2-3 daysRapid Risk Triage
Short review to organize an uncertain situation before proposing broader work.
- 3-5 page executive memo.
- Prioritized main risks.
- Assumptions and not verified items.
- Recommended next step.
Not included: pentest, full forensics, remediation or certification.
7-10 daysSecurity + AI Due Diligence
Review for evaluating a vendor, acquisition, investment or integration before committing.
- Executive memo.
- Risk register and main findings.
- Relevant security, data and AI risks.
- What is verified, what is missing and what remained out of scope.
- 30/60/90 actions and questions for the vendor or target.
Not included: formal audit, deep exploitation, legal opinion or remediation.
5-10 daysAI / LLM / RAG Risk Review
Review for AI systems connected to documents, tools, internal data or automations.
- AI risk map.
- Data exposure matrix.
- Notes on prompts, tools and permissions.
- Recommended minimum controls.
- Draft usage guidelines.
Not included: full build, model training or legal approval of AI providers.
2-6 weeksAI, Automation & Data Implementation
Implementation of concrete workflows when process, owner, available data and acceptance criteria are clear.
- Solution blueprint and technical scope.
- Automation of evidence, tickets, reports or approvals.
- Integrations across SaaS, APIs, spreadsheets, databases or documents.
- Permission controls, logs, human review and manual fallback.
- Runbook, testing, handoff and formal closeout.
Not included: open-ended development, unlimited support, uncontrolled autonomous agents or fragile scraping.
10-20 daysSOC 2 / ISO Readiness
Review to answer enterprise customers, prepare an audit or close evidence gaps.
- Scope memo.
- Control-to-evidence matrix.
- Gap assessment.
- Minimum policy pack.
- Evidence tracker and work plan.
Not included: certification, official audit or guaranteed enterprise approval.
7-12 daysIncident Readiness + Tabletop
Practical exercise to review roles, decisions and communication before a real incident.
- IR plan v0.1.
- RACI and severity matrix.
- Ransomware/BEC/breach playbooks.
- Tabletop deck and after-action report.
- 30/60/90 backlog.
Not included: 24/7 response, full forensics, continuous monitoring or breach legal advice.
MonthlyFractional Security Lead / vCISO
Ongoing guidance after an initial review, with defined hours and responsibilities.
- Monthly or biweekly committee.
- Living risk register.
- Updated roadmap.
- Evidence review.
- Monthly executive memo.
Not included: daily support, unlimited execution or incidents outside contract.