# Data Science & Engineering Experts (DSE) > A practitioner-led firm that helps healthcare, government, financial-services, and other regulated teams, plus growth and mid-market companies with serious data obligations, adopt AI through three connected service towers: AI governance and readiness, implementation and integration, and private AI plus managed AI operations. DSE prepares organizations for review, audit, buyer diligence, and operational handoff; it does not certify compliance or guarantee audit outcomes. ## Services - [Talent & Delivery Support](https://www.thedataexperts.us/talent-delivery-support.html): Georgia-first contract staffing, direct-hire recruiting, training, project support, administrative support, and rapid consulting with immediate intake. - [Private AI Stack and Managed Operations](https://www.thedataexperts.us/private-ai-security.html): Private AI architecture, secure deployment, dedicated hosting patterns, monitoring, maintenance, model and vendor change review, and evidence upkeep for teams that need stronger control. - [Security services pricing](https://www.thedataexperts.us/security-pricing.html): Published list floors for the security service line, owner-approved 2026-09-05: Security Readiness Check from $1,250, Security Foundations Assessment from $3,500 (cyber; physical security only via a licensed Georgia partner, referral basis), Security Awareness Training from $600/mo for up to 25 users, vCISO Essentials $3,500/mo, vCISO Core from $5,500/mo, vCISO Regulated from $9,000/mo (all vCISO tiers six-month minimum plus a one-time setup fee), Private AI Pilot from $40,000 fixed, Private AI Foundation from $75,000, Private AI Managed Ops from $8,000/mo on a 12-month minimum, and a custom-pricing route for larger estates. Every from price is a floor; the final fee is set at scoping and fixed in writing. Engagement letters are issued only after counsel-reviewed terms and errors-and-omissions coverage are in force for the scope. Readiness and advisory work, not certification or legal advice; DSE does not operate a 24/7 SOC. - [Enterprise BYOC: private AI in your cloud](https://www.thedataexperts.us/byoc.html): The PrivateStack deployment tier where the data plane runs inside a customer-owned AWS account and VPC under customer-managed KMS keys, reached by DSE only through an assumed, least-privilege IAM role. Under the Enterprise BYOC deployment, prompts, completions, retrieval documents, embeddings, audit logs, and backups remain in the customer VPC; control-plane metadata (tenant configuration, entitlements, billing) and operational telemetry are the documented exceptions and carry no content. Includes a row-by-row boundary map with the evidence artifact for each data path, a contrast row for the Hosted tier (DSE-managed infrastructure, inference via a disclosed zero-data-retention inference subprocessor), the four-step engagement path (evaluation call, architecture review, pilot, managed ops), and the limitation that Hosted and Solo tiers do not inherit the BYOC residency posture. AWS is the supported BYOC cloud today. - [PrivateStack: governed AI workspace platform](https://www.thedataexperts.us/work-privatestack.html): DSE's product: a governed AI workspace built on open-weight models like Llama, Mistral, and DeepSeek, with every request logged and exportable, flat $99-per-user-per-month pricing, and an Enterprise BYOC tier deployed inside the customer's own AWS or Azure account. The platform itself lives at privatestackhub.com. - [vCISO for AI programs](https://www.thedataexperts.us/vciso-ai.html): Retained, AI-specific security and governance leadership: AI risk-register ownership, system inventory, policy and evidence upkeep, and board-ready AI risk reporting. Program-wide conventional security leadership starts at the core cybersecurity hub. - [Fractional CISO for Atlanta small business](https://www.thedataexperts.us/fractional-ciso-atlanta.html): Local fractional CISO and vCISO for metro-Atlanta and Gwinnett small businesses, starting with a scored Security Readiness Check and ongoing senior security leadership. - [Partner Program for CPAs, fractional CFOs and MSPs](https://www.thedataexperts.us/partners.html): A tiered referral and white-label program (Referral, Certified, White-label) through which CPA firms, fractional CFO practices and IT managed service providers refer or resell DSE's fixed-fee, point-in-time security and AI risk assessments, fractional CISO retainers and PrivateStack workspaces. Referral fees up to 20% of first-year fees on collected cash; terms provided on acceptance. Certified is DSE's own program designation, not a third-party certification. Partners never receive tenant administration, credentials, client data or product IP. Advisory and orchestration: no 24/7 SOC. - [Startup AI Launch Pack](https://www.thedataexperts.us/startup-ai-launch-pack.html): A fixed-fee AI governance starter pack for startups and small growth firms: AI use-case inventory, acceptable-use policy, vendor review, lightweight risk register, and 90-day roadmap workshop. - [AI governance readiness](https://www.thedataexperts.us/ai-governance-readiness.html): Fixed-fee readiness assessment of AI systems against NIST AI RMF, the EU AI Act, and ISO/IEC 42001, delivering a risk register and audit-ready evidence. - [AI governance consulting](https://www.thedataexperts.us/ai-governance-consulting.html): Enterprise and regulated-team AI governance consulting for inventory, policy, risk tiering, vendor controls, evidence packs, and adoption guardrails. - [Enterprise AI adoption](https://www.thedataexperts.us/enterprise-ai-adoption.html): Consulting to move AI pilots into governed workflows with use-case triage, data readiness, control design, evaluation, implementation planning, and handoff. - [Enterprise AI Control Pack](https://www.thedataexperts.us/enterprise-ai-control-pack.html): Advisory enterprise AI governance control work for complex buyers: federated governance model, committee support, evidence framework, monitoring design, and audit-ready process. - [AI implementation and integration](https://www.thedataexperts.us/ai-implementation-integration.html): Tower 2 delivery path for workflow design, copilots, agents, data integration, control implementation, evaluation, and production handoff. - [Regulated industries AI governance overview](https://www.thedataexperts.us/regulated-industries-ai-governance.html): The comparison layer across healthcare, government, and financial services: what triggers review in each lane, when private AI is justified, and which DSE path usually fits first. - [Banking AI governance](https://www.thedataexperts.us/banking-ai-governance/): AI governance built for US banks, captive finance, and lenders, aligning SR 26-2 model-risk practice (which replaced SR 11-7) with NIST AI RMF and ISO/IEC 42001. - [AI system security (specialty hub)](https://www.thedataexperts.us/ai-security-cyber-risk.html): Security work specific to LLMs, agents, models, AI vendors, and AI-enabled workflows, including testing, vendor risk, incident exercises, privacy reviews, and secure AI deployment. Conventional identity, ransomware, backup, and business-security needs start at the core cybersecurity hub. - [Adversarial AI Assurance](https://www.thedataexperts.us/adversarial-ai-assurance.html): Point-in-time, authorized AI red-team assessment and defensive control engineering for regulated enterprises. The delivery loop connects assessment, customer-owned hardening decisions, and agreed re-test evidence. It is not certification, a compliance audit, continuous monitoring, or a 24/7 SOC. - [Vendor & Third-Party AI Risk Review](https://www.thedataexperts.us/vendor-ai-risk-review.html): A fixed-scope, senior-led AI vendor risk assessment of the third-party AI vendors, embedded models, and API-connected AI tools a firm already uses — what data they touch, how their models are governed, and where concentration and fourth-party risk sit. Delivers a board-ready AI vendor risk register and a remediation roadmap for chief risk officers, third-party/vendor-management leaders, and compliance officers at banks, insurers, and fintechs. Maps findings to the third-party and service-provider expectations that already govern the institution (June 2023 Interagency Guidance on Third-Party Relationships: Risk Management, 23 NYCRR 500.11, Regulation S-P service-provider oversight including the 72-hour vendor breach-notice arrangement, the NAIC AI Model Bulletin third-party expectation, NCUA Letters 07-CU-13 and 01-CU-20, and EU AI Act third-party obligations generically). It is a review — readiness and advisory — not an audit, certification, or penetration test of the vendor. Pairs with the free AI Vendor DDQ Generator. - [Model Risk Management (Lite)](https://www.thedataexperts.us/model-risk-management-lite.html): A proportionate, senior-led model risk management readiness and advisory engagement for mid-market banks (typically under $30 billion in assets) and larger credit unions, right-sized instead of a big-bank model-risk factory. Builds a model inventory, materiality-based risk tiering, a validation-readiness assessment, and effective-challenge and monitoring design for the model risk officer, model validation lead, or CRO. Aligned to SR 26-2 (Revised Guidance on Model Risk Management, issued by the Federal Reserve April 17, 2026; supersedes SR 11-7 and the SR 21-8 BSA/AML statement, with parallel OCC Bulletin 2026-13 and an FDIC statement), which is non-binding, principles-based, and risk- and materiality-based. SR 26-2 explicitly excludes generative AI and agentic AI from its model-risk scope, so DSE routes those systems out of the model perimeter and governs them under the NIST AI RMF, applying SR 26-2 principles by analogy — it does not claim SR 26-2 validates generative or agentic AI. It is readiness and advisory work: DSE prepares models to withstand independent validation and does not validate, certify, or attest to them. Pairs with the free Model Risk Tiering Calculator and the SR 26-2 vs SR 11-7 guide. - [AI Incident Response Tabletop](https://www.thedataexperts.us/ai-incident-response-tabletop.html): A facilitated half-day AI incident response tabletop exercise for financial services that simulates an AI-specific incident — model