Cyber Services
A fractional CISO practice and four adjacent programs — built around a diagnostic that started with 400+ program evaluations across nearly every vertical. Hourly, scoped to what you actually need, delivered by the same principal for the length of the engagement.
Primary practice
Framework-anchored AI governance assessments for NIST AI RMF, EU AI Act, and ISO/IEC 42001.
Right for: organizations building, deploying, or governing AI and needing a scored posture across a recognized framework — with a report they can act on, not a slide deck.
See AI Readiness assessments & pricing →Flagship
Executive security leadership sized to your organization. Program strategy and oversight, board risk advisory, team leadership, third-party risk governance, and incident response readiness — delivered by a working CISO, not a junior consultant with a template.
Right for: organizations that need the CISO role but not the CISO salary — typically 50 to 500 employees, or larger organizations bridging a transition.
See the fractional CISO practice →What's included
Program services
Program development
Build the program from scratch, or restructure an existing one — policy, controls, roles, metrics, and the evidence base an auditor will want to see. Anchored to your governing framework, not to a proprietary checklist.
Learn more →
Audit & certification
Pre-audit assessments, gap remediation, and audit-day support for SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST frameworks. Get to the finish line with fewer findings and less rework.
Learn more →
Governance & privacy
Governance, risk, and compliance programs; enterprise data privacy under GDPR, CCPA/CPRA, HIPAA, and emerging state regimes. Turn compliance from a fire drill into an operating capability.
Learn more →
Resilience
BC/DR strategy, plans, and exercises — including the ransomware-era question of what you actually do when the primary environment is compromised. Tabletop through full failover.
Learn more →
How we work
Every engagement begins with a free 25-minute consultation and, if it fits, a short scoping conversation to set the hourly rate for the work. Rates are set at engagement start and do not change over the course of it.
Fractional CISO engagements typically run 20 to 60 hours a month. Program work is scoped to deliverables. Audit support is measured by the audit's own calendar. You know what you're paying for before you commit.
Tell us what you're trying to solve. We'll tell you honestly whether we're the right fit.