Core services

  • CMMC and NIST 800-171

    A prime contractor is asking about CMMC.

    Scoping, gap assessment, documentation and evidence for defense contractors that handle Federal Contract Information or Controlled Unclassified Information.

    • Scoping: where CUI and FCI live, and which systems, people and providers are in scope
    • A gap assessment against all 110 NIST SP 800-171 requirements
    • A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M)
    Explore CMMC readiness
  • Assessments and SOC 2

    A customer wants your SOC 2 report before they sign.

    Honest baselines and audit readiness: gap assessments, SOC 2 preparation, security budget right-sizing and independent technology reviews.

    • A gap assessment against the framework that matters to you: SOC 2, NIST CSF 2.0, CMMC or your own objectives
    • A prioritized remediation roadmap with owners, effort and cost
    • SOC 2 readiness: scoping, control design, policies and evidence collection
    Explore Assessments & SOC 2
  • Virtual CISO

    You need a CISO, not a full-time hire.

    Part-time or interim security leadership: strategy, board reporting, budgets, and ownership of CMMC, SOC 2 and NIST programs.

    • A security strategy and roadmap tied to your business objectives
    • Board and executive reporting in plain language
    • Ownership of compliance programs such as CMMC, SOC 2 and NIST CSF
    Explore Virtual CISO
  • Zero Trust and cloud

    Your network outgrew its perimeter.

    Zero Trust architecture, identity and device security, secure cloud migrations and remote workforce reviews, hosted, on-premises or hybrid.

    • A Zero Trust maturity assessment against NIST SP 800-207 and the CISA Zero Trust Maturity Model
    • A target architecture and a phased roadmap
    • Identity and access: MFA, conditional access and least privilege
    Explore Zero Trust & cloud security

Specialist capabilities

Delivered on their own or as part of a core engagement.

  • Cyber BAMCIS training

    Our planning and decision method, taught to your leadership team and written into policy and incident response.

  • IV&V technology review

    An independent check that a security product can deliver what it promises, with a head-to-head comparison when you need one.

  • Cyber budget right-sizing

    Your technology, people and contracts measured against your objectives, so spending follows risk.

  • Managed security services

    Hosted security capabilities: design, monitoring, SIEM and alerting, with experienced people behind them.

  • Advisory and engineering

    Security architecture, security operations center design and solution engineering.

  • Walls of Tartarus

    Deception and resilience engineering that makes your environment a confusing, costly target, so attackers look elsewhere.

  • Remote workforce security

    A review of how your people work remotely today, and a plan to make it secure without slowing them down.

  • Secure cloud transitions

    Security expertise for a full or partial move to cloud or hybrid environments.

  • Briefings and speaking

    Executive and conference briefings on adopting federal cybersecurity standards in the private sector.

Tell us what’s driving the deadline

One short call is enough to know whether we’re the right fit and what the work would take.