§ DSE Cybersecurity·the core-security front door

Core cybersecurity services for growing firms.

We reduce the chance of email fraud, ransomware, credential theft, vendor risk, and unsafe AI use, and we give leadership a clear plan to fix the gaps that matter most. Most security incidents at companies this size do not come from sophisticated attackers. They come from the basics being undone. We give you a clear, prioritized picture, the policies and baseline to close the gaps, and ongoing senior leadership to keep them closed. Federal-grade rigor, scaled to a growing company's budget and stage.

NIST CSF CIS Controls NIST AI RMF OWASP LLM Top 10 RMF / ATO CMMC-aware
Book a free 30-minute Cyber Risk Check See the division catalog → for growing and mid-market companies across the United States
§ Choose your route·one security practice, two distinct problem sets

Start with the risk you need to own now.

Core cybersecurity
Secure the business

Assess the controls that protect people, identities, cloud environments, vendors, backups, and business operations. Start here for conventional cyber risk, ransomware readiness, compliance evidence, or ongoing security leadership.

Explore core cybersecurity services →
AI system security
Secure AI systems

Test and govern LLMs, agents, models, AI vendors, and AI-enabled workflows. Start here when the risk is specific to how an AI system behaves, uses data, calls tools, or fails under attack.

Explore AI system security →

The basics, undone, cause most incidents.

An executive without MFA, a backup nobody has tested, a contractor with standing access nobody revoked, an employee pasting client data into a public AI tool. This is the division built for the person who owns security risk, whether that is a dedicated security lead or CISO, or the COO, VP of Engineering, or owner carrying that load at a company without one. Growing and mid-market companies (roughly 50 to 500 employees) and funded startups, without a full internal security team and not ready to hire one, but past the point where "we'll deal with it later" is safe.

5 to 10
business days for a Security Foundations Assessment, the deeper paid step that turns the catalog into one prioritized picture. Leadership knows the risk is there. They just do not have a clear, prioritized picture of where it sits or what to fix first.
§ The deeper assessment·Security Foundations Assessment · six named deliverables
01
Cyber Risk Assessment

Your security posture mapped against the NIST Cybersecurity Framework and CIS Controls, based on configuration review, interviews, and observable evidence. A ranked gap list: what is most likely to hurt you, and why.

control and configuration assessment · based on what is observable. Not a penetration test and does not claim to find every vulnerability.
Review the national assessment →
02
Microsoft 365 & Identity Configuration Assessment

A point-in-time manual advisory review of client-provided portal exports, screenshots, and screen shares, with findings and a prioritized advisory roadmap.

Review the identity assessment →
03
Vendor & Connected-App Review

Third-party tools, contractors, and OAuth-connected apps that touch your data, with the high-risk grants flagged for removal or tightening.

04
Incident & Ransomware Readiness

Role mapping, executive and technical tabletop exercises, first-hour decision planning, and representative recovery evidence with RTO/RPO context. DSE makes no production changes unless separately contracted and authorized.

Review the readiness engagement →
05 · crossover
Secure AI Use Summary

A focused read on where AI tools are creating data exposure, with rules anchored to the NIST AI RMF and OWASP LLM Top 10. The full version is the AI-path offer; here it is the security-lens summary.

Go deeper on the AI front door →
06
Prioritized Remediation Roadmap

Your next three security moves, plus a 90-day plan sequenced by risk and effort. The document leadership uses to decide where to spend, and it sets up the remediation sprint and the fractional engagement.

§ Method & credibility·federal-grade rigor, by the person doing the work

Delivered by senior practitioners whose security experience comes from regulated financial services and federal environments, where controls are not optional and an audit clock is always running. That background includes authority-to-operate (ATO) documentation under the NIST Risk Management Framework, CMMC-aware federal delivery, cloud security, and identity and access (IAM) and least-privilege architecture as core disciplines. On the AI side, it includes red-teaming of agentic workflows (prompt injection, tool abuse, data exfiltration) and governance under the NIST AI RMF. DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope, while remaining accountable for scope, quality, integration, and outcomes.

§ Platforms & technology ecosystems·categories, not a logo wall

We work across your stack. We name only what we can evidence.

Most companies we meet already own more security technology than they have evidence for. Below are the ten ecosystem categories our work touches: what each one is supposed to deliver for you, what we actually do inside it, and where to go next. We describe categories rather than vendors on purpose. We name a platform publicly only where a reviewed evidence record supports the precise claim, and we publish no vendor logos.

