Services

Security work sized for a business without a security team

Every engagement starts with the same thing: clear questions, honest answers, and a report you can act on the same week.

Cybersecurity risk assessment

A structured review of your people, systems, and data against NIST CSF 2.0 — scored by function so you can see exactly where you stand.

NIST 800-171 gap analysis

Control-by-control comparison for businesses with federal or enterprise contract flow-downs, with an evidence checklist.

Executive summary reporting

A board- and client-ready summary that translates technical gaps into business risk, written in plain English.

Remediation roadmap

Prioritised actions with owners, effort, and 30 / 90 / 180-day timelines — sequenced by risk reduction per dollar.

Vendor & third-party review

Identify which suppliers touch your data, what they're contractually required to do, and where your exposure sits.

Security awareness training

Short, plain-English staff training on passwords, data handling, scams, and reporting — with completion tracking you can show an auditor or insurer.

Phishing simulation

Safe, realistic phishing campaigns sent to your team, with click and report rates by department and targeted coaching for anyone who falls for one.

Reassessment & tracking

Re-run the assessment after remediation to evidence measurable improvement for insurers and customers.

Healthcare & Counseling

HIPAA-aligned risk assessments, gap analysis, and remediation plans for therapy groups, counseling practices, and small clinics.

Learn more

Not sure where to start?

Run the free Mini Gap-Scan — 10 questions, about 5 minutes, no card required.

Start free Mini Gap-Scan