2-3 daysRapid Risk Triage
Paid entry point to organize uncertainty before proposing a full sprint.
- 3-5 page executive memo.
- Prioritized top risks.
- Assumptions and not verified items.
- Recommended next step.
Not included: pentest, full forensics, remediation or certification.
7-10 daysSecurity + AI Due Diligence Sprint
Core product for vendor risk, M&A, investment, procurement, partnership or enterprise onboarding.
- Executive Decision Memo.
- Risk register and top findings.
- Cyber + AI red flags.
- Known / Unknown / Not Verified.
- 30/60/90 plan and questions for vendor/target.
Not included: formal audit, deep exploitation, legal opinion or remediation.
5-10 daysAI / LLM / RAG Risk Review
Specialized review for AI connected to documents, tools, internal data, agents or workflows.
- AI risk map.
- Data exposure matrix.
- Prompt/tool risk notes.
- Minimum guardrails.
- AI operating policy v0.1.
Not included: full build, model training or legal approval of AI providers.
10-20 daysSOC 2 / ISO Readiness Accelerator
Accelerator to answer enterprise, prepare audit or close evidence gaps.
- Scope memo.
- Control-to-evidence matrix.
- Gap assessment.
- Minimum policy pack.
- Evidence tracker and roadmap.
Not included: certification, official audit or guaranteed enterprise approval.
7-12 daysIncident Readiness + Tabletop
Practical preparation so the first real incident is not also the first rehearsal.
- IR plan v0.1.
- RACI and severity matrix.
- Ransomware/BEC/breach playbooks.
- Tabletop deck and after-action report.
- 30/60/90 backlog.
Not included: 24/7 response, full forensics, continuous monitoring or breach legal advice.
MonthlyFractional Security Lead / vCISO
Recurring guidance only after a sprint, with capped hours and responsibilities.
- Monthly or biweekly committee.
- Living risk register.
- Updated roadmap.
- Evidence review.
- Monthly executive memo.
Not included: daily support, unlimited execution or incidents outside contract.