Practice 06
Compliance & GRC
SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, FedRAMP and privacy programs, scoped to the audit you actually face.
43 services
What we deliver.
Starting prices come from our live catalog. Your proposal fixes the tier and price before anything is signed.
FedRAMP Compliance Program
Specialized compliance program for cloud service providers seeking FedRAMP authorization, including readiness assessment, documentation preparation, and implementation support.
Healthcare Device Manufacturing Security Program
Comprehensive security assessment for medical device manufacturers, covering FDA compliance, manufacturing processes, and device security throughout the development lifecycle.
Election Systems Security Assessment
Specialized security assessment for election systems and voting infrastructure, including hardware testing, software evaluation, and process validation.
Financial Services Compliance Program
Comprehensive compliance assessment and implementation program for financial institutions, covering SEC, FINRA, SOX, PCI-DSS, and banking regulations.
Data Privacy Compliance Program
Comprehensive data privacy compliance program covering GDPR, CCPA, and other international privacy regulations with implementation support.
Aviation & Aerospace Security Assessment
Specialized security assessment for aviation and aerospace organizations, addressing the critical security challenges of aircraft systems, airport infrastructure, flight operations, and aerospace manufacturing. Our assessment helps aviation organizations protect safety-critical systems, intellectual property, and operational technology while meeting strict regulatory requirements and ensuring passenger safety.
Cannabis Industry Security Program
Comprehensive security assessment for cannabis operations, including cultivation facilities, retail operations, and supply chain compliance with state-specific regulations.
Educational Institution Security Program
Comprehensive security assessment for educational institutions, covering student data protection, campus infrastructure, and remote learning systems.
Digital Transformation Security Program
Comprehensive security assessment and framework designed specifically for organizations undergoing digital transformation initiatives. Our specialized program addresses the unique security challenges of rapid technological change, legacy system integration, new business models, and accelerated development cycles - ensuring security becomes an enabler rather than a barrier to digital innovation.
Pharmaceutical Industry Security Assessment
Comprehensive security assessment designed specifically for pharmaceutical organizations, addressing the unique security challenges of drug development, clinical trials, manufacturing, and distribution. Our specialized assessment examines intellectual property protection, research data security, regulatory compliance, and supply chain integrity to secure your most valuable assets and ensure compliance with industry regulations.
State & Local Government Compliance Assessment
Specialized compliance assessment for state and local government agencies addressing the unique regulatory requirements that apply to public sector entities. Our evaluation examines state-specific cybersecurity regulations, data protection laws, sunshine laws, records retention requirements, and security standards to help government entities achieve compliance and protect sensitive information.
Active Directory Security Assessment
Comprehensive security assessment of Active Directory infrastructure, focusing on privilege escalation, lateral movement, and domain compromise scenarios.
Security Architecture Review
Comprehensive analysis of your organization's security architecture design, evaluating defense-in-depth strategies, security control effectiveness, and alignment with business objectives and threat models.
Retail & E-commerce Security Assessment
Comprehensive security assessment designed specifically for retail and e-commerce organizations, addressing the complex challenges of securing omnichannel retail environments, payment processing systems, customer data, and inventory management. Our specialized assessment helps retailers protect their brand, customer trust, and operational continuity across physical and digital retail channels.
GDPR Compliance Assessment
Comprehensive evaluation of your organization's compliance with the European Union's General Data Protection Regulation (GDPR). Our assessment examines data processing activities, privacy controls, and governance frameworks to identify compliance gaps and provide a detailed remediation roadmap for organizations handling EU resident data.
Vendor & Third-Party Security Risk Assessment
Comprehensive evaluation of your organization's third-party risk management program and vendor security assessment practices. Our assessment examines your vendor security evaluation processes, contractual security requirements, ongoing monitoring capabilities, and supply chain security controls to identify vulnerabilities in your extended enterprise and provide a roadmap for enhanced third-party risk management.
HIPAA/HITECH Compliance Assessment
Comprehensive evaluation of your organization's compliance with HIPAA and HITECH regulations, focusing on the protection of electronic protected health information (ePHI). Our assessment examines technical, administrative, and physical safeguards, providing a detailed gap analysis and remediation plan to achieve and maintain compliance while reducing the risk of breaches and penalties.