failure, LLM data leakage, a bias event at scale, deepfake fraud, a poisoned model or dataset, or a regulatory inquiry — for the CRO, CCO, and General Counsel (board- and risk-committee-sponsored), with the CISO and, increasingly, the cyber insurer at the table. Scenarios are tuned to the firm's AI use cases and firm type during scoping, walked in real time on the clock, and followed by a post-exercise gap report and an IR playbook outline organized around the NIST AI RMF functions (govern, map, measure, manage). It is explicitly a readiness simulation and advisory work — NOT a live incident response retainer, NOT forensics or breach remediation, NOT a penetration test, NOT legal advice, and NOT a guarantee of any regulatory, examination, or litigation outcome; no system is touched and no live incident is handled. Regulatory framing stays generic (supervisory expectations, your regulator). Pairs with the free AI Incident Scenario Builder; links to the AI Security & Cyber Risk pillar and the pricing page. Primary CTA scopes a call at /engage.html?problem=ai-security. - [Shadow AI Discovery + Policy Readiness Sprint](https://www.thedataexperts.us/shadow-ai-discovery.html): A fixed-scope 3-4 week engagement for the CCO, CIO/CTO, or AI governance owner (with HR/people-ops and, post-incident, privacy counsel) to identify unsanctioned AI tool usage across the workforce and the data flowing to it, assess policy and control gaps, and deliver an exposure map, a prioritized control roadmap, and an AI acceptable-use policy framework — with a fuller acceptable-use policy build available as a scoped add-on. It is Discovery, not monitoring: work is bounded to accessible systems and agreed data sources (network/SaaS-usage and OAuth-grant inventories, expense and procurement records, and voluntary, non-punitive employee surveys and interviews), and is explicitly not covert surveillance, employee monitoring, or unauthorized system access. Framed with the NIST AI RMF and the generic supervisory expectations that already apply; it is readiness and advisory work, not a certification, legal advice, or a guarantee of any regulatory or examination outcome. Pairs with the free Shadow AI Inventory Quiz; links to the AI Security & Cyber Risk pillar and the pricing page. Primary CTA scopes a call at /engage.html?problem=ai-readiness. - [Privacy / DPIA for AI Systems](https://www.thedataexperts.us/privacy-dpia-for-ai.html): A fixed-scope data protection impact assessment (DPIA) and privacy impact assessment for a defined AI system, for the data protection officer or chief privacy officer (EU and multinationals), in-house privacy counsel, and CRO/compliance leaders in regulated sectors. Adapts the GDPR Article 35 DPIA methodology and US state risk-assessment structure to AI-specific risk factors, and runs a jurisdiction-by-jurisdiction trigger analysis across the GDPR (Article 35 DPIA, Article 22 automated decisions, Article 9 special-category data), the CCPA and CPPA automated decisionmaking technology (ADMT) risk-assessment rules, the Colorado AI Act impact assessment for high-risk systems, and the profiling and automated-decision assessment duties spreading across the US state privacy laws; a fundamental rights impact assessment (FRIA) framing under EU AI Act Article 27 is available where a deployer obligation is in view. Delivers the completed DPIA/PIA, a risk register, a mitigation set, a residual-risk statement, and a scope outline, with a portfolio program (typically five to ten systems) available as a scoped option. It is assessment, readiness, and advisory work: DSE does not provide legal advice, does not certify compliance with the GDPR, the CCPA, the Colorado AI Act, the EU AI Act, or any other law, and does not guarantee any regulatory or enforcement outcome; legal conclusions are for your counsel and DPO. Pairs with the free DPIA Threshold Checker; links to the AI Security & Cyber Risk pillar and the pricing page. Primary CTA scopes a call at /engage.html?problem=ai-privacy-dpia. - [AI Deepfake / Social-Engineering Defense Readiness Assessment](https://www.thedataexperts.us/ai-deepfake-defense-readiness.html): A fixed-scope, advisory readiness assessment of an organization's exposure to deepfake-enabled fraud and executive impersonation, for the CISO, head of fraud, treasurer, or CRO (board-risk-committee-sponsored after a sector incident, and increasingly asked for by cyber insurers). Driven by rising board urgency after a widely reported multimillion-dollar deepfake wire-fraud incident at a global firm. Maps exposure across the high-value transaction flows an attacker would target — wire and payment approval, treasury operations, help-desk identity verification, executive support/assistant workflows, and vendor payment changes — reviews the process controls that stop a synthetic-identity attempt (out-of-band verification, multi-person approval, callback protocols, and help-desk challenge-response), optionally walks simulated tabletop-style scenarios, and delivers a board-ready report with prioritized control gaps. It is advisory readiness work: explicitly NOT covert social engineering of staff, NOT unauthorized system access, and NOT ongoing detection or monitoring — for continuous detection tooling DSE orchestrates a vetted MDR or tooling partner rather than running it itself. It is not a guarantee against fraud and not legal advice. Pairs with the AI Incident Response Tabletop and the Governance Framework / vCISO offers, and with the free Deepfake Exposure Self-Check; links to the AI Security & Cyber Risk pillar and the pricing page. Primary CTA scopes a call at /engage.html?problem=ai-deepfake-defense. - [AI security assessment](https://www.thedataexperts.us/ai-security-assessment.html): Hands-on AI and LLM security testing and red teaming mapped to the OWASP LLM Top 10 and MITRE ATLAS, covering RAG and agent layers. - [LLM security testing](https://www.thedataexperts.us/llm-security-testing.html): Buyer-intent page for LLM security testing across RAG, copilots, and agents, including prompt injection, data leakage, tool abuse, OWASP LLM Top 10 mapping, and remediation evidence. - [AI governance checklist](https://www.thedataexperts.us/ai-governance-checklist/): A practical checklist for financial-services teams scoping AI governance and audit-readiness work before an engagement. - [mcp-warden](https://www.thedataexperts.us/mcp-warden/): DSE's authored open-source tool that catches MCP supply-chain risk, evidence of the hands-on security depth behind the readiness practice. - [Services overview](https://www.thedataexperts.us/services.html): The full DSE practice across AI governance and readiness, implementation and integration, private AI, managed AI operations, and supporting AI security/data engineering work. - [Data engineering consulting](https://www.thedataexperts.us/data-engineering.html): Data engineering consulting and services in the US — pipelines, data quality, governance, and AI-ready foundations that feed the implementation and private AI towers. - [Data security consulting](https://www.thedataexperts.us/data-security-consulting.html): Help protect data across cloud, warehouse, lakehouse, analytics, and AI flows through inventory and flow mapping, classification and ownership, identity and entitlements, encryption and key custody, platform and pipeline controls, and retention evidence. Technical and operational advisory work, not legal advice, an audit, certification, SOC/MDR, or penetration testing. - [Data science and machine learning](https://www.thedataexperts.us/data-science.html): Applied data science and machine learning consulting that ships to production: ML engineering, evaluation, and handoff for mid-market AI programs. - [Shadow AI risk assessment](https://www.thedataexperts.us/safe-ai-security-foundation.html): Find where staff paste company data into public AI tools and lock it down — an exposure map, an acceptable-use policy, and a 90-day roadmap. - [Core cybersecurity services](https://www.thedataexperts.us/cyber-risk.html): The canonical conventional-cybersecurity hub for growing firms, covering risk assessment, identity, ransomware and backup readiness, vendor risk, compliance evidence, and fractional security leadership. Routes AI-specific system risk to the separate AI system security specialty hub. The [Platforms & technology ecosystems](https://www.thedataexperts.us/cyber-risk.html#platform-ecosystems) section on the same page describes the ten ecosystem categories DSE works across — cloud, identity and productivity, endpoint and extended detection, logging and security operations, network and edge, vulnerability management, data security, secure software delivery, backup and recovery, and governance/risk/compliance — stating the buyer outcome and DSE's advisory role for each. It is deliberately text-first with no vendor logos: Microsoft 365 and Microsoft Entra ID are the only platforms named publicly, under an owner-approved advisory and evaluation classification with no independent certification, partner, or reseller status; every other platform is advisory and evaluation context only and is scoped separately with evidence. The [Regulated readiness lanes](https://www.thedataexperts.us/cyber-risk.html#regulated-readiness) section routes buyers who have a specific obligation rather than a general security question to the four DSE-589 lane pages — FTC Safeguards Rule, SEC Regulation S-P incident response, HIPAA Security Risk Analysis, and cyber insurance evidence — each scoped to a different entity type and primary authority, each stating who it is not for. The [Technical security assessments & program design](https://www.thedataexperts.us/cyber-risk.html#technical-security) section routes buyers with a specific technical problem to the five DSE-588 offer pages — cloud security architecture and configuration assessment, IAM/privileged-access/Zero Trust roadmap, vendor and SaaS security review, vulnerability management program design, and secure SDLC/AppSec program review — each a focused, point-in-time, evidence-backed engagement that is vendor-neutral by default. The [Diagnostic tools & proof assets](https://www.thedataexperts.us/cyber-risk.html#diagnostic-assets) section routes buyers to the free companion asset for each offer — the two