Governance
The rules your business runs on.
Most organizations we meet have security controls but no written position — which means no one can say what is allowed, what is prohibited, or who decided. Governance is the cheapest of the three practices and the one that makes the other two defensible.
- IT policy — Acceptable use, device standards, remote access, and the escalation path when something goes wrong — written in language a non-technical director can approve.
- Data-handling guidelines — What class of data may live where, who may move it, how long it is kept, and what happens at disposal.
- AI use policy — Which tools are sanctioned, what may be put into them, what must never be, and how exceptions get approved. The document that lets you say yes to AI instead of quietly saying no.
- Access and identity standards — Joiner, mover and leaver processes; privileged access; MFA and conditional access positions stated as policy rather than as settings.
- Posture documentation — The evidence pack — what is in place, why, and when it was last reviewed — for insurers, auditors and client procurement.
Fixed-fee engagement: Scoped to organization size · Typically delivered in two to four weeks.