Engagement plans
Three ways to work with us.
Each plan is fixed-scope and quoted up front after a short discovery call. Start with the one that matches where you are — organizations often move from Blueprint to Keystone to Sentinel over time.
Blueprint
Know your risk
A focused risk assessment for organizations that need a clear, ranked picture of their exposure and a credible plan.
- Crown-jewel asset and data-flow mapping
- Information security risk assessment
- Quantified view of your top risk scenarios
- Your Risk Ledger and 12-month treatment roadmap
- Executive risk briefing
Recommended
Keystone
Reduce what matters
A full program build: we assess your risk, then work alongside your team to treat it — audit-ready along the way.
- Everything in Blueprint
- Risk treatment with weekly working sessions
- Policies, procedures, and controls with named owners
- Risk appetite and acceptance process
- Unified control set mapped to your frameworks
- Audit readiness and fieldwork support
Sentinel
Your ongoing vCISO
Fractional security leadership and continuous risk monitoring that keep your risk picture current and your board informed.
- Named vCISO for strategy, board, and customer needs
- Monthly key risk indicators and control health
- Quarterly Risk Ledger review and board report
- Annual risk reassessment and program plan
- Incident response tabletop exercise
- Audit, insurance, and questionnaire support
Which plan fits?
A quick guide.
Choose Blueprint if…
- You don’t have a clear, ranked picture of your top risks
- Leadership needs a budget number and a plan
- You have capacity to execute, but want an expert roadmap
Choose Keystone if…
- You know your risks and need help reducing them
- A customer, regulator, or auditor has set a deadline
- You don’t have a dedicated security team
Choose Sentinel if…
- You need senior security leadership without a full-time hire
- The board wants regular, meaningful risk reporting
- You want to stay ahead of new threats and requirements
Common questions
Before you reach out
How is pricing set?
Every plan is quoted as a fixed fee after a short discovery call. Scope drivers are the size and complexity of your environment, how many frameworks you answer to, and how much of the work your team wants to own. You’ll have the number in writing before any work starts.
Is this a compliance engagement?
It’s a risk engagement that makes compliance easier. We start with what matters to your business and build controls that reduce real risk. Those same controls — mapped once — produce the evidence for SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, and privacy laws.
Do you perform the audit itself?
Certification audits and attestation reports are issued by independent firms (for example, a CPA firm for SOC 2 or an accredited certification body for ISO 27001). We prepare you, coordinate with them, and support you throughout. Where we offer assessment services, such as HITRUST, we keep advisory and assessment work separate as independence rules require.
What do you need from our team?
An executive sponsor, a day-to-day point of contact, and access to the people who run your systems. We work around your schedule and keep meetings short and purposeful.
Let’s find the right starting point.
Share a little about your situation and we’ll recommend a plan and give you a fixed quote.