Executive Travel Privacy & Security Assessment
Comprehensive international travel security and privacy assessment for executives, high-net-worth individuals, and VIPs. Ensures secure and private travel across borders while protecting digital assets, communications, and financial transactions.
Hospitality Sector Security Program
Specialized security assessment for hotels, resorts, restaurants, and hospitality organizations, addressing the unique challenges of securing guest data, payment systems, property management systems, and physical-digital security convergence. Our assessment helps hospitality businesses protect guest privacy, ensure PCI compliance, and maintain operational continuity while delivering exceptional guest experiences.
California Privacy Law Assessment (CCPA/CPRA)
Comprehensive evaluation of your organization's compliance with California's privacy regulations, including the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). Our assessment examines data handling practices, consumer rights processes, and disclosure requirements to identify compliance gaps and provide a detailed remediation roadmap.
Trifecta Security Assessment: Business Continuity, Disaster Recovery, and Incident Response
Comprehensive assessment covering three critical areas of organizational resilience - business continuity planning, disaster recovery strategies, and incident response capabilities.
PCI DSS Compliance Assessment
Comprehensive evaluation of your organization's compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements. Our assessment examines cardholder data environments, security controls, and processes to identify compliance gaps and provide a detailed remediation roadmap to achieve and maintain PCI DSS compliance while protecting sensitive payment information.
HITRUST e1 / i1 Readiness
Healthcare customers and payers increasingly require HITRUST. We scope the assessment, perform the readiness assessment against the e1 (44 requirements) or i1 (182 requirements) set, remediate gaps, build the evidence library in MyCSF terms and prepare you for the external assessor. We are the readiness partner, not the assessor.
Remote Work Security Assessment
Comprehensive evaluation of your organization's remote work security posture in today's hybrid workplace environment. Our assessment examines remote access infrastructure, endpoint security, home network risks, secure communications, data protection measures, and policy effectiveness for distributed workforces, providing a roadmap to secure your modern workplace.
Cyber Insurance Readiness Assessment
Prepare your organization for cyber insurance applications and renewals by evaluating compliance with insurer requirements, identifying control gaps, and implementing documentation to support favorable coverage terms and rates.
Data Privacy Impact Assessment
Systematic evaluation of data handling practices to ensure compliance with privacy regulations and identify potential privacy risks.
Startup Security Readiness Assessment
Specialized security assessment designed for startups at every growth stage, from angel funding through Series A and beyond. Our tailored approach addresses the unique security challenges of rapidly evolving startups, balancing innovation speed with essential security controls. We help founders and startup teams build security foundations that enable growth, satisfy investor expectations, and prepare for enterprise customer requirements without slowing down product development.
SOC 2 Readiness Assessment
Comprehensive evaluation of your organization's readiness for SOC 2 compliance, examining your controls against the relevant Trust Services Criteria. Our assessment provides a detailed gap analysis and implementation roadmap to help you prepare for a successful SOC 2 audit.
Employee Security Awareness Assessment
Comprehensive assessment of employee security awareness levels to identify training needs and security culture gaps.
NIST CSF 2.0 Maturity Assessment
A named, fixed-scope assessment against all six NIST Cybersecurity Framework 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover. Evidence-based interviews and document review produce a current-state maturity score per category, a target profile matched to your risk appetite, and a funded roadmap. The scorecard is built to be shown to a board, an acquirer or a cyber insurer.
ISO 27001 Certification Readiness Assessment
Comprehensive evaluation of your organization's readiness for ISO 27001 certification, examining your information security management system (ISMS) against the standard's requirements. Our assessment provides a detailed gap analysis and implementation roadmap to help you achieve certification efficiently and effectively.
Defense Industry Security Program
Comprehensive security assessment and compliance program for defense contractors and military industrial complex, focusing on CMMC, NIST 800-171, and classified information handling.
