§ 01Overview
Security Program & Risk
Governance, risk, and compliance with an engineering approach. Programs are designed by practitioners with hands-on technical experience, based on your organization's actual risks.
§ 02What's included
What the service covers.
Engage any item on its own, or combine them into a single engagement.
01
Virtual CISO (vCISO)
Senior security leadership at an agreed scope: strategy, priorities, hiring, and board communication.
02
Security program development
We establish a security program from the ground up or bring an existing one to the required level of maturity.
03
Risk assessment
A systematic assessment of your organization's actual risks, quantified so leadership can make decisions about priorities.
04
SOC 2 and ISO 27001 readiness
Gap analysis, control implementation, and support through the audit, up to the report or certificate.
05
Board and auditor reporting
The security posture presented clearly and measurably, in a form suited to boards and auditors.
06
Tabletop exercises
Structured incident response exercises with the people who would actually run the incident.
§ 03How we approach it
A clear methodology, every time.
1
Assess
We establish your current posture against the frameworks and threats relevant to your organization.
2
Plan
A prioritized plan tied to the organization's risks and business goals.
3
Implement
We introduce controls, policies, and processes in cooperation with your team.
4
Operate and report
Ongoing program operation and regular reporting to the board and auditors.
Independent and vendor-neutral. We don't resell the tools we test.
Our only product is expertise and evidence, so our advice has no agenda but yours.
Independent
Vendor-neutral. No licences to sell, no conflicts of interest.
Senior-led
Every engagement is run by senior engineers, not handed to a queue.
Evidence-led
Reproducible findings and documented proof, not severity labels.
Regulator-ready
Built to satisfy NIS2, DORA, ISO 27001, and GDPR by design.
FAQ
Questions, answered
What does a security program engagement include?
Establishing the risk management, policies, and controls a regulated company needs, verified through testing. A program set up this way also satisfies audit requirements.
Is compliance the same as security?
No. Compliance confirms that a control exists; security confirms that it holds under a real attack. We build the program primarily for security, and compliance is the result of a system set up that way.
Can you prepare us for a specific framework?
Yes. We assess your posture against NIS2, DORA, ISO 27001, SOC 2, or the EU AI Act, close the identified gaps, and prepare the documentation for the audit.
Do you stay involved after the program is built?
Yes, through a retainer. We adapt the program on an ongoing basis to new threats, new systems, and new regulatory obligations.