Project
First security program
A customer asked for something you do not have, and there is a date on it. Nothing is written down yet.
Good fit: First enterprise customer, first diligence, first time someone said "send us your security documentation."
What this covers
- Policies in your voice. A policy that does not describe how your company works is a liability in diligence.
- The controls that matter for your stack, and openly not the ones that do not.
- The tooling to run it, set up rather than recommended.
- Evidence collected as you go, so the audit is not a scramble at the end.
- The path to SOC 2 or ISO 27001, if a customer actually requires it.
What it doesn't
Worth saying plainly. The boundary is what makes the rest of it credible.
- Issue the report
You should never hire the same firm to build and to grade. We get you ready and sit with you through it.
- Sell you the full framework on day one
We find out what the buyer requires first. It is usually less than they asked for.
- Hand you a hundred-page assessment
The output is a working program, not a document about one.
The first two weeks
- Week one
What the buyer actually requires, confirmed with them where we can. This is where most of the scope disappears.
- Week two
The shortest credible path, written down, with the first controls already in place.