
The first thirty days are the assessment.
Nothing is guessed at. The register and the roadmap come out of the first month, and the retainer then runs against them.
- Assessment
A technical and organisational review of where you actually stand, rather than where the last report said you stood.
- Leadership interviews
We talk to your executive team, your IT lead, and whoever currently carries security. Most of the real risks surface here.
- Risk baseline
The register, scored and written down, with the risks that matter separated from the ones that only look urgent.
- Twelve-month roadmap
Sequenced, costed and agreed with you. This is the plan the rest of the engagement runs against.
- Ongoing CISO ownership
Continuous ownership begins: a monthly executive decision session, quarterly board reporting, and the register, the roadmap and the supplier questions carried between them.
Thirty days to prove one.
A first conversation takes about thirty minutes and costs nothing.