Services

A portfolio of scoped sprints

Offers designed to reduce uncertainty, deliver evidence and avoid infinite support. Each service has typical duration, deliverables, exclusions and closure criteria.

2-3 days

Rapid Risk Triage

Paid entry point to organize uncertainty before proposing a full sprint.

  • 3-5 page executive memo.
  • Prioritized top risks.
  • Assumptions and not verified items.
  • Recommended next step.

Not included: pentest, full forensics, remediation or certification.

7-10 days

Security + AI Due Diligence Sprint

Core product for vendor risk, M&A, investment, procurement, partnership or enterprise onboarding.

  • Executive Decision Memo.
  • Risk register and top findings.
  • Cyber + AI red flags.
  • Known / Unknown / Not Verified.
  • 30/60/90 plan and questions for vendor/target.

Not included: formal audit, deep exploitation, legal opinion or remediation.

5-10 days

AI / LLM / RAG Risk Review

Specialized review for AI connected to documents, tools, internal data, agents or workflows.

  • AI risk map.
  • Data exposure matrix.
  • Prompt/tool risk notes.
  • Minimum guardrails.
  • AI operating policy v0.1.

Not included: full build, model training or legal approval of AI providers.

10-20 days

SOC 2 / ISO Readiness Accelerator

Accelerator to answer enterprise, prepare audit or close evidence gaps.

  • Scope memo.
  • Control-to-evidence matrix.
  • Gap assessment.
  • Minimum policy pack.
  • Evidence tracker and roadmap.

Not included: certification, official audit or guaranteed enterprise approval.

7-12 days

Incident Readiness + Tabletop

Practical preparation so the first real incident is not also the first rehearsal.

  • IR plan v0.1.
  • RACI and severity matrix.
  • Ransomware/BEC/breach playbooks.
  • Tabletop deck and after-action report.
  • 30/60/90 backlog.

Not included: 24/7 response, full forensics, continuous monitoring or breach legal advice.

Monthly

Fractional Security Lead / vCISO

Recurring guidance only after a sprint, with capped hours and responsibilities.

  • Monthly or biweekly committee.
  • Living risk register.
  • Updated roadmap.
  • Evidence review.
  • Monthly executive memo.

Not included: daily support, unlimited execution or incidents outside contract.

OfferDecision enabledTypical durationFit
Rapid Risk TriageHow serious is this and what should we review first?2-3 daysInitial urgency, questionnaire, suspicious vendor or AI initiative.
Due Diligence SprintDo we sign, buy, invest or pause?7-10 daysVendor/M&A/procurement/enterprise onboarding.
AI Risk ReviewCan we deploy AI with defensible controls?5-10 daysLLM, RAG, agents, copilots or automations with data.
Readiness AcceleratorWhat is missing to answer enterprise/compliance?10-20 daysB2B SaaS, tech vendors, audits or security reviews.
Incident TabletopDo we know what to do during a real incident?7-12 daysCompanies with sensitive data or critical continuity.
Next step

First we define the decision. Then the sprint.

We do not request access or sensitive evidence without scope and authorization.

Qualify opportunity