The Anchor Path
How we build and run your information security risk program.
Five phases that turn uncertainty into a managed, measured risk program. Discover, Assess, and Treat build the foundation; Monitor and Assure keep it running and prove it works.
01
Discover
Weeks 1–3
We learn how your business makes money, what it can’t afford to lose, and where your sensitive data and critical systems live.
What we do
- Stakeholder interviews across leadership, IT, engineering, and operations
- Crown-jewel asset and data-flow inventory
- Threat landscape review for your industry
- Vendor and third-party inventory
You receive
- Asset and data-flow map
- Initial threat profile
- Scope for the risk assessment
02
Assess
Weeks 3–6
We measure the risk to what matters — in terms leadership understands — and agree on how much risk the business is willing to carry.
What we do
- Likelihood and impact scoring for each risk scenario
- FAIR-based quantification of top risks
- Control effectiveness review
- Risk appetite workshop with leadership
You receive
- The Risk Ledger, ranked by business impact
- Risk appetite statement
- Executive risk briefing
03
Treat
Months 2–6
We decide what to do about each risk, then work alongside your people to get it done.
What we do
- Treatment decisions: mitigate, transfer, accept, or avoid
- Control design and implementation with named owners
- Policies and procedures that fit your operations
- Insurance and contract alignment for transferred risk
You receive
- 12-month treatment roadmap tied to risk reduction
- Implemented, owned controls
- Documented risk acceptances with expiry dates
04
Monitor
Monthly, ongoing
Risk changes every week. We watch the indicators that tell you whether it’s rising or falling.
What we do
- Key risk indicator and control health checks
- Vulnerability, access, and vendor risk tracking
- Emerging threat and AI risk review
- Risk Ledger updates as the business changes
You receive
- Monthly risk dashboard
- Issue log with owners and due dates
- Early warning when risk is rising
05
Assure
Quarterly & annually
We prove the program works — to your board, customers, insurers, and auditors.
What we do
- Quarterly board and executive risk reporting
- Readiness testing and evidence packages
- Auditor and assessor coordination (SOC 2, ISO 27001, HIPAA, HITRUST, and more)
- Annual risk reassessment and program plan
You receive
- Board-ready risk report
- Audit and certification support
- Year-over-year maturity scoring
How we work with you
Principles that don’t change from client to client.
Risk first
Every control earns its place by reducing a risk you actually carry. If it doesn’t, we’ll tell you — even when a checklist says otherwise.
Your team, stronger
We build capability, not dependency. Your people own the controls; we make sure they know why each one matters and how to keep it working.
No surprises
Fixed scope, a visible roadmap, and regular status updates. You’ll know what we’re doing, what it costs, and what’s left at every point.
Ready to find out where you stand?
Most engagements start with Discover and Assess — the fastest way to replace uncertainty with a ranked list of risks and a plan.