Our Approach

The Anchor Path: Discover, Assess, Treat, Monitor, and Assure — how we build and run your information security risk program.

The Anchor Path

How we build and run your information security risk program.

Five phases that turn uncertainty into a managed, measured risk program. Discover, Assess, and Treat build the foundation; Monitor and Assure keep it running and prove it works.

01

Discover

Weeks 1–3

We learn how your business makes money, what it can’t afford to lose, and where your sensitive data and critical systems live.

What we do

  • Stakeholder interviews across leadership, IT, engineering, and operations
  • Crown-jewel asset and data-flow inventory
  • Threat landscape review for your industry
  • Vendor and third-party inventory

You receive

  • Asset and data-flow map
  • Initial threat profile
  • Scope for the risk assessment

02

Assess

Weeks 3–6

We measure the risk to what matters — in terms leadership understands — and agree on how much risk the business is willing to carry.

What we do

  • Likelihood and impact scoring for each risk scenario
  • FAIR-based quantification of top risks
  • Control effectiveness review
  • Risk appetite workshop with leadership

You receive

  • The Risk Ledger, ranked by business impact
  • Risk appetite statement
  • Executive risk briefing

03

Treat

Months 2–6

We decide what to do about each risk, then work alongside your people to get it done.

What we do

  • Treatment decisions: mitigate, transfer, accept, or avoid
  • Control design and implementation with named owners
  • Policies and procedures that fit your operations
  • Insurance and contract alignment for transferred risk

You receive

  • 12-month treatment roadmap tied to risk reduction
  • Implemented, owned controls
  • Documented risk acceptances with expiry dates

04

Monitor

Monthly, ongoing

Risk changes every week. We watch the indicators that tell you whether it’s rising or falling.

What we do

  • Key risk indicator and control health checks
  • Vulnerability, access, and vendor risk tracking
  • Emerging threat and AI risk review
  • Risk Ledger updates as the business changes

You receive

  • Monthly risk dashboard
  • Issue log with owners and due dates
  • Early warning when risk is rising

05

Assure

Quarterly & annually

We prove the program works — to your board, customers, insurers, and auditors.

What we do

  • Quarterly board and executive risk reporting
  • Readiness testing and evidence packages
  • Auditor and assessor coordination (SOC 2, ISO 27001, HIPAA, HITRUST, and more)
  • Annual risk reassessment and program plan

You receive

  • Board-ready risk report
  • Audit and certification support
  • Year-over-year maturity scoring

See the full risk monitoring plan →

How we work with you

Principles that don’t change from client to client.

Risk first

Every control earns its place by reducing a risk you actually carry. If it doesn’t, we’ll tell you — even when a checklist says otherwise.

Your team, stronger

We build capability, not dependency. Your people own the controls; we make sure they know why each one matters and how to keep it working.

No surprises

Fixed scope, a visible roadmap, and regular status updates. You’ll know what we’re doing, what it costs, and what’s left at every point.

Ready to find out where you stand?

Most engagements start with Discover and Assess — the fastest way to replace uncertainty with a ranked list of risks and a plan.