Business Continuity Planning Assessment
Comprehensive evaluation of your organization's business continuity capabilities and operational resilience through detailed Business Impact Analysis (BIA), risk assessment, and continuity planning. Our specialized approach combines regulatory compliance requirements with practical business resilience strategies to ensure your organization can maintain critical operations during disruptions and recover effectively from various business interruption scenarios.
Compliance Assessment
Evaluate and achieve compliance with major security frameworks
CMMC 2.0 Level 1 & 2 Readiness (NIST SP 800-171)
For contractors handling FCI or CUI. We scope the CUI boundary, assess all NIST SP 800-171 practices, calculate and document your SPRS score, write the System Security Plan and POA&M, and prepare you for self-assessment or a C3PAO assessment. CMMC phase-in dates have moved more than once; NIST SP 800-171 and DFARS 252.204-7012 obligations apply regardless, so we plan against the requirement rather than a single deadline.
Compliance Automation Implementation & Managed Compliance
Compliance automation platforms collect evidence; they do not write your policies, fix failing tests, scope your audit or answer your auditor. We implement the platform against your real environment, author policies that match how you work, close the failing controls, prepare you for the audit and stay on as the managed compliance team if you want one. Platform-neutral: we work with the tool you chose and never take a fee from an auditor.
Continuous Attack Surface Monitoring
Comprehensive continuous monitoring of your external attack surface with regular assessments and testing.
ISO/IEC 42001 & EU AI Act Readiness
Organizations building or deploying AI are being asked for ISO/IEC 42001 certification and EU AI Act conformity. This engagement inventories your AI systems, classifies them under the AI Act risk tiers, assesses the AI management system against ISO 42001 Annex A, and produces the policies, impact assessments and roadmap needed to reach certification readiness.
SMB Compliance Readiness
Targeted assessment for SMBs preparing for compliance certification.
HIPAA Security Risk Analysis — Small Practice
The Security Rule requires every covered entity and business associate to perform a security risk analysis. This engagement delivers exactly that for small and mid-sized practices: an asset and ePHI inventory, threat and vulnerability analysis, risk ratings, and a remediation plan you can show OCR, a payer or a cyber insurer. It is the entry point below the full HIPAA/HITECH Compliance Assessment.
FTC Safeguards Rule & IRS WISP Compliance Package
The FTC Safeguards Rule and IRS Publication 4557 require tax preparers, auto dealers, mortgage brokers and other small financial institutions to keep a Written Information Security Program, name a qualified individual, assess risk and train staff. This annual package delivers a WISP that reflects your firm, the risk assessment behind it, staff training and the yearly review that keeps it valid — with a practitioner who can act as your qualified individual.
Vulnerability Management as a Service
Most organizations own a scanner and still carry a backlog nobody triages. We run authenticated internal and external scanning, prioritize by exploitability and business context rather than CVSS alone, open and track remediation tickets with your IT team or MSP, verify fixes and report the trend leadership and auditors want to see.
AI Governance & TRiSM Program
Stand up AI governance (TRiSM): inventory AI systems, classify risk, map to EU AI Act / NIST AI RMF / ISO 42001, and operate ongoing AI risk, trust, and security management with human oversight.
Process
How an engagement runs.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Research
Latest from the blog

ciso-strategy · Sep 24, 2026
Brinqa-PlexTrac and Cribl-Radiant Deals Signal CTEM and SOC Platforms Are Absorbing Point Tools
Thirty-three cybersecurity M&A deals in August 2026, led by Brinqa-PlexTrac and Cribl-Radiant Security, show exposure management and SOC platforms swallowing offensive-security and AI-native automation tools.

risk-management · Sep 23, 2026
Three Linux Kernel Flaws Hit CISA's KEV List: A CISO Triage Playbook
CISA added three actively exploited Linux kernel CVEs to its KEV catalog with a 72-hour federal remediation window. Here is a step-by-step triage order for CISOs.

incident-response · Sep 22, 2026
The Revolut Breach Is a Case Study in Confusing Authentication With Authorization
Revolut disclosed customer data to attackers who spoofed a government agency's email domain for five months. The root cause was not weak email security but a workflow that treated a valid domain as proof of a valid request.
Start an engagement