Services
Each of these is a defined engagement with a deliverable, not open-ended time.
Cyber risk and resilience
- Cybersecurity risk assessment
- An independent read on where the exposure actually is, sized and prioritized so it can be funded or accepted.
- Scope and standard
- What is examined
- What you receive
- Typical duration
- Risk management consulting
- Standing up or repairing the program that decides what gets fixed, what gets accepted, and who signs.
- Program design and operating model
- Control frameworks: NIST, ISO 27001, HITRUST, PCI DSS
- Audit committee and board reporting
- Regulatory and audit readiness
AI assurance
- AI risk management and assurance
- Governance for AI systems already in production, and a defensible answer for the regulator, the auditor and the customer asking how they are controlled.
- Inventory and risk classification of AI systems
- Controls, evaluation and monitoring
- Third-party and model supply chain review
- Alignment and safety review for deployed systems
Executive advisory
- Management and technology consulting
- Working sessions on architecture, build-versus-buy, vendor selection and organizational design, for leaders who want a second opinion from someone with no product to sell.
- Technology and architecture review
- Security organization design
- Vendor and portfolio rationalization
