Where are we?
A documented baseline.

We establish where you are, what matters, what happens next and who owns it.
The register and the roadmap come out of the first month, and the retainer then runs against them.
Technical and organisational review, existing suppliers, controls, obligations, incidents and previous assessments. We establish where you actually stand, rather than where the last report said you stood.
Leadership interviews and technical review expose the gap between documented security and operational reality. Most of the real risks surface here.
The risk register, scored and written down, with the risks that matter separated from the ones that only look urgent.
A sequenced, costed rolling security roadmap, prioritised across the next 12 months and agreed with leadership. This is the plan the rest of the engagement runs against.
Day 31Ownership
Now ongoing CISO ownership begins.
A documented baseline.
A prioritised risk register.
A rolling security roadmap.
Named accountability.
Clear decisions, costs and trade-offs.
Ownership, reporting, decision-making.
Identity, endpoints, cloud, infrastructure and external attack surface.
IT providers, MSPs, critical vendors and internal responsibilities.
Incident readiness, backup, recovery and business continuity.
Customer requirements, insurance, regulation and compliance.
At the end of the first 30 days, you receive the baseline, risk register and rolling security roadmap.
If we haven’t delivered the agreed cybersecurity foundation for reasons within our control, you don’t pay.
If we have, the first quarterly payment becomes due and we move from assessment to ongoing ownership.
From month two, Secure & Scale shifts from establishing the plan to driving it.
We maintain the risk register, drive the roadmap, challenge suppliers, prepare leadership decisions and report progress to the board.
A first conversation takes about thirty minutes and costs nothing.