Services

Focused services

Reviews and implementations with defined scope to understand risk, organize evidence and build controlled AI, automation or data workflows.

2-3 days

Rapid Risk Triage

Short review to organize an uncertain situation before proposing broader work.

  • 3-5 page executive memo.
  • Prioritized main risks.
  • Assumptions and not verified items.
  • Recommended next step.

Not included: pentest, full forensics, remediation or certification.

7-10 days

Security + AI Due Diligence

Review for evaluating a vendor, acquisition, investment or integration before committing.

  • Executive memo.
  • Risk register and main findings.
  • Relevant security, data and AI risks.
  • What is verified, what is missing and what remained out of scope.
  • 30/60/90 actions and questions for the vendor or target.

Not included: formal audit, deep exploitation, legal opinion or remediation.

5-10 days

AI / LLM / RAG Risk Review

Review for AI systems connected to documents, tools, internal data or automations.

  • AI risk map.
  • Data exposure matrix.
  • Notes on prompts, tools and permissions.
  • Recommended minimum controls.
  • Draft usage guidelines.

Not included: full build, model training or legal approval of AI providers.

2-6 weeks

AI, Automation & Data Implementation

Implementation of concrete workflows when process, owner, available data and acceptance criteria are clear.

  • Solution blueprint and technical scope.
  • Automation of evidence, tickets, reports or approvals.
  • Integrations across SaaS, APIs, spreadsheets, databases or documents.
  • Permission controls, logs, human review and manual fallback.
  • Runbook, testing, handoff and formal closeout.

Not included: open-ended development, unlimited support, uncontrolled autonomous agents or fragile scraping.

10-20 days

SOC 2 / ISO Readiness

Review to answer enterprise customers, prepare an audit or close evidence gaps.

  • Scope memo.
  • Control-to-evidence matrix.
  • Gap assessment.
  • Minimum policy pack.
  • Evidence tracker and work plan.

Not included: certification, official audit or guaranteed enterprise approval.

7-12 days

Incident Readiness + Tabletop

Practical exercise to review roles, decisions and communication before a real incident.

  • IR plan v0.1.
  • RACI and severity matrix.
  • Ransomware/BEC/breach playbooks.
  • Tabletop deck and after-action report.
  • 30/60/90 backlog.

Not included: 24/7 response, full forensics, continuous monitoring or breach legal advice.

Monthly

Fractional Security Lead / vCISO

Ongoing guidance after an initial review, with defined hours and responsibilities.

  • Monthly or biweekly committee.
  • Living risk register.
  • Updated roadmap.
  • Evidence review.
  • Monthly executive memo.

Not included: daily support, unlimited execution or incidents outside contract.

OfferDecision enabledTypical durationFit
Rapid Risk TriageHow serious is this and what should we review first?2-3 daysInitial urgency, questionnaire, suspicious vendor or AI initiative.
Due DiligenceDo we proceed, ask for more evidence or pause?7-10 daysVendor, M&A, procurement or enterprise onboarding.
AI Risk ReviewCan we deploy AI with reasonable controls?5-10 daysLLM, RAG, agents, copilots or automations with data.
Scoped implementationWhich workflow should we build and how do we leave it operable?2-6 weeksApplied AI, integrations, reports, evidence and repetitive processes.
ReadinessWhat evidence is missing for enterprise or audit review?10-20 daysB2B SaaS, tech vendors, audits or security reviews.
Incident TabletopWho decides what during an incident?7-12 daysCompanies with sensitive data or critical continuity.

Triage first

Before building, we validate process, frequency, data, risk, owner and success metric.

Scoped implementation

We implement one to three workflows with closed scope, testing, documentation and acceptance criteria.

Limited care

Continuity is handled with hours, backlog and clear responsibilities. No implicit support.

Next step

First we understand the situation. Then we define scope.

We do not request access or sensitive evidence without scope and authorization.

Start a conversation