interactive, browser-local diagnostics (a NIST CSF 2.0 current-vs-target profile workbook and a CISA Cross-Sector CPG baseline scorecard) and the six print-ready proof deliverables (assessment sample excerpt, identity evidence checklist, incident-response first-60-minutes decision card, backup and recovery test worksheet, vCISO vs MSP vs MDR comparison, and cyber-insurance evidence checklist) — grouped by the decision each one helps a buyer make. - [Free 30-minute Cyber Risk Check](https://www.thedataexperts.us/cyber-risk-check.html): The free diagnostic entry point to the core cybersecurity practice — a scored self-assessment plus a 30-minute call that surfaces a growing firm's highest-risk gaps and next three moves, then routes into the risk assessment, readiness, identity, and fractional-leadership offers. No cost and no obligation. - [Cybersecurity risk assessment](https://www.thedataexperts.us/cybersecurity-risk-assessment.html): A national, point-in-time NIST CSF 2.0 assessment with evidence review, Current and Target Profiles, severity-ranked findings, and a prioritized remediation roadmap for executive and IT buyers. - [Microsoft 365 and identity security assessment](https://www.thedataexperts.us/microsoft-365-identity-security-assessment.html): A structured manual advisory review of client-provided Microsoft 365 and Entra portal evidence, producing an evidence register, severity-ranked findings, and remediation priorities. - [Incident response and ransomware readiness](https://www.thedataexperts.us/incident-response-ransomware-readiness.html): A conventional cyber-readiness engagement covering role mapping, executive and technical tabletop exercises, restore-test evidence, first-hour decisions, and an after-action roadmap; not live DFIR or a response retainer. - [Fractional CISO and security program leadership](https://www.thedataexperts.us/fractional-ciso-security-leadership.html): National conventional-security leadership for growing and regulated organizations covering roadmap and risk-register ownership, governance cadence, board reporting, diligence, budget, remediation oversight, and disclosed provider orchestration; DSE does not operate a SOC or MDR. - [FTC Safeguards Rule readiness](https://www.thedataexperts.us/ftc-safeguards-rule-readiness.html): Readiness support for non-bank financial institutions under FTC jurisdiction (16 CFR 314.1(b)) for the FTC Safeguards Rule at 16 CFR part 314. Explicitly NOT for banks, savings associations, and federally insured credit unions supervised elsewhere, for CFTC-jurisdiction or Farm Credit entities excluded by 16 CFR 314.2(h)(3), or for entities not significantly engaged in financial activities. Works the 16 CFR 314.4 elements — Qualified Individual, written risk assessment, the eight §314.4(c) safeguards, the §314.4(d) testing regime, training and service-provider oversight, the written incident response plan, the annual board report, and the §314.4(j) FTC notification duty for a security event involving the unencrypted customer information of 500 or more consumers — and checks the narrow §314.6 fewer-than-5,000-consumers exception rather than assuming it. Artifacts: applicability worksheet, element-by-element gap register, written risk assessment draft, incident response plan draft, Qualified Individual board-report template, remediation roadmap. Cites eCFR and the Federal Register (86 FR 70272 effective January 10, 2022; 87 FR 71509 delay; 88 FR 77499 with §314.4(j) effective May 13, 2024). No outstanding phased compliance dates. Readiness and advisory work: not legal advice, an audit, a certification, an attestation, or a guarantee of compliance, enforcement outcome, insurance, or contract award. - [SEC Regulation S-P incident response readiness](https://www.thedataexperts.us/sec-reg-s-p-incident-response-readiness.html): Readiness support for the amended Regulation S-P at 17 CFR 248.30 for covered institutions as §248.30(d)(3) defines them — brokers and dealers including funding portals, investment companies, investment advisers registered with the Commission, and transfer agents registered with the Commission or another appropriate regulatory agency. Explicitly NOT for banks and credit unions, FTC-jurisdiction non-bank financial institutions, or advisers not registered with the Commission. Covers the written safeguards policies, the §248.30(a)(3) incident response program, the §248.30(a)(4) customer notification duty with its 30-day clock from becoming aware, the documented substantial-harm exception, the §248.30(a)(5) service-provider oversight and 72-hour provider breach-notice arrangement, and the wider customer-information and sensitive-customer-information definitions. Both tiered compliance dates have passed: larger entities December 3, 2025 and smaller entities June 3, 2026, from the 18- and 24-month compliance periods in the adopting release (89 FR 47688, Release Nos. 34-100155; IA-6604; IC-35193, published June 3, 2024, effective August 2, 2024). Artifacts: covered-institution scope worksheet, incident response program gap register, customer information inventory, notification decision workflow, service-provider notice register, notice-content checklist and roadmap. Not legal advice, breach counsel, an audit, a certification, or a guarantee of any examination or enforcement outcome. - [HIPAA Security Risk Analysis support](https://www.thedataexperts.us/hipaa-security-risk-analysis-support.html): Support for the client's own Security Risk Analysis obligation at 45 CFR 164.308(a)(1)(ii)(A), a Required implementation specification under subpart C of 45 CFR part 164, for covered entities and business associates (including subcontractors) that create, receive, maintain, or transmit ePHI. Explicitly NOT for organizations with no ePHI in scope, for employers looking at their own employment records, or for anyone seeking a HIPAA certification — HIPAA has no certification regime and DSE is not a covered entity's compliance authority. Business associate agreement terms are a separate legal matter DSE does not draft, negotiate, or opine on. Distinguishes current requirements from the proposed rule: the HIPAA Security Rule NPRM at 90 FR 898 (published January 6, 2025, comments closed March 7, 2025) remains a PROPOSAL with no compliance date and is treated as a roadmap watch item only, never as a requirement. Artifacts: ePHI inventory and data-flow map, threat and vulnerability register, risk determination and rating, safeguard determination record covering the 45 CFR 164.306(d) Required/Addressable decisions, risk management plan under §164.308(a)(1)(ii)(B), and an evidence pack with a refresh-trigger list. Cites eCFR primary rule text; NIST CSF 2.0 is a supporting organizing structure, not a HIPAA determination. - [Cyber insurance readiness assessment](https://www.thedataexperts.us/cyber-insurance-readiness-assessment.html): Control evidence readiness for a cyber insurance application, renewal, or post-quote control condition. The distinguishing honesty of this lane is that there is no regulator and no rule: cyber insurance eligibility is governed by each carrier's underwriting, which differs by carrier and by cycle, so DSE organizes evidence against NIST CSF 2.0 and the CISA Cross-Sector Cybersecurity Performance Goals and maps the overlap to obligations that actually bind (16 CFR part 314, 17 CFR 248.30, 45 CFR part 164 subpart C) so evidence is produced once and used twice. **DSE is not an insurance broker, agent, producer, adjuster, or carrier, is not licensed to transact insurance, does not place, market, bind, or negotiate coverage, cannot speak for any carrier, and guarantees no eligibility, terms, premium, limit, retention, or claim outcome.** Explicitly NOT for coverage placement, policy-wording or coverage opinions, or claims advocacy, and DSE does not complete or sign the application — those answers are the client's representations. Artifacts: control evidence register, answer-support pack, gap list with remediation plan, obligation overlap map, broker-ready summary, next-cycle roadmap. Publishes no claim-denial rates, premium averages, or market loss statistics because they cannot be sourced from a primary source. Distinct from the buyer-education cyber-insurance evidence article: this page is the scoped offer, its deliverables, and its boundaries. - [Cloud security architecture & configuration assessment](https://www.thedataexperts.us/cloud-security-architecture-assessment.html): A point-in-time, vendor-neutral cloud security architecture and configuration assessment based on client-provided evidence (configuration exports, architecture diagrams, identity and network exports, logging settings, policy documents) using DSE's bounded-evidence method. No cloud provider is named as a capability claim; DSE does not request administrator credentials, connect tooling, or run automated scans. Organized against NIST CSF 2.0 with CISA Cross-Sector CPGs as a supporting baseline. Artifacts: cloud control map, configuration findings register, identity and privilege review, exposure and logging summary, target architecture sketch, prioritized remediation roadmap. Typical timebox 3 to 5 weeks. Advisory and readiness work — not a penetration test, an audit, a certification, or a guarantee of any compliance or security outcome. - [IAM, privileged access & Zero Trust roadmap](https://www.thedataexperts.us/iam-zero-trust-roadmap.html): A point-in-time advisory review of identity, privileged access, and Zero Trust posture from client-provided evidence (directory and identity exports, role membership, access-policy exports, privileged-role inventories, joiner-mover-leaver documentation), organized against NIST SP 800-207 and NIST CSF 2.0. Most work is vendor-neutral; where a named platform is in scope, the reviewed scope is stated in the owner-approved advisory wording for Microsoft Entra and Microsoft 365 only, with no certification, partner, or reseller status and no implementation, hardening, or monitoring claim. Artifacts: identity and access evidence register, privileged access findings, authentication and access-policy review, Zero Trust maturity read, joiner-mover-leaver review, prioritized Zero Trust roadmap. Typical timebox 3 to 5 weeks. Advisory and readiness work, not an implementation service, an