Book a free 30-minute Cyber Risk Check tell us what you already run, and we will tell you what we would review first
Cloud
Cloud environments

What you need from it: a documented view of how your cloud accounts, administrative identities, logging, and internet-facing exposure stand against the control outcomes your board, customers, and insurers ask about. What we do: we review client-provided configuration evidence, architecture documentation, and ownership, rate the gaps by likelihood and business impact, and hand you a sequenced remediation plan. We do not implement, harden, or watch the environment for you.

See the assessment scope →
Identity & productivity
Identity and productivity suites

What you need from it: evidence of where account takeover, standing privilege, and unreviewed access actually sit, in a form a customer or an insurer will accept. What we do: for Microsoft 365 and Microsoft Entra ID we deliver a structured, point-in-time manual advisory review of client-provided portal configuration and exports, with an evidence register, findings, and remediation priorities. This is an owner-approved advisory and evaluation classification with no independent certification, partner, or reseller status. Implementation, hardening, and monitoring require separate evidence and scope. Every other identity or productivity platform is advisory and evaluation context only and is scoped separately with evidence.

See the identity assessment scope →
Endpoint & XDR
Endpoint and extended detection tooling

What you need from it: confidence that the endpoint protection you already pay for is deployed everywhere it belongs, configured to the policy you believe you have, and producing evidence a named owner reviews. What we do: we assess coverage, configuration evidence, exception handling, and ownership against your control baseline, then tell you whether the answer is a configuration change or a different tool. We do not operate the console or work the alert queue.

See the assessment scope →
SIEM & security operations
Logging and security operations tooling

What you need from it: a defensible requirement for what must be logged, retained, and reviewed, and an honest read on whether your current platform and provider meet it. What we do: we define the requirement, review the evidence you can produce today, and run a vendor-neutral selection or renewal review on your behalf. Detection and response are delivered by a provider you contract. DSE does not operate a 24/7 SOC, provide managed detection and response, or perform continuous monitoring.

See the leadership scope →
Network & SASE
Network and edge security

What you need from it: a clear picture of where your network, remote-access, and edge design still assumes a perimeter that no longer exists, and what that exposure is worth in business terms. What we do: we review architecture documentation and client-provided configuration evidence, describe the target design and its trade-offs, and sequence the change against risk and effort. Implementation is executed by your team or by a disclosed specialist we select and remain accountable for.

See the assessment scope →
Vulnerability management
Vulnerability and patch programs

What you need from it: a program that stops measuring scan volume and starts measuring whether the findings that matter get closed, by a named owner, inside an agreed window. What we do: we assess the program rather than the scanner: asset coverage, prioritization logic, exception handling, ownership, and closure evidence. Scanning and remediation execution are scoped separately in writing.

See the assessment scope →
Data security
Data security and governance

What you need from it: a defensible answer to where sensitive data lives, who can reach it, how long it is kept, and what evidence exists that those controls operate. What we do: we review classification, access, retention, and logging evidence and map the gaps to the obligations you actually carry. We advise on where tooling is warranted and how to choose it; we do not deploy or run it, and we do not label the result a compliance outcome.

See the assessment scope →
DevSecOps & AppSec
Secure software delivery

What you need from it: knowledge of which security controls are genuinely enforced in the pipeline and which are a dashboard nobody reads before release. What we do: we review the secure-development controls that matter (branch and release gates, secret handling, dependency and build evidence, and who owns a failing check) then recommend where each control belongs. Tool selection stays vendor-neutral and evidence-led. Application penetration testing is a separate, separately authorized engagement.

See the assessment scope →
Backup & recovery
Backup and recovery

What you need from it: proof that a restore actually works, and recorded recovery-time evidence, before a disruptive event forces the question. What we do: we scope and observe a client-authorized representative restore exercise, record RTO and RPO evidence, and fold the result into your response plan and roadmap. The restore is executed by your team or your provider. DSE makes no production changes unless separately contracted and authorized.

See the readiness scope →
GRC
Governance, risk, and compliance

What you need from it: a risk register, a control map, and a reporting cadence your board and your customers recognize, established before you buy a platform to hold them. What we do: we define the program and the evidence model first, then advise on whether a governance or compliance-automation platform is warranted and how to select one. Readiness work prepares you for an examination; it is not an audit, a certification, or an attestation, and accredited bodies retain those roles.

See the leadership scope →

How we name platforms. The two platforms named in the identity and productivity card above are the only ones we name publicly, under an owner-approved advisory and evaluation classification with no independent certification, partner, or reseller status. Every other platform in these categories is advisory and evaluation context only, never a hands-on implementation claim, and is scoped separately with evidence before it appears in an engagement or in public copy. We publish no vendor logos.

