You need an honest read on where the program actually stands before you decide what to fix first. We review current state, identify gaps, assign owners, and prioritize — plainly, not against a generic maturity model.
- Deliverables
- Executive summary, gap list with owners, prioritized improvement roadmap
- Timeline
- 2–4 weeks
- Your inputs
- Access to relevant systems, docs, and a point of contact
- Starting price
- Starting at $6,500
Scan output is a list, not a program. We validate findings, coordinate remediation with the people who own the systems, track exceptions, and report progress in terms executives will read.
- Deliverables
- Validated findings, remediation tracker, exception log, executive report
- Timeline
- Ongoing monthly, or a fixed 4–6 week engagement
- Your inputs
- Scan tooling access or scan output, stakeholder contacts
- Starting price
- Starting at $2,500
Administrative and privileged access accumulates quietly. We review who has access to what, document ownership, and build MFA/SSO and privileged access governance that survives staff turnover.
- Deliverables
- Access review report, ownership map, MFA/SSO and PAM governance documentation
- Timeline
- 3–5 weeks
- Your inputs
- Directory and IAM/PAM tooling access, org chart context
- Starting price
- Scoped after intake call
A risk register that lives in a shared drive isn't a program. We build the register, map controls to policy, organize evidence, and set a treatment cadence your team can keep running.
- Deliverables
- Risk register, third party risk process, evidence organization, treatment tracker
- Timeline
- 4–6 weeks initial build
- Your inputs
- Existing policy docs, vendor list, prior audit findings if any
- Starting price
- Scoped after intake call
Most incident response plans are written once and never tested. We build the plan, define roles and escalation paths, run a tabletop, and document what the tabletop actually revealed.
- Deliverables
- IR plan, roles & escalation matrix, tabletop exercise, after-action report
- Timeline
- 3–4 weeks
- Your inputs
- Key stakeholder availability for the tabletop session
- Starting price
- Scoped after intake call
Template policy dumps don't survive contact with an auditor. We write policies, standards, and SOPs grounded in what your team actually does — then keep them short enough to be read.
- Deliverables
- Policy and procedure set matched to your operating environment
- Timeline
- 3–6 weeks depending on scope
- Your inputs
- Current process documentation, stakeholder interviews
- Starting price
- Scoped after intake call
Experienced judgment without a full time hire. Risk translation, business alignment, program coordination, and executive communication on a structured monthly cadence. See the Fractional BISO page for the full model.
- Deliverables
- Monthly program review, executive reporting, ongoing risk and roadmap coordination
- Timeline
- Ongoing monthly engagement
- Your inputs
- Recurring access to leadership and relevant systems
- Starting price
- Typical $5,000–$12,000 monthly
Intake forms, evidence requests, and status reporting eat hours every week. We build lightweight workflows — not a new platform — that cut the repetitive parts down.
- Deliverables
- Working intake/evidence/reporting workflow, handoff documentation
- Timeline
- 2–5 weeks depending on complexity
- Your inputs
- Access to the systems the workflow touches
- Starting price
- Scoped after intake call