audit, a certification, or a guarantee. - [Vendor & SaaS security review](https://www.thedataexperts.us/vendor-saas-security-review.html): A point-in-time review of the non-AI third-party vendors, SaaS tools, contractors, and connected apps that touch company or client data, from client-provided evidence (vendor and SaaS inventory, OAuth and connected-app grant exports, data-flow documentation, existing questionnaires and reports, contract terms). Distinct from the separate AI vendor risk review, which owns AI vendors, embedded models, and API-connected AI tools. Organized against NIST CSF 2.0 supply-chain outcomes. Artifacts: vendor and SaaS inventory, risk-tiered vendor register, connected-app and access findings, minimum-evidence expectations, concentration and dependency read, prioritized remediation roadmap. Typical timebox 2 to 4 weeks. Advisory and readiness work — not an audit, a certification, or a penetration test of any vendor. DSE does not request administrator credentials or run automated scans. - [Vulnerability management program design](https://www.thedataexperts.us/vulnerability-management-program-design.html): A point-in-time advisory review and design of a vulnerability management program from client-provided evidence (asset inventories, existing scan and finding reports, prioritization and SLA policy, ticketing and remediation workflow, exception records, program metrics). DSE assesses the program, does not operate scanners, and does not run scans; no scanner vendor is named as a capability claim. Organized against NIST CSF 2.0 and CISA Cross-Sector CPGs. Artifacts: program maturity assessment, asset coverage gap analysis, prioritization and SLA design, ownership and routing model, metrics and closure-evidence pack, prioritized program roadmap. Typical timebox 2 to 4 weeks. Advisory and program-design work — not an audit, a certification, or a penetration test. - [Secure SDLC & AppSec program review](https://www.thedataexperts.us/secure-sdlc-appsec-review.html): A point-in-time, vendor-neutral review of the secure-development and application security controls in a delivery pipeline from client-provided evidence (pipeline and branch-protection exports, secure-development and code-review policy, dependency and build evidence, secret-handling documentation, release-gate records), organized against the NIST Secure Software Development Framework (SP 800-218) and NIST CSF 2.0. No source-control, pipeline, or scanning vendor is named as a capability claim; application penetration testing is a separate, separately authorized engagement. Artifacts: secure-development control map, pipeline gate findings register, secret-handling review, dependency and build-integrity read, ownership and escalation model, prioritized AppSec roadmap. Typical timebox 3 to 5 weeks. Advisory and readiness work — not an audit, a certification, or a code audit for hire. - [Security overview (trust & compliance)](https://www.thedataexperts.us/security.html): DSE's own security and confidentiality control environment — controls designed against the SOC 2 criteria (no SOC 2 attestation held), TLS 1.2+ and AES-256 encryption, least-privilege access, MFA, and category-level subprocessor disclosure. - [Small-business security](https://www.thedataexperts.us/secure-smb.html): A point-in-time Security Posture Assessment, an advisory oversight retainer with MDR-partner orchestration, and HIPAA and client-data compliance readiness for small businesses. - [Engagement models & market estimates](https://www.thedataexperts.us/pricing.html): Named engagement models with non-binding market-estimate ranges across AI governance, readiness, security, implementation, data engineering, data science, private LLM platforms, and SMB security, plus a client-side quick-estimate tool. Ranges are estimates, not quotes; final fees are fixed in writing after a scoping call. ## Selected work - [Government Mission Solutions for Federal Teams](https://www.thedataexperts.us/federal.html): Government AI, data, and modernization services organized around mission-fit advisory, implementation planning, and evidence-aware handoff. - [Federal AI Readiness & Governance Services](https://www.thedataexperts.us/federal-ai-readiness.html): A decision-oriented path from use-case inventory through risk framing, evaluation planning, implementation boundaries, decision evidence, and a prioritized roadmap. - [Capability briefs](https://www.thedataexperts.us/briefs/): The capability brief library. Each brief is reference architecture and proposed capability written to the DSE Claims Policy; no brief claims past performance, certification, or an Authority to Operate. - [Partner-Enabled Specialized Field & Professional Services](https://www.thedataexperts.us/briefs/partner-enabled-field-and-professional-services.html): Capability brief for DSE-led contract management of specialized professional, infrastructure, equipment, and field requirements delivered with qualified subcontractors. No partner, license, bond, or capacity is implied secured. - [Secure AI Readiness & Governance for Federal Programs](https://www.thedataexperts.us/briefs/secure-ai-readiness-governance-federal.html): Capability brief for a DSE-led readiness engagement: AI use-case register, NIST AI RMF tiering, boundary decision, control mapping onto the program's existing baseline, evaluation design, and a decision evidence package. Unclassified work only. - [Private AI & Secure LLM Deployment](https://www.thedataexperts.us/briefs/private-ai-secure-llm-deployment.html): Capability brief with a vendor-neutral reference architecture for LLM, retrieval, inference, and evaluation inside a controlled data boundary. Residency language applies to customer-deployed architecture only. - [Government Data Modernization Services](https://www.thedataexperts.us/government-data-modernization.html): A mission-data modernization path covering source mapping, data quality, interoperability, decision products, operating ownership, and implementation handoff. - [Secure Multi-Tenant LLM Platform: A Build-and-Transfer Framework for Regulated Industries](https://www.thedataexperts.us/work/secure-multi-tenant-llm-platform-framework.html): The reference architecture behind a production multi-tenant LLM SaaS platform delivered in roughly eleven weeks, with hard tenant isolation, JWT-at-the-edge authentication, and a clean IP handoff. - [Clinical Documentation AI: A HIPAA-Compliant Implementation Framework](https://www.thedataexperts.us/work/healthcare-documentation-ai-framework.html): A healthcare AI framework for privacy-first clinical documentation, human-in-the-loop review, EHR integration, and auditability inside a HIPAA-bound environment. - [Federal Contract Intelligence Pipeline: A Framework for Opportunity Triage at Scale](https://www.thedataexperts.us/work/federal-contract-intelligence-pipeline-framework.html): A federal workflow framework that turns a high-volume solicitation feed into a scored opportunity store and a daily Go/No-Go digest. ## Free governance tools - [AI governance tools](https://www.thedataexperts.us/tools/): Fifteen free in-browser AI tools across governance maturity, Gen-AI risk, model risk, regulatory mapping, exam-readiness evidence, vendor risk, implementation readiness, AI incident response, shadow-AI discovery, and privacy/DPIA threshold analysis. Nothing is sent to a server. - [AI Regulatory Evidence Replay Lab for credit unions](https://www.thedataexperts.us/tools/ai-regulatory-evidence-replay.html): A free, browser-local evidence-readiness diagnostic for federally insured credit unions and community financial institutions. Choose a member assistant, credit decision, fraud or BSA/AML monitoring, or employee copilot scenario; rate six reproducibility domains; and get a score, scenario-specific primary-source lenses, evidence gaps, and a downloadable 30, 60, and 90-day plan. Informed by NCUA's current AI resource and third-party letters, the voluntary NIST AI RMF Core, and Treasury's Financial Services AI Risk Management Framework. No selections are sent or stored. A readiness aid, not legal advice, an audit, certification, supervisory opinion, or examination guarantee. - [Ask DSE](https://www.thedataexperts.us/tools/ask-dse.html): A free, cited AI assistant that answers questions about AI governance, AI/model risk management (including SR 26-2 and SR 11-7), and financial-services compliance (EU AI Act, NIST AI RMF, GLBA, NYDFS Part 500) using ONLY DSE's published writing, with a deep-link citation to the exact article and section behind every claim. It retrieves the most relevant published article sections and constrains the answer to those sources; any link not drawn from the retrieved sources is stripped before the reader sees it, and if the corpus does not answer a question it says so and points to a principal rather than guessing. The question text is never logged. It is a readiness aid, not legal advice, a certification, or an audit/examination-outcome guarantee; DSE is not an accredited certification body. - [Workbook & Resource Center](https://www.thedataexperts.us/tools/workbook-resource-center.html): A free, in-browser front door to DSE's financial-services compliance workbook library — 16 real GLBA, NYDFS Part 500, NYDFS Part 23 (BitLicense), CCPA/CPRA, NIST CSF 2.0, NIST AI RMF, Reg S-P (2024), FINRA, ISO/IEC 42001, HIPAA, and CMMC workbooks and templates. Filter the whole library by entity type (banks, credit unions, insurers, broker-dealers, RIAs, fintechs, crypto/BitLicense, or all financial institutions), by regulation, by role, and by compliance lifecycle stage (assess, map, build, report, track, or decide), search by keyword, and add several workbooks to a governance kit to request them together. Browsing and kit-building run entirely in the browser; each download keeps its existing work-email gate (the file is emailed to a work address) and nothing is uploaded. It indexes the same senior-built workbooks as the Financial Services Compliance Resource Library. A readiness index, not legal advice or certification. - [AI Governance Control Center](https://www.thedataexperts.us/ai-governance-control-center.html): The hub of the AI Governance Operating Stack — a free, 100% client-side set of finserv-native AI-governance tools built on one