The City of London tower cluster at first light, offices still lit against a blue sky.
What happens first

The first thirty days are the assessment.

Steps5 in the first month
AssessmentWeeks one to four
OwnershipFrom month two
Delivered byCornhill Cyber, CISSP

Nothing is guessed at. The register and the roadmap come out of the first month, and the retainer then runs against them.

  1. AssessmentWeek one

    A technical and organisational review of where you actually stand, rather than where the last report said you stood.

  2. Leadership interviewsWeek one to two

    We talk to your executive team, your IT lead, and whoever currently carries security. Most of the real risks surface here.

  3. Risk baselineWeek two to three

    The register, scored and written down, with the risks that matter separated from the ones that only look urgent.

  4. Twelve-month roadmapWeek three to four

    Sequenced, costed and agreed with you. This is the plan the rest of the engagement runs against.

  5. Ongoing CISO ownershipFrom month two

    Continuous ownership begins: a monthly executive decision session, quarterly board reporting, and the register, the roadmap and the supplier questions carried between them.

Thirty days to prove one.

A first conversation takes about thirty minutes and costs nothing.