Skip to content
Project

First security program

A customer asked for something you do not have, and there is a date on it. Nothing is written down yet.

Good fit: First enterprise customer, first diligence, first time someone said "send us your security documentation."

What this covers

  • Policies in your voice. A policy that does not describe how your company works is a liability in diligence.
  • The controls that matter for your stack, and openly not the ones that do not.
  • The tooling to run it, set up rather than recommended.
  • Evidence collected as you go, so the audit is not a scramble at the end.
  • The path to SOC 2 or ISO 27001, if a customer actually requires it.

What it doesn't

Worth saying plainly. The boundary is what makes the rest of it credible.

Issue the report

You should never hire the same firm to build and to grade. We get you ready and sit with you through it.

Sell you the full framework on day one

We find out what the buyer requires first. It is usually less than they asked for.

Hand you a hundred-page assessment

The output is a working program, not a document about one.

The first two weeks

Week one

What the buyer actually requires, confirmed with them where we can. This is where most of the scope disappears.

Week two

The shortest credible path, written down, with the first controls already in place.