Skip to main content
How we work

Four phases. One program that actually holds up.

Every engagement, a full vCISO retainer or a focused SOC 2 sprint, moves through the same disciplined process, calibrated to your size and timeline.

01

Assess

Typically 1-3 weeks

We map your environment, identify the gaps against the framework, and give you a prioritized roadmap. Then we start fixing things — not just documenting them.

What you get

  • Structured interviews with key stakeholders across engineering, IT, and leadership
  • A review of your current controls, tools, and documentation
  • Benchmarking against NIST CSF, SOC 2, ISO 27001, or the framework relevant to you
  • A risk-ranked findings summary in plain English

What we need from you

  • Access to relevant documentation and system diagrams
  • 30-60 minutes from 2-4 key stakeholders
  • A point of contact to coordinate scheduling
02

Plan

Typically 1-2 weeks

We build the implementation plan. Who does what, when, and how. Policies, controls, evidence collection, tool configuration. All mapped to your audit timeline.

What you get

  • A prioritized 90-day and 12-month roadmap
  • A board-ready executive summary deck
  • Clear ownership recommendations for each initiative
  • A realistic timeline and effort estimate for every workstream

What we need from you

  • A review session with leadership to align on priorities
  • Confirmation of budget or resourcing constraints we should plan around
03

Implement

Timeline varies by scope

This is where most consultants hand you a document and step back. We don't. Your vCISO rolls up their sleeves alongside your team — writing policies, configuring controls, running vendor reviews, and managing the audit relationship if one is in motion.

What you get

  • Hands-on policy and control implementation
  • Direct collaboration with engineering and IT on technical controls
  • Vendor and third-party risk assessments handled on your behalf
  • Audit liaison and evidence collection support if you're pursuing SOC 2 or ISO 27001

What we need from you

  • A designated technical point of contact for implementation questions
  • Reasonable access to systems and tooling as controls are configured
04

Maintain

Ongoing

A security program isn't a project with an end date — it's an operating discipline. We keep your program current through ongoing advisory, ownership of monitoring cadences, and periodic reassessment as your company grows and risk evolves.

What you get

  • Ongoing advisory access via Slack, email, or a standing call
  • Continuous control monitoring and evidence upkeep
  • Policy reviews and updates as your business changes
  • Annual or semi-annual reassessment to catch drift before an auditor does

What we need from you

  • A light ongoing cadence — typically a weekly or biweekly sync
  • A heads-up on major business changes (new products, new data types, new markets)
A note on timelines

Realistic pacing, not rushed compliance theater

Some phases can move fast — an assessment might take two weeks. Others, like a SOC 2 Type II observation period, require months by design because that's what it takes for an auditor to trust the evidence. We'll be upfront about which is which from day one.

Ready when you are

See what this looks like for your company

Book a free consultation and we'll map the process to your specific timeline, team, and compliance goals.