Security and risk programs that are auditable, and actually run.
Essential services cannot afford security programs that exist only on paper. We baseline risk, harden operations, and govern AI, with evidence an auditor can follow.
What it risk & cyber solves
The questions that bring people to us for this work, what is usually behind them, and what we do about it.
“Are we ready for our next audit?”
The problemControls exist in policy, but evidence is scattered and gathered in a rush before each audit.
How we solve itRisk assessments, control design, and continuous evidence collection aligned to NIST, ISO, SOC 2, or HIPAA.
“Would we recover from ransomware?”
The problemBackups are untested, logging is partial, and response plans have never been exercised.
How we solve itIdentity hardening, patch baselines, tested backups, centralized logging, and recovery drills tied to continuity plans.
“Who approved this AI tool, and on what evidence?”
The problemAI tools arrive through vendors and staff faster than anyone can assess them.
How we solve itAI governance: an intake process, pilots with thresholds, and model risk management.
Each answer rests on the same method. Here it is for it risk & cyber.
How we do it
Four steps, in order, with governance designed in from the first one.
Baseline
Risk, operations, and access reviewed; an evidence plan and priorities set.
Harden
Identity, patching, backups, and logging brought to a defensible baseline.
Detect and respond
Detection from cloud and network telemetry, containment playbooks, and recovery drills.
Govern AI
Intake, pilot thresholds, access control, provenance, adversarial testing, and audit logging.
Data governance in this work
Security that cannot be evidenced does not count at audit.
- Coverage of critical assets and control effectiveness, reported to leadership.
- Evidence collected as work happens, not assembled before each audit.
- AI systems held to the same access, logging, and change control as any other system.
What you get
- A risk baseline and prioritized remediation plan
- Control design and an evidence plan
- Exercised incident response playbooks
- An AI governance framework
- A production plan with budget and staffing
A method is only useful once it is running. Here is how it gets there.
Phase by phase, with a gate at each one
Each gate is agreed before its phase begins, so nothing moves forward on optimism.
Baseline
Month one: risk and operations baselines, access reviews, evidence plan, and priority pilots.
Gate: Priorities agreedPilot
Month two: pilot controls with monitoring, playbooks exercised, interim evaluation.
Gate: Controls working in practicePlan
Month three: a production plan with budget, staffing, governance, and measurable targets.
Gate: Plan approved
How it runs
A ninety-day plan to start, aligned to NIST, ISO 27001, SOC 2, or HIPAA as your obligations require.
Where we do this work
Technical detail
Risk & compliance
- NIST, ISO, SOC 2, and HIPAA alignment
- Risk assessments and control design
- Audit readiness, remediation plans, and evidence collection
Security operations
- Identity hardening and patch baselines
- Tested backups and centralized logging
- Detection and response from cloud and network telemetry
- Containment playbooks and recovery drills
AI governance
- Opportunity intake weighing benefits, constraints, and equity
- Pilots with accuracy, latency, and cost thresholds and rollback criteria
- Model risk management: access control, provenance, adversarial testing, audit logging
Tell us which audit or incident worries you most.
We will baseline where you stand and give you an auditable plan to close the gaps.
