior security leader embedded in your business part-time. Your vCISO owns the security program end to end: policy, risk, vendor review, incident response, board reporting, and the customer questionnaires that land in sales' inbox.
Security program ownership and policy set
Quarterly risk review and executive reporting
Vendor and third-party risk management
Incident response planning and tabletop exercises
Customer security questionnaires and audit liaison
Typical engagement: 2–6 days a month, 12-month minimum.
Leadership
Fractional CTO
Executive technology judgment when you need it, not a full-time salary. Your fractional CTO sets the technology direction, makes the build-versus-buy calls, keeps vendors honest, and gives your engineers — or your outsourced team — a senior person to answer to.
Technology strategy and multi-year roadmap
Budgeting, vendor selection, and contract review
Engineering team oversight and hiring support
Due diligence for acquisitions and investors
Typical engagement: 2–8 days a month, or a fixed project.
Security
Cybersecurity strategy, risk & assessments
You cannot protect everything equally, so we start by finding out what matters most and how exposed it is. Assessments are written for the people who have to act on them, not to pad a binder.
Security posture and gap assessments
Vulnerability scanning and penetration testing coordination
Risk register, treatment plan, and prioritized roadmap
Security awareness training for staff
Typical engagement: fixed-fee assessment, 2–4 weeks.
Compliance
Compliance readiness & security programs
A framework is a description of a working security program. We build the program — controls, evidence, policies, and the habits that keep them true — then walk you through the audit.
Gap analysis against your target framework
Policy and procedure authoring
Control implementation and evidence collection
Auditor selection and audit-day support
Infrastructure
Technology infrastructure
Networks, cloud, identity, and devices — designed to be secure by default and boring to operate. We work alongside your existing IT staff or provider, or take the whole thing on.
Network design, segmentation, and hardening
Cloud architecture and migration (Microsoft 365, Azure, AWS)
Identity, MFA, and endpoint management
Backup, disaster recovery, and business continuity
Security cameras, alarms, and access control, installed
Installs are quoted at a fixed price and can be paid in full or over time. See Financing.
Software
Software & integration
When the software you can buy doesn't fit the way you work, we build the piece that's missing — internal tools, integrations between systems, and automations — with security review built into every release.
Custom internal tools and portals
System integration and data pipelines
Workflow automation
Secure development review for existing products