Focused engagements
One problem, one defined piece of work.
Each engagement below stands on its own, or slots into a Clarity Sprint or a retained cadence. Fixed scope, a named deliverable, and a reason it is worth doing now. Scoped and priced on the fit call.
Led by Alex Sellers. When scope calls for it, vetted senior practitioners join under the same terms. Trusted open-source and vetted vendor tools are used where they earn their place.
AI governance
AI governance sprint
You get
An AI acceptable-use policy, a risk-assessment template built on the NIST AI Risk Management Framework, a tool approval path, prompt-injection and data-handling guidance, and a short employee education session. Assessments of the two or three tools your teams are already using come with it.
Why it is worth doing
AI adoption is moving faster than anyone's mandate to govern it. A written boundary lets the business say yes to tools quickly and defend that yes to customers, counsel, and insurers. It also produces the evidence an ISO 42001 or customer questionnaire will ask for.
Two to three weeks. Stands alone or opens a retained cadence.
Exercises
Incident response and disaster recovery tabletops
You get
A scenario built around your actual systems and obligations, a facilitated two-to-three-hour exercise with defined roles, phases, and decision points, and a written after-action report with owners for every gap found.
Why it is worth doing
A team that has rehearsed decides better under pressure. The exercise surfaces the gaps in roles, backup validation, restore times, and communications while they are still cheap to fix, and produces evidence insurers and enterprise customers increasingly ask for.
Three to four weeks from kickoff to report. Annual repeat recommended; the second scenario can be built from the first report.
Third-party risk
Vendor and SaaS security review service
You get
Review criteria and a questionnaire sized to your risk tiers, a documented review of each vendor or integration in scope (security posture, data handling, access, SOC report or equivalent), and a decision record procurement and leadership can act on. Available per vendor or as a monthly service.
Why it is worth doing
Every new tool is a new place your data lives. A repeatable review turns vendor adoption from a Slack thread into a decision with an owner, and keeps the inventory current for audits and customer questionnaires.
Per vendor, or a monthly allowance inside a retained cadence.
Team
First security hire package
You get
The business-risk case for the headcount, the role definition, a structured interview loop with a question bank and scoring model, a practical exercise, hiring-manager guidance, and a 30-60-90 onboarding plan tied to your roadmap.
Why it is worth doing
The first security hire usually inherits a backlog and no mandate. A defined role and a measured loop make the hire faster, reduce the odds of a mis-hire, and hand the new person a plan on day one. This is also the natural exit from a fractional engagement.
Three to four weeks for the package; interview support by the hour if wanted.
Culture
Security Champions launch and nurturing
You get
Program design (charter, rotation model, time commitment), recruitment support, the first three monthly sessions (threat modeling, secure development, a practical AI-security workshop), and a handoff kit. Ongoing nurturing is available as a monthly cadence: session content, recognition, and remediation follow-through.
Why it is worth doing
Security coverage without security headcount. Engineers who own security where the work happens fix things faster than a central team can ask them to, and the program keeps working after the launch energy fades only if someone keeps feeding it.
Launch in four to six weeks; nurturing month to month.
Awareness
Awareness and phishing program operations
You get
Setup or tune-up of your training platform, a communications calendar, phishing simulation and response procedures, remedial follow-up, and privacy-preserving aggregate reporting for leadership and auditors. Platform licenses are yours; the operation is the service.
Why it is worth doing
Annual compliance training changes little on its own. An operated program, with recurring communication and a clear response path when someone clicks, is what changes behavior and what auditors and customers accept as evidence.
Setup in two to three weeks; operations monthly.
Governance
Policy pack and security knowledge base
You get
A sequenced set of policies across the domains an audit or customer will ask about (information security, acceptable use, access, data classification, vendor, incident, change, business continuity, and others as scoped), written for the people who must follow them, plus an audience-first knowledge base structure separating public guidance, restricted material, and templates.
Why it is worth doing
Policies that no one can find or read are a liability in an audit and useless in an incident. A readable set with owners and a home shortens every future questionnaire and readiness effort.
Three to five weeks depending on the number of domains.
Risk
Enterprise risk register and KRI model
You get
A source-backed risk register with each risk tied to evidence, exposure, an owner, a remediation action, and a decision path; a set of key risk indicators leadership can track; a risk-appetite workshop; and a policy-exception workflow.
Why it is worth doing
Leadership cannot set risk appetite from a finding list. A register that connects evidence to owners and indicators turns security risk into decisions with a record, and it is the backbone of every executive brief that follows.
Three to four weeks for the first version; maintained inside a retained cadence.
Access
Zero Trust and secure access business case
You get
An assessment of remote access, private-application exposure, and identity controls; a prioritized proposal (MoSCoW) with resource needs, continuity considerations, known risks, and mitigations; vendor evaluation criteria; and a rollout and exception-handling plan.
Why it is worth doing
Legacy remote access is one of the most common paths into a company and one of the hardest projects to get funded without a clear case. A proposal leadership can approve, with the rollout risks named, is what moves it from a wish to a program.
Three to four weeks for the case; rollout support by agreement.
Productivity suite
Google Workspace and Microsoft 365 security review
You get
A read-only review of identity and MFA, admin roles, mail authentication (SPF, DKIM, DMARC), external sharing, device and session controls, audit logging, and retention against current vendor and CIS baselines, with a sequenced hardening list your admin can execute.
Why it is worth doing
Your productivity suite is your identity provider, your document store, and your primary phishing surface. Most of the fixes are configuration, not spend; the value is knowing which ones matter first.
One to two weeks. Hardening support available by agreement.
Cloud
Cloud security posture review
You get
A read-only review of AWS and GCP (Azure on request) covering IAM and privilege, encryption, logging and monitoring, network and public exposure, instance metadata, and backup posture; findings ranked by business impact and sequenced against engineering capacity, with owners.
Why it is worth doing
Cloud findings without a sequence do not get fixed. A ranked list your engineers agree with, and a plan that respects their capacity, is what turns a scanner report into fewer findings carried quarter to quarter.
Two to three weeks. Trusted open-source or vetted vendor tooling is used only where scoped in together.
Assurance
SOC 2, ISO 27001, and ISO 42001 readiness lead
You get
Scope and control mapping, a gap assessment, control ownership across functions, evidence operations (including platform setup such as Vanta or equivalent), policy rollout, remediation tracking, and liaison with the audit firm you choose. Not an audit and not an attestation; you select and contract the auditor directly.
Why it is worth doing
Enterprise customers and insurers ask for these, and readiness is where most of the cost and delay hides. A lead who owns the evidence system and keeps other functions on schedule gets you to the audit sooner and with fewer surprises, without building a paperwork factory.
SOC 2 and ISO 27001 typically eight to sixteen weeks to readiness; ISO 42001 pairs naturally with the AI governance sprint.
Not sure which one you need?
Bring the decision or milestone in front of you to a 20-minute fit call. You will leave with a recommendation — including if it is none of these.