Services

Three engagements.
All of them end in evidence.

Each one starts with an applicability review, because recommending controls before knowing what actually binds you is how compliance budgets get wasted. Everything is structured on NIST CSF 2.0, so the work compounds instead of stacking up.

Financial services

FTC Safeguards Rule Compliance

The rule covers any business significantly engaged in financial activities, which reaches far past banks: lenders, auto dealers, tax preparers, mortgage brokers, title companies, insurance-adjacent firms. Most discover they are covered late. Civil penalties run to tens of thousands of dollars per violation per day, and being non-compliant when a breach happens can also void your cyber insurance.

What happens

Coverage determination: whether the rule applies to you, and on what basis
Written Information Security Program (WISP) built around how you actually operate
Qualified Individual designation and the board or senior-officer reporting cycle
Risk assessment, access control, encryption and MFA review
Service provider contracts and ongoing vendor monitoring process
Incident response plan, tested, including the FTC 30-day notification trigger

What you keep

Coverage memo you can show counsel or an insurer
Complete WISP, ready to approve
Written risk assessment and remediation plan
Vendor register with security requirements and review criteria
Incident response plan and annual report template for your board

Firms with fewer than 5,000 consumer records are exempt from some elements, such as the written risk assessment and annual board report, but not from the rule itself. Part of this engagement is establishing exactly where you sit.


Healthcare

HIPAA Security Readiness

For providers, health plans and the business associates that serve them: software vendors, billing firms, IT providers, medical transcription. Enforcement has not slowed while the Security Rule overhaul is pending, and incomplete or missing risk analysis remains the single most cited failure in OCR settlements. The overhaul itself points clearly at where things are heading: encryption, MFA, asset inventory, regular testing.

What happens

Scope of ePHI: where it lives, who touches it, which vendors hold it
Security Rule risk analysis documented to withstand OCR review
Administrative, physical and technical safeguards mapped to your operations
Business associate agreement review and vendor due diligence process
Breach response playbook covering HIPAA and the 30-day Florida FIPA clock
Readiness review against the proposed Security Rule changes, so remediation is not done twice

What you keep

Risk analysis report and risk management plan
Policy and procedure set, ready to approve and issue
ePHI asset inventory and data flow map
BAA and vendor register with assessment criteria
Breach response runbook with notification templates
Workforce training outline

If you are a business associate selling into health systems, this engagement also equips you to answer customer security questionnaires without improvising each time.


AI governance

AI Governance Program

Your staff are already using AI tools, with or without a policy. Customers, insurers and regulators have started asking what controls sit around them. This engagement builds that layer: what is in use, what risk it carries, who reviews it, and what evidence exists that the oversight is real rather than declared.

What happens

Discovery of AI systems in use, including features embedded in tools you already licensed
Risk classification per use case, aligned to the NIST AI RMF
Acceptable use, data handling and human oversight policy
Review of what your AI vendors do with your data, under their actual contract terms
ISO 42001 management system structure where certification is a goal
EU AI Act exposure review if you have European operations or customers

What you keep

AI system inventory with risk tiers and owners
AI governance policy and oversight model
Vendor assessment questionnaire and register
Roadmap toward ISO 42001 alignment or certification
Board-level briefing on your AI risk posture

This is the area where most security consultants have nothing to offer yet. If AI use is what triggered your question, start here.


Next step

Not sure which one?
That is what the call is for.

Thirty minutes, no charge. If nothing here fits your situation I will tell you that.

Book a scoping call

+1 786 664 1200