Engagement Plans

Blueprint, Keystone, and Sentinel — fixed-scope plans to assess, reduce, and continuously manage your risk.

Engagement plans

Three ways to work with us.

Each plan is fixed-scope and quoted up front after a short discovery call. Start with the one that matches where you are — organizations often move from Blueprint to Keystone to Sentinel over time.

Blueprint

Know your risk

A focused risk assessment for organizations that need a clear, ranked picture of their exposure and a credible plan.

Typically 3–6 weeks · Anchor Path: Discover + Assess

  • Crown-jewel asset and data-flow mapping
  • Information security risk assessment
  • Quantified view of your top risk scenarios
  • Your Risk Ledger and 12-month treatment roadmap
  • Executive risk briefing

Sentinel

Your ongoing vCISO

Fractional security leadership and continuous risk monitoring that keep your risk picture current and your board informed.

Annual subscription · Monitor + Assure

  • Named vCISO for strategy, board, and customer needs
  • Monthly key risk indicators and control health
  • Quarterly Risk Ledger review and board report
  • Annual risk reassessment and program plan
  • Incident response tabletop exercise
  • Audit, insurance, and questionnaire support

Which plan fits?

A quick guide.

Choose Blueprint if…

  • You don’t have a clear, ranked picture of your top risks
  • Leadership needs a budget number and a plan
  • You have capacity to execute, but want an expert roadmap

Choose Keystone if…

  • You know your risks and need help reducing them
  • A customer, regulator, or auditor has set a deadline
  • You don’t have a dedicated security team

Choose Sentinel if…

  • You need senior security leadership without a full-time hire
  • The board wants regular, meaningful risk reporting
  • You want to stay ahead of new threats and requirements

Common questions

Before you reach out

How is pricing set?

Every plan is quoted as a fixed fee after a short discovery call. Scope drivers are the size and complexity of your environment, how many frameworks you answer to, and how much of the work your team wants to own. You’ll have the number in writing before any work starts.

Is this a compliance engagement?

It’s a risk engagement that makes compliance easier. We start with what matters to your business and build controls that reduce real risk. Those same controls — mapped once — produce the evidence for SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, and privacy laws.

Do you perform the audit itself?

Certification audits and attestation reports are issued by independent firms (for example, a CPA firm for SOC 2 or an accredited certification body for ISO 27001). We prepare you, coordinate with them, and support you throughout. Where we offer assessment services, such as HITRUST, we keep advisory and assessment work separate as independence rules require.

What do you need from our team?

An executive sponsor, a day-to-day point of contact, and access to the people who run your systems. We work around your schedule and keep meetings short and purposeful.

Let’s find the right starting point.

Share a little about your situation and we’ll recommend a plan and give you a fixed quote.