How we work
A Gold engagement runs about twelve months. You see progress every quarter and a documented program at the end.
Months 1 to 3: foundation
Assessment, risk register, and fixes for the critical gaps first: multi-factor authentication, privileged access and backups. Policy writing begins.
Months 4 to 6: network and compliance
Network redesign and segmentation, plus the compliance program for FTC Safeguards and IRS Publication 4557.
Months 7 to 9: advanced controls
Monitoring and logging, endpoint detection, and a rehearsed incident response plan.
Months 10 to 12: test and improve
Technical testing, the annual IT security audit, and the roadmap for year two.
Throughout, you get a named lead, monthly reporting in plain language, and employee training. Your IT provider keeps running the systems; we direct what they protect and how.
Find out where your firm stands.
A 30-minute call covers your current controls, the rules that apply to you, and what a first 90 days would look like. No cost, no sales deck.