Skip to content
Blackhole Cyberstrategy Book a fit call

Focused engagements

One problem, one defined piece of work.

Each engagement below stands on its own, or slots into a Clarity Sprint or a retained cadence. Fixed scope, a named deliverable, and a reason it is worth doing now. Scoped and priced on the fit call.

Led by Alex Sellers. When scope calls for it, vetted senior practitioners join under the same terms. Trusted open-source and vetted vendor tools are used where they earn their place.

AI governance

AI governance sprint

You get

An AI acceptable-use policy, a risk-assessment template built on the NIST AI Risk Management Framework, a tool approval path, prompt-injection and data-handling guidance, and a short employee education session. Assessments of the two or three tools your teams are already using come with it.

Why it is worth doing

AI adoption is moving faster than anyone's mandate to govern it. A written boundary lets the business say yes to tools quickly and defend that yes to customers, counsel, and insurers. It also produces the evidence an ISO 42001 or customer questionnaire will ask for.

Two to three weeks. Stands alone or opens a retained cadence.

Exercises

Incident response and disaster recovery tabletops

You get

A scenario built around your actual systems and obligations, a facilitated two-to-three-hour exercise with defined roles, phases, and decision points, and a written after-action report with owners for every gap found.

Why it is worth doing

A team that has rehearsed decides better under pressure. The exercise surfaces the gaps in roles, backup validation, restore times, and communications while they are still cheap to fix, and produces evidence insurers and enterprise customers increasingly ask for.

Three to four weeks from kickoff to report. Annual repeat recommended; the second scenario can be built from the first report.

Third-party risk

Vendor and SaaS security review service

You get

Review criteria and a questionnaire sized to your risk tiers, a documented review of each vendor or integration in scope (security posture, data handling, access, SOC report or equivalent), and a decision record procurement and leadership can act on. Available per vendor or as a monthly service.

Why it is worth doing

Every new tool is a new place your data lives. A repeatable review turns vendor adoption from a Slack thread into a decision with an owner, and keeps the inventory current for audits and customer questionnaires.

Per vendor, or a monthly allowance inside a retained cadence.

Team

First security hire package

You get

The business-risk case for the headcount, the role definition, a structured interview loop with a question bank and scoring model, a practical exercise, hiring-manager guidance, and a 30-60-90 onboarding plan tied to your roadmap.

Why it is worth doing

The first security hire usually inherits a backlog and no mandate. A defined role and a measured loop make the hire faster, reduce the odds of a mis-hire, and hand the new person a plan on day one. This is also the natural exit from a fractional engagement.

Three to four weeks for the package; interview support by the hour if wanted.

Culture

Security Champions launch and nurturing

You get

Program design (charter, rotation model, time commitment), recruitment support, the first three monthly sessions (threat modeling, secure development, a practical AI-security workshop), and a handoff kit. Ongoing nurturing is available as a monthly cadence: session content, recognition, and remediation follow-through.

Why it is worth doing

Security coverage without security headcount. Engineers who own security where the work happens fix things faster than a central team can ask them to, and the program keeps working after the launch energy fades only if someone keeps feeding it.

Launch in four to six weeks; nurturing month to month.

Awareness

Awareness and phishing program operations

You get

Setup or tune-up of your training platform, a communications calendar, phishing simulation and response procedures, remedial follow-up, and privacy-preserving aggregate reporting for leadership and auditors. Platform licenses are yours; the operation is the service.

Why it is worth doing

Annual compliance training changes little on its own. An operated program, with recurring communication and a clear response path when someone clicks, is what changes behavior and what auditors and customers accept as evidence.

Setup in two to three weeks; operations monthly.

Governance

Policy pack and security knowledge base

You get

A sequenced set of policies across the domains an audit or customer will ask about (information security, acceptable use, access, data classification, vendor, incident, change, business continuity, and others as scoped), written for the people who must follow them, plus an audience-first knowledge base structure separating public guidance, restricted material, and templates.

Why it is worth doing

Policies that no one can find or read are a liability in an audit and useless in an incident. A readable set with owners and a home shortens every future questionnaire and readiness effort.

Three to five weeks depending on the number of domains.

Risk

Enterprise risk register and KRI model

You get

A source-backed risk register with each risk tied to evidence, exposure, an owner, a remediation action, and a decision path; a set of key risk indicators leadership can track; a risk-appetite workshop; and a policy-exception workflow.

Why it is worth doing

Leadership cannot set risk appetite from a finding list. A register that connects evidence to owners and indicators turns security risk into decisions with a record, and it is the backbone of every executive brief that follows.

Three to four weeks for the first version; maintained inside a retained cadence.

Access

Zero Trust and secure access business case

You get

An assessment of remote access, private-application exposure, and identity controls; a prioritized proposal (MoSCoW) with resource needs, continuity considerations, known risks, and mitigations; vendor evaluation criteria; and a rollout and exception-handling plan.

Why it is worth doing

Legacy remote access is one of the most common paths into a company and one of the hardest projects to get funded without a clear case. A proposal leadership can approve, with the rollout risks named, is what moves it from a wish to a program.

Three to four weeks for the case; rollout support by agreement.

Productivity suite

Google Workspace and Microsoft 365 security review

You get

A read-only review of identity and MFA, admin roles, mail authentication (SPF, DKIM, DMARC), external sharing, device and session controls, audit logging, and retention against current vendor and CIS baselines, with a sequenced hardening list your admin can execute.

Why it is worth doing

Your productivity suite is your identity provider, your document store, and your primary phishing surface. Most of the fixes are configuration, not spend; the value is knowing which ones matter first.

One to two weeks. Hardening support available by agreement.

Cloud

Cloud security posture review

You get

A read-only review of AWS and GCP (Azure on request) covering IAM and privilege, encryption, logging and monitoring, network and public exposure, instance metadata, and backup posture; findings ranked by business impact and sequenced against engineering capacity, with owners.

Why it is worth doing

Cloud findings without a sequence do not get fixed. A ranked list your engineers agree with, and a plan that respects their capacity, is what turns a scanner report into fewer findings carried quarter to quarter.

Two to three weeks. Trusted open-source or vetted vendor tooling is used only where scoped in together.

Assurance

SOC 2, ISO 27001, and ISO 42001 readiness lead

You get

Scope and control mapping, a gap assessment, control ownership across functions, evidence operations (including platform setup such as Vanta or equivalent), policy rollout, remediation tracking, and liaison with the audit firm you choose. Not an audit and not an attestation; you select and contract the auditor directly.

Why it is worth doing

Enterprise customers and insurers ask for these, and readiness is where most of the cost and delay hides. A lead who owns the evidence system and keeps other functions on schedule gets you to the audit sooner and with fewer surprises, without building a paperwork factory.

SOC 2 and ISO 27001 typically eight to sixteen weeks to readiness; ISO 42001 pairs naturally with the AI governance sprint.

Not sure which one you need?

Bring the decision or milestone in front of you to a 20-minute fit call. You will leave with a recommendation — including if it is none of these.

Book a fit call