Security and risk programs that are auditable, and actually run.

Essential services cannot afford security programs that exist only on paper. We baseline risk, harden operations, and govern AI, with evidence an auditor can follow.

What it risk & cyber solves

The questions that bring people to us for this work, what is usually behind them, and what we do about it.

  • “Are we ready for our next audit?”

    The problem

    Controls exist in policy, but evidence is scattered and gathered in a rush before each audit.

    How we solve it

    Risk assessments, control design, and continuous evidence collection aligned to NIST, ISO, SOC 2, or HIPAA.

  • “Would we recover from ransomware?”

    The problem

    Backups are untested, logging is partial, and response plans have never been exercised.

    How we solve it

    Identity hardening, patch baselines, tested backups, centralized logging, and recovery drills tied to continuity plans.

  • “Who approved this AI tool, and on what evidence?”

    The problem

    AI tools arrive through vendors and staff faster than anyone can assess them.

    How we solve it

    AI governance: an intake process, pilots with thresholds, and model risk management.

Each answer rests on the same method. Here it is for it risk & cyber.

How we do it

Four steps, in order, with governance designed in from the first one.

  1. Baseline

    Risk, operations, and access reviewed; an evidence plan and priorities set.

  2. Harden

    Identity, patching, backups, and logging brought to a defensible baseline.

  3. Detect and respond

    Detection from cloud and network telemetry, containment playbooks, and recovery drills.

  4. Govern AI

    Intake, pilot thresholds, access control, provenance, adversarial testing, and audit logging.

Data governance in this work

Security that cannot be evidenced does not count at audit.

  • Coverage of critical assets and control effectiveness, reported to leadership.
  • Evidence collected as work happens, not assembled before each audit.
  • AI systems held to the same access, logging, and change control as any other system.

What you get

  • A risk baseline and prioritized remediation plan
  • Control design and an evidence plan
  • Exercised incident response playbooks
  • An AI governance framework
  • A production plan with budget and staffing

A method is only useful once it is running. Here is how it gets there.

Phase by phase, with a gate at each one

Each gate is agreed before its phase begins, so nothing moves forward on optimism.

  1. Baseline

    Month one: risk and operations baselines, access reviews, evidence plan, and priority pilots.

    Gate: Priorities agreed
  2. Pilot

    Month two: pilot controls with monitoring, playbooks exercised, interim evaluation.

    Gate: Controls working in practice
  3. Plan

    Month three: a production plan with budget, staffing, governance, and measurable targets.

    Gate: Plan approved

How it runs

A ninety-day plan to start, aligned to NIST, ISO 27001, SOC 2, or HIPAA as your obligations require.

Technical detail

Risk & compliance

  • NIST, ISO, SOC 2, and HIPAA alignment
  • Risk assessments and control design
  • Audit readiness, remediation plans, and evidence collection

Security operations

  • Identity hardening and patch baselines
  • Tested backups and centralized logging
  • Detection and response from cloud and network telemetry
  • Containment playbooks and recovery drills

AI governance

  • Opportunity intake weighing benefits, constraints, and equity
  • Pilots with accuracy, latency, and cost thresholds and rollback criteria
  • Model risk management: access control, provenance, adversarial testing, audit logging

Tell us which audit or incident worries you most.

We will baseline where you stand and give you an auditable plan to close the gaps.

Talk to us

How we advise