A Disciplined Path from Insight to Outcome
Every engagement follows a proven, framework-aligned methodology — scaled to your organization, delivered by senior advisors, and measured against outcomes that matter to leadership.
Five Phases. One Accountable Advisor.
Our methodology adapts to a two-week assessment or a multi-year transformation, while keeping the same rigour and transparency.
PHASE 01
Discover
1–2 weeks
Understand mission, risk appetite, obligations and stakeholders before forming any view.
- Executive and stakeholder interviews
- Document and policy review
- Regulatory and contractual obligations mapping
- Scope, success criteria and rules of engagement
Key deliverable
Engagement charter & stakeholder map
PHASE 02
Assess
2–4 weeks
Establish an evidence-based baseline against recognized frameworks.
- Control and maturity assessment (NIST CSF 2.0, CIS, ISO 27001)
- Technical reviews and validation where in scope
- Risk identification and rating
- Gap analysis against target state
Key deliverable
Current-state assessment & risk register
PHASE 03
Design
1–3 weeks
Translate findings into a prioritized, funded and realistic plan.
- Target-state architecture and operating model
- Prioritized roadmap (quick wins, 6/12/24 months)
- Budget and resourcing options
- Lab validation of key recommendations
Key deliverable
Strategic roadmap & executive briefing
PHASE 04
Deliver
Engagement-specific
Implement alongside your team with clear governance and accountability.
- Policy, standard and procedure development
- Program and project leadership
- Vendor selection and oversight
- Knowledge transfer to internal staff
Key deliverable
Implemented controls & program artefacts
PHASE 05
Sustain
Ongoing
Measure, report and continuously improve so gains are not lost.
- KPI / KRI dashboards and metrics
- Board and leadership reporting
- Periodic reassessment and tabletop exercises
- Emerging risk monitoring (e.g., AI, regulation)
Key deliverable
Quarterly assurance reporting
Flexible Ways to Work Together
Choose the model that matches your need today — many clients begin with an assessment and progress to fractional leadership.
Fixed scope · Fixed fee
Assessment Engagements
Time-boxed diagnostics that give leadership an independent, evidence-based view of posture and priorities.
- Cybersecurity maturity assessment
- Cloud security & governance review
- AI readiness and risk assessment
- Vendor / third-party risk review
Defined outcomes · Milestone-based
Project Engagements
Outcome-driven initiatives with clear deliverables, milestones and acceptance criteria.
- Security program build-out
- Incident response plan & tabletop
- Business continuity / DR planning
- Technology roadmap & procurement advisory
Monthly retainer
Fractional Leadership
Ongoing executive leadership — vCISO or fractional CIO — embedded with your team at a fraction of a full-time cost.
- Fractional vCISO
- Fractional CIO / technology leadership
- Security program management
- Board and committee reporting
On-demand · Block hours
Advisory & Board Support
Trusted counsel for executives and governing bodies when decisions carry significant technology risk.
- Board cyber risk briefings
- Executive education sessions
- Strategic decision support
- Independent second opinion
How We Protect Quality and Trust
Senior-led, always
Engagements are led directly by a certified senior advisor — never handed off to junior staff after the sale.
Framework-aligned
Findings and roadmaps map to recognized frameworks so they stand up to auditors, insurers and regulators.
Validated in the lab
Key technical recommendations are tested in our Technology Lab before they reach your environment.
Confidential by design
NDAs, least-privilege access, encrypted evidence handling and defined data retention for every engagement.
Executive-ready communication
Every deliverable includes a plain-language executive summary suitable for boards and senior leadership.
Vendor-neutral
No reseller commissions. Recommendations are made solely on fit, risk and value to your organization.
Grounded in Recognized Standards
Our work maps to the frameworks your auditors, insurers, regulators and boards already recognize — in Canada and internationally.