shared, browser-local AI register. Shows live register counts by type and risk tier, launches the tools (the AI Inventory & Risk-Tiering Wizard, Gen-AI Risk Scorecard, AI Governance Maturity Self-Assessment, Regulatory Crosswalk, and Exam-Readiness Evidence-Pack are live; Ask-DSE is in build), and links the finserv workbook library. Your data never leaves your browser; nothing is uploaded. A readiness toolkit, not legal advice or certification. - [AI Inventory & Risk-Tiering Wizard](https://www.thedataexperts.us/tools/ai-inventory-risk-tiering-wizard.html): The spine of the stack — a free, in-browser wizard that builds a client-side AI register (stored only in the browser, never uploaded) and computes a transparent risk tier for each AI system or use case from a documented rubric (materiality, data sensitivity, deployment, and an autonomy term derived from type). It maps the required controls for each tier against the NIST AI RMF functions (Govern, Map, Measure, Manage) and SR 26-2's validation, effective-challenge, and monitoring expectations, adds fair-lending testing under ECOA and Regulation B where in scope, and flags generative and agentic AI as outside SR 26-2 model-risk scope. Exports the register to CSV and JSON and imports JSON back, lossless. The tiers, scores, and controls are structured heuristics, not codified definitions; this is readiness, not a model validation or certification. - [Gen-AI Risk Scorecard](https://www.thedataexperts.us/tools/gen-ai-risk-scorecard.html): Free browser-local scorecard for generative-AI use cases. Scores hallucination, prompt injection, data leakage, third-party LLM dependency, and human oversight gaps; produces a board-ready summary; exports Markdown; and can save the result back to the shared AI register. It is a structured readiness aid, not legal advice, model validation, certification, or an audit guarantee. Nothing is sent to a server. - [AI Governance Maturity Self-Assessment](https://www.thedataexperts.us/tools/ai-governance-maturity-self-assessment.html): A free, browser-local, organization-level AI governance maturity self-assessment for financial services. Sixteen statements across the four NIST AI RMF functions — Govern, Map, Measure, Manage — are rated on a 1-to-5 capability scale (Initial, Developing, Defined, Managed, Optimizing), returning a maturity score per function and overall, a band, priority gaps to close, and a board-ready summary. Finserv expectations are mapped into the questions: board and committee oversight and three-lines-of-defense; SR 11-7 / SR 26-2 model risk governance, independent validation, and effective challenge; fair lending under ECOA and Regulation B and UDAP/UDAAP; interagency third-party and vendor AI risk; and OWASP LLM Top 10 security testing for generative and agentic AI. Saved attempts are stored only in the browser's localStorage so a re-take shows the delta per function and overall versus the prior attempt (longitudinal tracking); exports CSV and JSON and prints a board view. The maturity levels and bands are DSE's own practitioner heuristics, not codified NIST AI RMF or supervisory definitions; it is a readiness aid, not an audit, certification, examination outcome, or legal advice. Nothing is sent to a server. Reads the shared browser-local AI register for context and pairs with the AI Inventory & Risk-Tiering Wizard and the Gen-AI Risk Scorecard behind the AI Governance Control Center. - [Regulatory Crosswalk / Regulation Explorer](https://www.thedataexperts.us/tools/regulatory-crosswalk.html): Free, in-browser tool that maps an AI use case to the financial-services regulatory regimes that plausibly govern it, filterable by regulator and jurisdiction and driven by the shared browser-local AI register's use-case attributes (type, business function, materiality, data sensitivity, deployment) or entered standalone. Covers SR 11-7 (superseded), SR 26-2 / OCC Bulletin 2026-13 model risk management — with the generative and agentic AI governance gap called out explicitly (SR 26-2, issued April 17, 2026, excludes generative and agentic AI from its model-risk scope) — ECOA and Regulation B fair lending (CFPB Circular 2022-03 on adverse action and complex algorithms), BSA/AML independent testing under the FFIEC manual, the Gramm-Leach-Bliley Act (Safeguards and Privacy Rules), the NYDFS 23 NYCRR Part 500 cybersecurity regulation and its October 16, 2024 AI guidance, the NIST AI RMF 1.0 as a voluntary baseline, and the Colorado AI Act (SB 24-205, materially amended in 2026 and delayed to January 1, 2027). Each regime carries a citation to its source, an effective or status date, and an applicability flag (applies, likely, verify with counsel, recommended baseline, or superseded); anything uncertain is marked verify with counsel rather than asserted. Versioned with a visible changelog; exports CSV and JSON. It is an informational regulatory mapping and readiness aid, not legal advice, a legal determination, a certification, or a guarantee of compliance. Nothing is sent to a server. - [Exam-Readiness Evidence-Pack Generator](https://www.thedataexperts.us/tools/exam-readiness-evidence-pack.html): Free browser-local generator that turns the shared AI register into a regulator-friendly evidence package answering the questions an examiner opens with — where is AI used, who owns it, and how is its risk classified. Assembles a model and use-case inventory, ownership by accountable role, risk classification by tier, per-system control coverage, and an honest list of identified gaps for exam-readiness (untiered systems, missing owners, undocumented controls, no framework in scope, stale or missing reviews, and generative/agentic systems with no gen-AI risk score). Maps to the NIST AI RMF and SR 11-7 / SR 26-2 model-risk guidance. Exports to PDF (print-to-PDF stylesheet) and Markdown; if the register is empty it routes the user to the Inventory & Risk-Tiering Wizard first. It is a readiness aid and a structural completeness check, not an audit, model validation, certification, legal advice, or a guarantee of passing an examination. Nothing is sent to a server. - [AI workflow readiness calculator](https://www.thedataexperts.us/tools/ai-workflow-readiness-calculator.html): Answer six questions about one business workflow to get a readiness band (ready to pilot, close with gaps, or not yet) scored on definition, data, evaluation, oversight, integration burden, and risk, with the specific gaps to close before an AI build; routes to AI implementation and integration; runs in your browser. - [AI system inventory generator](https://www.thedataexperts.us/tools/ai-system-inventory-generator.html): Generate a tiered AI use-case register with EU AI Act fields; exports CSV and Markdown. - [EU AI Act risk classifier](https://www.thedataexperts.us/tools/eu-ai-act-risk-classifier.html): Walk through a structured questionnaire to determine where a given AI system lands across the EU AI Act risk categories. - [AI acceptable-use policy generator](https://www.thedataexperts.us/tools/ai-acceptable-use-policy-generator.html): Generate a policy draft with healthcare, finserv, and govcon clause variants; exports Markdown. - [NIST AI RMF checklist generator](https://www.thedataexperts.us/tools/nist-ai-rmf-checklist-generator.html): Track Govern, Map, Measure, and Manage completion across NIST AI RMF 1.0 subcategories; exports CSV. - [Model risk tiering calculator](https://www.thedataexperts.us/tools/model-risk-tiering-calculator.html): Answer five questions to get a materiality-based read on whether an AI system is a model in scope of SR 26-2, and if so a structured Tier 1, 2, or 3 with the controls that follow; runs in your browser. - [AI vendor due diligence questionnaire generator](https://www.thedataexperts.us/tools/ai-vendor-due-diligence-questionnaire.html): Answer three questions to assemble a tailored AI vendor DDQ a financial institution can send a vendor, with grouped questions on governance, model validation, data and security, fair lending for credit uses, third and fourth-party risk, incident response, contract rights, and ongoing monitoring; tags the framework drivers that apply (interagency third-party guidance, SR 26-2, 23 NYCRR 500.11, Regulation S-P, the NAIC AI Model Bulletin, NCUA Letters 07-CU-13 and 01-CU-20); runs in your browser. - [AI incident scenario builder](https://www.thedataexperts.us/tools/ai-incident-scenario-builder.html): A free, in-browser tool that generates pre-built AI incident scenarios plus a 10-question incident-response readiness checklist. Pick an AI use case (lending, fraud, customer service, underwriting, or trading) and a firm type (bank, credit union, insurer, broker-dealer/RIA, or fintech) and it returns three concrete, on-the-clock scenario narratives across the AI-specific failure modes — model failure, LLM data leakage, bias at scale, deepfake fraud, poisoned model or adversarial evasion, and a regulatory inquiry — with a generic regulator phrase tuned to the firm type (named rules are deliberately left generic). The 10-question "does your IR plan answer this?" checklist covers incident command, rollback/fallback, blast-radius reconstruction, escalation thresholds, communications, evidence retention, regulator notification, vendor cooperation, run/degrade/shutoff criteria, and post-incident learning. Exports Markdown, copy, and print; nothing is sent to a server. It is a starting point to focus a conversation, not an audit, not a live incident response service, and not legal advice. Pairs with and routes to the AI Incident Response Tabletop and /engage.html?problem=ai-security. - [Shadow AI inventory quiz](https://www.thedataexperts.us/tools/shadow-ai-inventory-quiz.html): A free, in-browser self-assessment for a compliance, HR, or technology leader on their visibility into employee AI-tool use. Answer ten scored questions (approved-tool list, AI acceptable-use policy, connected-app/OAuth visibility, data-egress/DLP controls, employee input, sensitive-data awareness, a named governance owner, a sanctioned AI alternative, training, and a recurring re-inventory cadence) and pick an industry (financial services, insurance, healthcare, legal, or other professional services) and it returns a banded exposure score (low/medium/high out of 20), the priority gaps to