How the work is delivered. DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.

What this section is not. Nothing here is a claim that DSE operates a 24/7 SOC, provides managed detection and response, performs continuous monitoring, delivers live digital forensics and incident response (DFIR), runs penetration tests, resells licenses, or holds a formal vendor relationship. Assessment work is point-in-time, and it is not an audit, a certification, an attestation, or a guarantee of a compliance, insurance, or contract outcome.

Scope your stack in a free 30-minute Cyber Risk Check See the assessment scope →
§ Regulated readiness lanes·four obligations, four entity types

If a rule already binds you, start with the rule.

Some buyers do not have a general security question. They have a specific obligation, a named regulator, and an evidence problem. Each lane below is scoped to a different entity type and a different primary authority, cites the rule text rather than a summary of it, states the effective or compliance dates it relies on, and says plainly who it is not for. Readiness and advisory work in every case. None of it is legal advice, an audit, a certification, an attestation, or a guarantee of a compliance, enforcement, insurance, or contract outcome.

Book a free 30-minute Cyber Risk Check tell us which obligation is driving the deadline, and we will tell you whether a lane fits
FTC Safeguards
FTC Safeguards Rule readiness

For: non-bank businesses that the Rule itself calls financial institutions, under FTC jurisdiction per 16 CFR 314.1(b). Not for: banks, savings associations, and federally insured credit unions supervised elsewhere, or entities not significantly engaged in financial activities. Covers the 16 CFR 314.4 elements end to end.

See the Safeguards lane →
Reg S-P
Regulation S-P incident response readiness

For: covered institutions as 17 CFR 248.30(d)(3) defines them, broker-dealers, investment companies, SEC-registered advisers, and registered transfer agents. Not for: banks, FTC-jurisdiction firms, or advisers not registered with the Commission. Both tiered compliance dates have passed.

See the Reg S-P lane →
HIPAA
HIPAA Security Risk Analysis support

For: covered entities and business associates that create, receive, maintain, or transmit ePHI. Not for: organizations with no ePHI in scope, or anyone seeking a HIPAA certification, which does not exist. Support for your own obligation at 45 CFR 164.308(a)(1)(ii)(A); BAA terms remain a separate legal matter.

See the HIPAA lane →
Cyber insurance
Cyber insurance evidence readiness

For: organizations preparing an application, a renewal, or a post-quote control condition. Not for: anyone wanting coverage placed, a coverage opinion, or claim advocacy. DSE is not a broker, does not place coverage, cannot speak for any carrier, and guarantees no eligibility, premium, or claim outcome. No federal rule governs this lane and we do not invent one.

See the insurance lane →
Underneath all four
The same evidence method

Every lane rides on the assessment method behind our national risk assessment: a bounded evidence request, focused interviews, business-context severity, and a roadmap with named owners. Where two obligations ask for the same artifact, we produce it once. Where the honest answer is that a rule does not reach you, we say so in the diagnostic call rather than sell you a lane.

See the assessment method →

How we cite. Each lane cites primary sources only, the eCFR text of the rule, the Federal Register rulemaking record, and the NIST publications a rule incorporates. Current requirements are separated from proposed rules on the page itself, and a proposal is never described as a requirement. We publish no enforcement counts, penalty averages, claim-denial rates, or breach statistics, because we could not source those from a primary source.

What these lanes are not. Readiness and advisory work, point-in-time, scoped in writing. Not legal advice, not an audit, not a certification, not an attestation, and not a regulatory examination. No guarantee of compliance, an enforcement or examination outcome, insurance coverage or eligibility, or a contract award. Your counsel, auditors, assessors, and carriers retain their respective roles, and we do not take any of them on. No lane makes your organization secure and none prevents, detects, or reduces the likelihood of any security incident; each documents risk against a defined scope at a point in time.

Scope your obligation in a free 30-minute Cyber Risk Check See the assessment scope →
§ Technical security assessments & program design·five focused, evidence-backed offers

When the question is technical, go straight to the offer.

Some buyers already know where the risk sits: the cloud is configured by hand, identity has sprawled, a vendor set nobody has tiered, a vulnerability program that measures scan volume instead of closure, or a delivery pipeline whose security gates may not hold. Each offer below is a focused, point-in-time engagement built on the same bounded-evidence method: a defined evidence request, focused interviews, business-context severity, and a roadmap with named owners. Every one is advisory and readiness work, vendor-neutral by default, and priced after a free diagnostic.

