04
Service 04Program development · Risk · vCISO

Security Program & Risk

We build and run security programs that work in practice and meet the expectations of auditors and regulators.
At a glance
Typical engagement3–12 months
Engagement shapesRetainer · Project · vCISO
Led bySenior security leader
OutputSecurity program and reporting
§ 01Overview
Security Program & Risk

Governance, risk, and compliance with an engineering approach. Programs are designed by practitioners with hands-on technical experience, based on your organization's actual risks.

§ 02What's included

What the service covers.

Engage any item on its own, or combine them into a single engagement.
01
Virtual CISO (vCISO)
Senior security leadership at an agreed scope: strategy, priorities, hiring, and board communication.
02
Security program development
We establish a security program from the ground up or bring an existing one to the required level of maturity.
03
Risk assessment
A systematic assessment of your organization's actual risks, quantified so leadership can make decisions about priorities.
04
SOC 2 and ISO 27001 readiness
Gap analysis, control implementation, and support through the audit, up to the report or certificate.
05
Board and auditor reporting
The security posture presented clearly and measurably, in a form suited to boards and auditors.
06
Tabletop exercises
Structured incident response exercises with the people who would actually run the incident.
§ 03How we approach it

A clear methodology, every time.

1
Assess
We establish your current posture against the frameworks and threats relevant to your organization.
2
Plan
A prioritized plan tied to the organization's risks and business goals.
3
Implement
We introduce controls, policies, and processes in cooperation with your team.
4
Operate and report
Ongoing program operation and regular reporting to the board and auditors.
§ 04What you get

Results you can act on.

Every engagement ends with documented findings and evidence, written for the technical team and for the board.
01Security strategy with a prioritized plan
02Risk register with quantified exposure
03Policies, standards, and control set
04Audit-ready documentation and evidence
05Board-level reports

Independent and vendor-neutral. We don't resell the tools we test.

Our only product is expertise and evidence, so our advice has no agenda but yours.
Independent
Vendor-neutral. No licences to sell, no conflicts of interest.
Senior-led
Every engagement is run by senior engineers, not handed to a queue.
Evidence-led
Reproducible findings and documented proof, not severity labels.
Regulator-ready
Built to satisfy NIS2, DORA, ISO 27001, and GDPR by design.
FAQ

Questions, answered

What does a security program engagement include?
Establishing the risk management, policies, and controls a regulated company needs, verified through testing. A program set up this way also satisfies audit requirements.
Is compliance the same as security?
No. Compliance confirms that a control exists; security confirms that it holds under a real attack. We build the program primarily for security, and compliance is the result of a system set up that way.
Can you prepare us for a specific framework?
Yes. We assess your posture against NIS2, DORA, ISO 27001, SOC 2, or the EU AI Act, close the identified gaps, and prepare the documentation for the audit.
Do you stay involved after the program is built?
Yes, through a retainer. We adapt the program on an ongoing basis to new threats, new systems, and new regulatory obligations.

Ready to scope security program & risk?

Our team will help you define the scope on a 30-minute call.
Book a scoping call or email contact@raptoric.com