The challenge behind the engagement.
This service shows where the security program stands, where it needs to be, and what to do first. We choose one recognized framework with you and set the target level leadership wants to reach. We run workshops with each function owner, review your policies, diagrams, runbooks, and ticket samples, and verify sampled controls in your environment so the score reflects what actually runs, not what is written down. You receive a current-state and target-state scorecard, the rubric behind it, and a twelve to twenty-four month roadmap with owners, effort, and dependencies. The target level is something leadership chooses, not a certification anyone grants, and we do not promise a given score by a given date.
For CISOs, CTOs, and security managers who inherited a program, are building one, or must justify next year’s budget to a board that wants a score and a plan. Typical triggers: a new security leader’s first quarter, a board or private equity request for a maturity picture, customers asking about several security standards at once alongside a government contract, or the first annual reassessment.
What we do.
What you can use.
Choose the lens and the target
We agree the framework, the scope (which parts of the business, which locations), and the target level leadership wants to reach, set by how sensitive your data is and how your team is staffed. Your contracts and regulations ground that target, so the scorecard answers the questions your customers and regulators actually put to you.
Score from evidence, not questionnaires
Workshops with each function owner, a review of policies, network diagrams, runbooks, ticket samples, and prior audits, and sampled verification in your identity, endpoint, backup, and cloud environments. Each area gets a current rating, a target rating, and a plain gap statement, all scored on a rubric we hand over so your team can rescore next year without us.
Sequence the roadmap and brief the board
Gaps are grouped into themes, then sequenced over twelve to twenty-four months with an owner, effort, dependencies, a budget class, and the specific outcome each initiative closes. First-quarter quick wins target multi-factor authentication gaps, endpoint coverage, backup restore tests, and admin account cleanup. You receive one-page charters for the major initiatives and a board summary stating the target.
Who it’s for.
When you need it.
- New security leaders who inherited a program and need an objective baseline
- Teams building a security program from scratch toward a recognized target
- Leaders who must justify security spending to a board wanting a score
- Organizations juggling several frameworks that want one comparable maturity picture
- A newly hired security leader needs an objective read within the first quarter
- A board or private equity sponsor requests a maturity score and plan
- Customers ask about several standards while a government contract looms
- The annual reassessment cycle comes due and last year's scores need refreshing
What the scope can include.
- 01
Framework and target selection matched to your obligations, your data sensitivity, and your staffing
- 02
Workshops with owners of identity, endpoint, network, cloud, application, data, vendor, incident response, and governance
- 03
Artifact review of policies, diagrams, runbooks, ticket samples, and prior audit results
- 04
Sampled technical verification in consoles so ratings reflect what runs, not what is written
- 05
Scorecard with a current and a target rating and a gap statement for each area
- 06
Roadmap sequencing with owners, effort, dependencies, budget class, and the outcome each initiative closes
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 50 employees, one location, a small IT team or outsourced IT
About 50–70 hours50–250 employees, in-house IT, cloud plus office systems, one or two locations
About 90–130 hours250–1,000 employees, multiple locations or business units, several frameworks to map
About 150–220 hours- Number of locations, business units, and function owners to interview
- How many other frameworks the scorecard has to map to (customer, audit, government contract)
- How much documentation and asset inventory already exist
- Depth of hands-on verification in your systems vs. interview-only scoring
4–6 weeks for small and mid-size scopes; 8–10 weeks for large
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Current-state and target-state maturity scorecard against your chosen framework, with the rubric used
- Themed gap list and a 12 to 24 month roadmap naming owner, effort, dependencies, and budget class per initiative
- One-page charters for major initiatives and a board summary stating the target level and expected date
- Rescoring guide and review cadence so your team can repeat the assessment without us
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Are you certifying us at a maturity level?
No. The target level is something leadership selects to match your risk and obligations; nobody certifies you to it. The scorecard is our evidence-based rating against a rubric you keep, and it works for a board, an insurer, or a customer as a clear maturity picture. It is not a formal compliance assessment or a certification audit; where you need one of those, your independent assessor or auditor decides the result, and this scorecard simply shows how ready you are for it.
Which framework should we score against when customers, auditors, and a government contract all ask for something different?
We use one recognized framework as the umbrella and map it to the others as reference points, so a single scorecard answers the government contract, the audit, and the customer question at the same time. Your contracts and regulations ground the target, so the score speaks directly to what each party is asking. Where a customer wants a specific attestation, the scorecard shows which gaps stand in the way, but your independent auditor decides that result. The roadmap can double as the structure of your budget request; the figures stay yours.
- NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0
- NIST Cybersecurity Framework 2.0: Quick-Start Guide for Creating and Using Organizational Profiles
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
- NIST IR 8286 Rev. 1: Integrating Cybersecurity and Enterprise Risk Management (ERM)
- CIS Critical Security Controls Version 8.1
- ISO/IEC 27005:2022 - Guidance on managing information security risks
- Cross-Sector Cybersecurity Performance Goals