Book a free 30-minute Cyber Risk Check tell us which technical risk is driving the work, and we will tell you which offer fits
Cloud
Cloud security architecture & configuration assessment

Prove your cloud accounts, administrative identities, exposure, and logging match the control outcomes your board and insurers ask about, and get a sequenced plan to close the gaps. Vendor-neutral.

See the cloud assessment scope →
Identity
IAM, privileged access & Zero Trust roadmap

Turn identity sprawl and standing privilege into a staged Zero Trust roadmap, mapped to NIST SP 800-207, that a named owner can execute against.

See the identity roadmap scope →
Third parties
Vendor & SaaS security review

Tier the non-AI vendors, SaaS tools, and connected apps that touch your data, and flag the access that should be removed or tightened. AI-vendor risk has its own review.

See the vendor review scope →
Vuln program
Vulnerability management program design

Stop measuring scan volume and start proving that the findings that matter get to a named owner and close inside an agreed window. DSE designs the program; it does not run scans.

See the program-design scope →
AppSec
Secure SDLC & AppSec program review

Find out which security gates in your delivery pipeline actually hold before release, who owns a failing check, and where secrets and dependencies are exposed. Vendor-neutral.

See the AppSec review scope →

How the work is delivered. DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.

What these offers are not. Each is point-in-time advisory and readiness work based on client-provided evidence. None is legal advice, an audit, a certification, an attestation, or a guarantee of a compliance or security outcome. DSE does not operate a 24/7 SOC, provide continuous monitoring or managed detection and response, perform live incident response or DFIR, run penetration tests, or resell licenses. Remediation implementation is performed only where it is separately scoped in writing.

Scope the right offer in a free 30-minute Cyber Risk Check See the assessment method →
§ Diagnostic tools & proof assets·free, browser-local, nothing sent to us

See the work before you commission it.

Every offer above has a free companion you can use today: interactive diagnostics you run in your own browser and print-ready proof deliverables that show the format a finished engagement produces. Nothing is sent to us. They are grouped below by the decision each one helps you make.

Assess, know where you stand: a NIST CSF 2.0 current-vs-target profile workbook, a CISA CPG baseline scorecard, and a synthetic assessment sample excerpt so you can read a finished deliverable before you scope one.

Prepare, be ready before the bad week: the incident-response first-60-minutes decision card settles who decides in the first hour, and the backup & recovery test worksheet shows whether a restore actually works and records the recovery time.

Decide, buy the roles in the right order: the vCISO vs MSP vs MDR comparison separates who sets direction, who runs the estate, and who watches the alerts.

Insure, answer the questionnaire accurately: the cyber-insurance evidence checklist assembles the artifacts an application asks you to attest to.

Identity, pull the evidence first: the identity evidence checklist lists the sign-in, mail-flow, and logging evidence to gather before an identity review.

Browse all free diagnostic tools & proof assets → Turn a diagnostic into a plan in a free 30-minute Cyber Risk Check
§ Offer ladder·from free door to recurring
Free door
30-Minute Cyber Risk Check
Identify highest-risk gaps and your next three moves.
Free
Assess
Security Foundations Assessment
The deeper fixed-scope assessment above. Scope and price are confirmed in writing after the Cyber Risk Check.
scoped after the check
Execute
30-Day Remediation Sprint
Execute the top priorities from the roadmap. Scoped and fixed-fee off the findings.
from $7,500
Ongoing
Fractional Security Leadership
Ongoing senior security ownership, typically 10 to 20 hours per week.
$5,000 to $10,000 / mo
Assessment tiers · fixed fee, no time-and-materials · 50% on kickoff, 50% on delivery
TierScopeInvestment
EssentialsSingle environment, team under ~75. All six deliverables, written readout.$2,500
FoundationUp to ~250 employees. Adds deeper vendor and supply-chain review and a live leadership readout.$3,750
Foundation+Up to ~500 employees or a regulated environment. Adds a board-ready deck and a 30-day check-in.$5,000

Priced as an approvable expense, not a procurement event.

§ What is out of scope·boundaries are a credibility signal

Assessment and advisory, not a SOC.

§ Two front doors·cybersecurity help or AI help

Is the risk inside an AI system? Use the specialist route.

This page owns conventional cybersecurity intent. If the risk centers on an LLM, agent, model, AI vendor, or AI-enabled workflow, the AI system security pillar owns that specialty. The Secure AI Use Review remains the crossover point for employee use of public AI tools.

Explore AI system security → Our security & compliance posture →

Would your backups actually restore? Find out in 30 minutes.

Most companies your size are one tested backup, one MFA gap, or one over-permissioned vendor away from a bad week. No pitch, just your top gaps and next three moves.

Book a free 30-minute Cyber Risk Check Scope a call →