close first, a list of common unsanctioned AI tools in that industry (public chatbots such as ChatGPT, Gemini, Claude, or a browser Copilot; AI note-takers; AI writing and coding assistants; AI features inside existing SaaS), and a sample AI acceptable-use-policy framework outline. Exports Markdown, copy, and print; nothing is sent to a server. It is a self-assessment to focus a shadow-AI conversation, not an audit, not employee surveillance, and not legal advice. Pairs with and routes to the Shadow AI Discovery + Policy Readiness Sprint and /engage.html?problem=ai-readiness. - [AI DPIA threshold checker](https://www.thedataexperts.us/tools/ai-dpia-threshold-checker.html): A free, in-browser threshold checker for a DPO, privacy counsel, or compliance leader asking whether an AI system needs a DPIA. Select where the system operates or whose data it affects (EU/EEA, California, Colorado, other US states, or none/unsure), what it does with personal data (decisions with legal or significant effects, profiling with limited effect, systematic monitoring, general assistance, or no personal data), whether it processes special-category or sensitive data, and at what scale, and it returns a likely-required, advisable, or not-clearly-triggered read, a framework-by-framework breakdown (GDPR Article 35 DPIA, CCPA/CPPA ADMT risk assessment, Colorado AI Act impact assessment, and other US state privacy laws), and a scope outline for the assessment. The logic routes anything ambiguous up, never down. Exports Markdown, copy, and print; nothing is sent to a server. It is a starting point to focus a privacy conversation, not legal advice and not a legal determination that any assessment is or is not required; whether an assessment is legally required, and whether it is sufficient, is a conclusion for your data protection officer and counsel. Pairs with and routes to the Privacy / DPIA for AI Systems assessment and /engage.html?problem=ai-privacy-dpia. - [Deepfake exposure self-check](https://www.thedataexperts.us/tools/deepfake-exposure-self-check.html): A free, in-browser self-assessment for a CISO, head of fraud, treasurer, or risk leader asking how exposed the organization is to deepfake-enabled fraud. Select which high-risk workflows exist (wire/payment approval, treasury operations, help-desk/IT identity verification, executive assistant workflows, and vendor payment changes) and answer four questions about the controls around them (whether out-of-band verification is required before money moves, whether callback protocols exist for payment and payee changes, whether high-value approval requires more than one person, and whether staff have had deepfake voice/video fraud awareness training), and it returns a deepfake-fraud exposure band, a control-by-control breakdown, and the top process gaps to close, framed constructively as fixes. Exports Markdown, copy, and print; nothing is sent to a server. It is a self-assessment to focus a conversation, not an audit, not a covert test of staff, not ongoing monitoring, and not a guarantee against fraud. Pairs with and routes to the AI Deepfake / Social-Engineering Defense Readiness Assessment and /engage.html?problem=ai-deepfake-defense. - [NIST CSF 2.0 Current-vs-Target Profile Workbook](https://www.thedataexperts.us/tools/nist-csf-current-vs-target-profile.html): A free, browser-local workbook that builds a NIST Cybersecurity Framework 2.0 Current-vs-Target Profile across all 22 CSF 2.0 categories (the six Functions Govern, Identify, Protect, Detect, Respond, Recover from NIST CSWP 29). Set a Current and Target tier per category on the CSF 2.0 Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive), add notes, and get a gap table sorted by largest gap with CSV export. The categories and tiers are NIST's; the gap is plain target-minus-current arithmetic. It is a self-diagnostic workbook, not a DSE assessment, an audit, or an implementation tier certification; CSF 2.0 is a voluntary framework and nothing is sent to a server. Owner service: the Cybersecurity Risk Assessment & Roadmap. - [CISA Cross-Sector CPG Baseline Scorecard](https://www.thedataexperts.us/tools/cisa-cpg-baseline-scorecard.html): A free, browser-local scorecard for CISA's voluntary Cross-Sector Cybersecurity Performance Goals, organized into the eight CPG goal families (Account Security, Device Security, Data Security, Governance & Training, Vulnerability Management, Supply Chain / Third Party, Response & Recovery, Network & Other). Mark each goal Implemented, Partial, Not implemented, or Not applicable and get coverage per family plus your next three discussion items — the highest-impact goals not yet implemented — with CSV export. Goals are stated as plain-language outcomes rather than invented identifiers. Discussion starters, not remediation advice or a compliance result; the CPGs are a voluntary baseline and nothing is sent to a server. Owner service: the free Cyber Risk Check. - [Cybersecurity Assessment Sample Excerpt](https://www.thedataexperts.us/tools/cybersecurity-assessment-sample-excerpt.html): A free, print-friendly synthetic excerpt of a DSE cybersecurity risk assessment — a finding register (control area, observation in business context, severity, evidence source, owner, target date) and a roadmap slice — built with the bounded-evidence method on the Cybersecurity Risk Assessment & Roadmap page. Structure is real; every entry is invented and no organization, system, or finding is real. Not client data, not a DSE assessment, an audit, a certification, or legal advice. Owner service: the Cybersecurity Risk Assessment & Roadmap. - [Microsoft 365 & Identity Evidence Checklist](https://www.thedataexperts.us/tools/microsoft-365-identity-evidence-checklist.html): A free, print-friendly checklist of the client-provided exports and screenshots a point-in-time identity and access review gathers — admin-role inventory, conditional-access export, MFA registration report, app registrations and consent grants, legacy-authentication report, guest-access review, and audit-log retention setting. DSE reviews client-provided Microsoft 365 and Microsoft Entra portal configuration and exports in a structured, point-in-time manual advisory review and makes no Microsoft partnership, certification, or reseller claim. A self-diagnostic evidence-gathering aid, not a scan, an audit, or a certification. Owner service: the Microsoft 365 & Identity Security Assessment. - [Incident Response: The First 60 Minutes](https://www.thedataexperts.us/tools/incident-response-first-60-minutes.html): A free, print-friendly decision card for the opening hour of a suspected incident — who declares, who isolates, who calls counsel and the cyber-insurance carrier hotline, what to preserve, and what NOT to do (wipe, reimage, power off, or pay a ransom without counsel and insurer involvement) — across three time blocks (0–10, 10–30, 30–60 minutes). A planning aid for your team's own plan: DSE does not provide live incident response, digital forensics, or a 24/7 hotline; where you need those we help you scope and select a provider you contract directly. Owner service: Incident Response & Ransomware Readiness. - [Backup & Recovery Test Worksheet](https://www.thedataexperts.us/tools/backup-recovery-test-worksheet.html): A free, printable worksheet to record, per critical system, RTO and RPO targets, the last real restore-test date, the restore evidence artifact, the result, and the gap owner — plus a standard for what counts as restore evidence (a timed restore log, a screenshot of restored data, a data-integrity check, and an offline/immutable-copy confirmation). Turns "we have backups" into evidence they have been tested. A self-diagnostic worksheet, not a DSE assessment, an audit, or a certification. Owner service: Incident Response & Ransomware Readiness. - [vCISO vs MSP vs MDR: Who Owns What](https://www.thedataexperts.us/tools/vciso-vs-msp-vs-mdr-comparison.html): A free, print-friendly one-screen comparison of three constantly-confused roles — vCISO (security leadership and program), MSP (IT operations), and MDR (detection and response operations) — across accountability, scope, what each owns, what each does not own, typical buyer, and how each fails. No vendor names and no pricing. DSE provides fractional security leadership (vCISO); it is not an MSP and does not operate MDR, and where you need those it helps you scope and select the providers. Links to the vCISO vs MSP vs MDR deep-dive article. Owner service: Fractional CISO & Security Program Leadership. - [Cyber Insurance Evidence Checklist](https://www.thedataexperts.us/tools/cyber-insurance-evidence-checklist.html): A free, printable register of the control-evidence artifacts underwriting applications commonly request — MFA coverage, endpoint detection and response (EDR) coverage, backup and restore-test evidence, an incident response plan and its test date, patching cadence, privileged-access controls, and security-awareness training records — with columns to record the evidence artifact and its as-of date. The same pack answers enterprise-customer questionnaires. DSE is not an insurance broker, agent, or carrier and guarantees no eligibility, premium, or claim outcome; carrier requirements vary and your application answers are your representations. Links to the cyber-insurance evidence-readiness deep-dive article. Owner service: the Cyber Insurance Evidence Readiness Assessment. ## Key guides - [Governed Databricks data pipeline reference implementation](https://www.thedataexperts.us/work/governed-databricks-data-pipeline-reference-implementation.html): A DSE-owned implementation showing immutable public-source capture, a 20-table Bronze contract, fail-closed quality gates, checksum-bound S3 publication, Unity Catalog schema verification, immutable changefeeds, and traceable Silver analytics. The August 19, 2026 verification snapshot recorded 18 publication watermarks and zero quality violations. This is engineering evidence, not a client case study, certification, endorsement, SLA, or future-state guarantee. - [AI governance for financial services (pillar hub)](https://www.thedataexperts.us/ai-governance-financial-services/): The authoritative overview of AI governance for US banks, captive finance, and fintechs, with a framework matrix mapping each AI use to the authority that governs it (SR 26-2 model risk, NIST AI RMF, fair lending, third-party AI risk, EU AI Act) and links into the full governance cluster. - [AI governance for healthcare](https://www.thedataexperts.us/healthcare-ai-governance/): AI governance readiness, private AI architecture, and implementation support for healthcare teams handling PHI and other sensitive data, mapping HIPAA, the NIST AI RMF, and ONC expectations to defensible data boundaries, named owners, review steps, and operational evidence. Readiness and advisory work alongside your privacy, security, compliance, and counsel functions — not HIPAA certification, not legal advice, and no borrowed healthcare logos. - [AI Governance Readiness Snapshot (sample deliverable)](https://www.thedataexperts.us/ai-governance-readiness-sample/): A redacted, anonymized walkthrough of the Snapshot deliverable so a buyer can see exactly what they get before scoping. Shows the six components with illustrative excerpts: the AI inventory and use-case register, risk classification and tiering, a control crosswalk to SR 26-2 model risk, third-party risk, fair lending (ECOA/Reg B), NIST AI RMF, and NYDFS Part 500 / GLBA where relevant, gap findings with severity and remediation, a prioritized 90-day roadmap, and a one-page board and examiner-facing brief. Every value is illustrative; no real client or data. Readiness evidence, not certification. - [AI governance for credit unions (NCUA)](https://www.thedataexperts.us/ai-governance-credit-unions/): AI governance for federally insured credit unions. The differentiator is honesty about what does not exist: there is no NCUA model-risk rule equivalent to SR 26-2, and the NCUA has not adopted SR 11-7 or SR 26-2. In GAO-25-107197 (May 2025) the GAO recommended NCUA develop model-risk guidance, and NCUA staff concluded any new requirements would need rulemaking, so as of mid-2026 no formal NCUA AI model-risk regime exists. Includes a table mapping each credit-union AI use to the existing lens that governs it (cybersecurity under Part 748, third-party risk under Letters 07-CU-13 and 01-CU-20, fair lending, UDAAP, BSA/AML and OFAC, governance, data privacy) and the evidence to assemble, organized with the NIST AI RMF and CISA practices. - [Sponsor-bank BaaS AI third-party risk and model governance](https://www.thedataexperts.us/sponsor-bank-baas-ai-risk/): How a sponsor bank running Banking-as-a-Service and fintech partnerships governs the partner's AI. The differentiator is honesty about what does not exist: there is no separate, codified BaaS AI rule, so expectations are an application of the June 2023 Interagency Guidance on Third-Party Relationships: Risk Management (OCC, FDIC, Federal Reserve), which superseded the OCC's 2013 and 2020 third-party bulletins; SR 26-2 model-risk guidance (non-binding, the April 2026 revision that replaced SR 11-7, with generative and agentic AI excluded from model-risk scope); and the 2023-2026 BaaS supervisory and enforcement trend (financial-crime/BSA, third-party risk, consumer protection, the FDIC's September 2024 FBO recordkeeping proposal, and a 2026 Senate bill directing a GAO study). The bank cannot outsource responsibility for compliance. Includes a table mapping each BaaS/fintech AI risk to the framework that governs it (third-party lifecycle stage, SR 26-2 model risk, fair lending, BSA/AML) and the control plus evidence or contract right the sponsor bank needs (data and model testing access, audit rights, breach notice, exit plan), plus how federal third-party and model-risk expectations differ from NYDFS Part 500 and SEC Reg S-P. - [Microsoft 365 Copilot governance for banks](https://www.thedataexperts.us/microsoft-365-copilot-governance-banks/): How US banks and fintechs secure and govern a Microsoft 365 Copilot rollout: permission and oversharing remediation with sensitivity labels, Purview DLP, and SharePoint Advanced Management restricted-content discovery, prompt-injection and data-leakage red teaming mapped to the OWASP LLM Top 10 and MITRE ATLAS, and Purview audit evidence. Governed as a vendor product under third-party risk, not as an SR 26-2 model. - [NYDFS Part 500 AI compliance](https://www.thedataexperts.us/nydfs-part-500-ai-compliance/): How 23 NYCRR Part 500 applies to AI for NY-licensed banks, insurers, and DFS-covered entities. NYDFS supervises AI through a cybersecurity lens, not as an AI-model-governance regime: Part 500 is the binding rule, and the October 2024 guidance and May 2026 frontier-AI advisory tell covered entities to fold AI cyber risk into their existing Part 500 risk assessment and controls without creating new requirements. Includes a control map from each AI risk to the Part 500 obligation and the evidence, plus how Part 500 differs from SR 26-2 model risk. - [AI governance and compliance for insurers](https://www.thedataexperts.us/insurance-ai-governance/): How insurers meet the NAIC AI Model Bulletin and NYDFS Part 500 for algorithmic underwriting fairness, model risk, and market-conduct exam readiness. - [FINRA and Reg S-P AI compliance for broker-dealers](https://www.thedataexperts.us/broker-dealer-ai-compliance/): Reg S-P 2024 amendments and FINRA AI examination readiness for broker-dealers: surveillance-model oversight and third-party AI risk. - [SEC AI exam and Reg S-P compliance for RIAs](https://www.thedataexperts.us/ria-ai-governance/): SEC AI examination priorities and Reg S-P duties for registered investment advisers: Form ADV AI disclosure, the Marketing Rule, and model governance. - [Free AI governance tools for banks and fintechs](https://www.thedataexperts.us/writing/free-ai-governance-tools-banks-fintechs.html): What each of DSE's four free in-browser tools does, when to use it, and how to sequence them before an engagement. - [Self-hosted AI deployment security and compliance guide](https://www.thedataexperts.us/writing/self-hosted-ai-deployment-security-compliance-finserv-healthcare.html): The architecture, controls, and compliance-evidence mapping for secure self-hosted AI in finserv and healthcare across SOC 2, HIPAA, GLBA, and CMMC. - [NIST AI RMF for financial services](https://www.thedataexperts.us/writing/nist-ai-rmf-financial-services.html): How banks and fintechs operationalize the NIST AI Risk Management Framework for AI governance and audit-readiness. - [AI model risk management and SR 11-7](https://www.thedataexperts.us/writing/ai-model-risk-management-sr-11-7.html): Extending SR 11-7 model risk management to machine-learning and AI systems in regulated lenders. - [EU AI Act for US banks and fintechs](https://www.thedataexperts.us/writing/eu-ai-act-us-banks-fintechs.html): What the EU AI Act means for US financial institutions and how its obligations map to existing governance. - [AI governance vs AI compliance in financial services](https://www.thedataexperts.us/writing/ai-governance-vs-ai-compliance-financial-services.html): The difference between governing AI and proving compliance, and why readiness comes first. - [Healthcare AI governance: vendor path vs private boundary](https://www.thedataexperts.us/writing/healthcare-ai-governance-private-boundary-vs-vendor-path.html): A practical healthcare guide to when AI around PHI can stay on a governed vendor path, when it needs a stronger private boundary, and what evidence the team should assemble either way. - [HIPAA AI governance readiness](https://www.thedataexperts.us/writing/hipaa-ai-governance-readiness.html): A five-part readiness checklist for healthcare AI under HIPAA — use-case inventory, business associate agreement mapping, minimum-necessary scoping, Security Rule safeguards, and the evidence pack a review will ask for. - [Shadow AI in healthcare: building a risk inventory](https://www.thedataexperts.us/writing/shadow-ai-in-healthcare-risk-inventory.html): Where healthcare shadow AI actually comes from (consumer AI tools, EHR-embedded features, department-level pilots) and the healthcare-specific fields a PHI risk inventory needs to be actionable. - [Federal AI governance for unclassified systems](https://www.thedataexperts.us/writing/federal-ai-governance-private-ai-boundary-unclassified-systems.html): A public-sector guide to when an unclassified AI use can stay on a vendor path and when it needs tighter control, stronger private boundaries, or more attributable evidence. - [Private AI controls for public-sector sensitive workloads](https://www.thedataexperts.us/writing/private-ai-controls-for-public-sector-sensitive-workloads.html): The control checklist behind the boundary decision — tenant isolation, data boundary, access and tool permissioning, attributable logging, supply-chain provenance, and a tested kill-switch for unclassified federal AI deployments. - [OWASP LLM Top 10 assessment](https://www.thedataexperts.us/writing/owasp-llm-top-10-assessment-how-dse-tests.html): A practitioner walkthrough of how DSE tests each OWASP LLM Top 10 risk. - [OWASP LLM Top 10 mapped to NIST AI RMF controls](https://www.thedataexperts.us/writing/owasp-llm-top-10-mapped-to-nist-ai-rmf-controls.html): A control crosswalk linking each OWASP LLM risk to the matching NIST AI RMF function. - [MITRE ATLAS for tool-using and multi-agent AI](https://www.thedataexperts.us/writing/mitre-atlas-for-tool-using-and-multi-agent-ai.html): Applying the MITRE ATLAS threat model to agentic and tool-using AI systems. - [Shadow AI discovery and building a real AI inventory](https://www.thedataexperts.us/writing/shadow-ai-discovery-building-a-real-ai-inventory.html): How to find unsanctioned AI use and build an inventory that governance can act on. - [Startup AI Governance Launch Checklist](https://www.thedataexperts.us/writing/startup-ai-governance-launch-checklist.html): The minimum governance baseline before startup AI usage spreads: inventory, acceptable-use policy, vendor review, risk register, review gates, and evidence pack. - [AI Governance Starter Kit](https://www.thedataexperts.us/writing/ai-governance-starter-kit-startup-growth-enterprise.html): A general-purpose governance starter kit for startup, growth, and enterprise buyers: artifact outlines, customer-review evidence, and route-specific next steps. - [Growth AI Governance Operating Model](https://www.thedataexperts.us/writing/growth-ai-governance-operating-model.html): How growth-stage companies keep AI governance current through ownership, risk tiers, vendor controls, review cadence, and evidence upkeep. - [Private AI Architecture vs Public API](https://www.thedataexperts.us/writing/private-ai-architecture-vs-public-api.html): A control-boundary guide for choosing public APIs, isolated deployments, or private AI based on data sensitivity, logs, vendor dependence, and operations. - [Private AI Decision Matrix](https://www.thedataexperts.us/private-ai-security.html#decision-matrix): An email-gated, downloadable matrix for deciding when public APIs are sufficient, when private AI is justified, what evidence should exist, and when not to buy private AI yet. - [Managed AI Operations Runbook](https://www.thedataexperts.us/writing/managed-ai-operations-runbook.html): The post-launch runbook for private AI systems: monitoring, maintenance, model and vendor change review, evidence upkeep, incident paths, and cost controls. - [AI Workflow Implementation Brief](https://www.thedataexperts.us/writing/ai-workflow-implementation-brief.html): A buyer-facing implementation guide covering workflow scope, controls, evaluation, and handoff between policy approval and production. - [Anonymized AI Implementation Case Note](https://www.thedataexperts.us/work/anonymized-ai-implementation-case-note.html): An anonymized delivery pattern showing how a retrieval-and-review workflow moves from approved use case to operable system with handoff. - [AI Implementation Evaluation Checklist](https://www.thedataexperts.us/downloads/ai-implementation-evaluation-checklist.pdf): A downloadable checklist buyers can use to review workflow definition, controls, evaluation, and handoff readiness before launch. - [Trust Center](https://www.thedataexperts.us/trust-center.html): DSE's United States-only front door for direct client-service, partner/integration, and contractor intake workbook downloads, privacy notices and data-sharing choices, and the formal agreement path. The editable DOCX and reference PDF workbooks are information-gathering only, not contracts or authorization to begin work. The Trust Center keeps PHI, credentials, secrets, controlled data, production logs, and consumer or patient data out of initial exchanges; formal agreements follow a controlled review and execution path. The standard HIPAA BAA does not accept redlines and is not a public download. - [Enterprise AI Control Committee Charter](https://www.thedataexperts.us/writing/enterprise-ai-control-committee-charter.html): How enterprise AI governance defines decision rights, committee scope, escalation, monitoring cadence, evidence, and residual-risk acceptance. - [Implementation After AI Policy](https://www.thedataexperts.us/writing/implementation-after-ai-policy.html): How AI policy becomes workflow design, data integration, control checkpoints, evaluation, logging, and handoff. - [MCP security checklist](https://www.thedataexperts.us/writing/mcp-security-checklist.html): A checklist for securing Model Context Protocol servers and tool integrations. - [MCP supply-chain security and what mcp-warden catches](https://www.thedataexperts.us/writing/mcp-supply-chain-security-what-mcp-warden-catches.html): The MCP supply-chain risks that mcp-warden detects and why they matter. - [How AI Red-Team Findings Become Blue-Team Controls](https://www.thedataexperts.us/writing/ai-red-team-findings-to-blue-team-controls.html): A practical five-step path from an authorized AI red-team finding to a customer-owned control decision, implementation evidence, and scoped re-test. Explains where MCP definition-integrity controls fit and where they do not. - [AI governance operating model and committee charter for banks](https://www.thedataexperts.us/writing/ai-governance-operating-model-committee-charter-banks.html): How to structure an AI governance operating model and committee charter for US banks: committee design, RACI, operating cadence, policy lifecycle, and KRI reporting aligned to SR 11-7 and NIST AI RMF. - [SR 26-2 vs SR 11-7: what changed for AI model risk management](https://www.thedataexperts.us/writing/sr-26-2-vs-sr-11-7-model-risk-management.html): The April 2026 interagency guidance that replaced SR 11-7, what changed, the generative AI carve-out, and what banks need to do now. - [AML transaction monitoring model validation](https://www.thedataexperts.us/writing/aml-transaction-monitoring-model-validation.html): How banks validate BSA/AML transaction-monitoring models after SR 26-2 superseded SR 11-7 and the SR 21-8 BSA/AML statement, plus the FFIEC independent-testing obligation, above-the-line and below-the-line threshold tuning, and where machine-learning and generative-AI components fall in or outside the SR 26-2 model perimeter. - [Model Risk Tiering Calculator (SR 26-2)](https://www.thedataexperts.us/tools/model-risk-tiering-calculator.html): A free, in-browser calculator that organizes a materiality-based model risk tiering conversation under SR 26-2's risk-based approach. Five questions return whether an AI system is a model in scope of SR 26-2 at all (generative and agentic AI fall outside its model-risk scope; a simple deterministic rules engine may fall outside the model definition), and for a statistical or machine-learning model a structured Tier 1, Tier 2, or Tier 3 with the validation, effective challenge, and monitoring that follow, plus the frameworks that attach (SR 26-2 model risk, fair lending under ECOA and Regulation B for credit uses, FFIEC independent testing for BSA/AML). The tiers are a structured heuristic, not codified SR 26-2 definitions. Nothing is sent to a server; this is readiness, not a model validation or certification. - [AI Vendor Due Diligence Questionnaire (DDQ) Generator](https://www.thedataexperts.us/tools/ai-vendor-due-diligence-questionnaire.html): A free, in-browser generator that assembles a tailored due-diligence questionnaire a financial institution can send an AI vendor. Three inputs (what the vendor AI does, what data it touches, and your regulatory context) drive a DDQ grouped into governance and accountability, model development and validation and transparency, data handling and privacy and security, fair lending and bias (added only for credit underwriting, pricing, or adverse-action uses), third and fourth-party risk, incident response and breach notification, contractual rights, and ongoing monitoring. Each section is tagged with the framework drivers that apply: for federal banks the June 2023 Interagency Guidance on Third-Party Relationships: Risk Management plus SR 26-2 where the vendor AI is a model (generative and agentic AI fall outside SR 26-2 model-risk scope); for NYDFS-covered entities 23 NYCRR 500.11; for SEC broker-dealers and RIAs Regulation S-P service-provider oversight including the 72-hour vendor breach-notice arrangement; for insurers the NAIC AI Model Bulletin third-party expectation under which the insurer remains responsible; and for credit unions NCUA Letters 07-CU-13 and 01-CU-20. It is a starting-point questionnaire to organize vendor AI oversight, not legal advice, not a complete compliance program, and not a certification. Nothing is sent to a server. - [Agentic AI governance for banks](https://www.thedataexperts.us/writing/agentic-ai-governance-banks-sr-26-2-gap.html): What existing law applies to agentic AI when SR 26-2 doesn't — UDAP/UDAAP, fair lending, third-party risk — and the five-element control architecture banks need. - [AI model explainability requirements for US banks](https://www.thedataexperts.us/writing/ai-model-explainability-requirements-us-banks.html): How ECOA and Regulation B require specific adverse-action reasons for every AI credit model regardless of complexity, what SR 26-2's generative AI carve-out does and does not change, the technical explainability architecture by model type (SHAP for gradient-boosted models, decision-trail logging for GenAI and agentic systems), and the six governance artifacts that constitute an audit-ready explainability posture for a bank or fintech. - [NAIC AI Model Bulletin requirements for insurers](https://www.thedataexperts.us/writing/naic-ai-model-bulletin-insurers.html): What the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers requires of insurers: a written AI Systems (AIS) Program with governance and board accountability, model validation and testing for errors, bias, and unfair discrimination, and third-party AI oversight where the insurer stays responsible. Includes an AIS-component-to-evidence table for market-conduct exams and how the state-adopted insurance guidance differs from SR 26-2 federal bank model risk. - [Regulation S-P 2024 amendments for broker-dealers and RIAs](https://www.thedataexperts.us/writing/reg-s-p-2024-amendments-broker-dealers-rias.html): What the SEC's 2024 Regulation S-P amendments require now that both compliance dates have passed (larger entities December 3, 2025; smaller entities June 3, 2026): a written incident response program, a 30-day customer breach-notification duty with a documented substantial-harm exception, service-provider oversight including a 72-hour vendor breach-notice arrangement, expanded customer-information scope, and recordkeeping. Includes a Reg S-P obligation-to-evidence table and where AI and generative-AI deployments on customer nonpublic personal information fall inside the rule, plus how Reg S-P differs from SR 26-2 federal bank model risk and NYDFS Part 500 cybersecurity. - [AI security controls for LLM-powered banking chatbots and virtual assistants](https://www.thedataexperts.us/writing/ai-security-controls-llm-banking-chatbots-virtual-assistants.html): The primary deployment-side security controls for LLM-powered banking chatbots: prompt injection guardrails at the input and retrieval layers, output filtering with PII scrubbing, per-session context isolation, action scope limits, human confirmation gates for irreversible account actions, and continuous adversarial monitoring mapped to the OWASP LLM Top 10. Covers the SR 26-2 framing (generative AI chatbots fall outside model-risk scope), supervisory alignment to the June 2023 interagency third-party risk guidance and GLBA, what the LLM vendor SOC 2 report does and does not cover, and the governance evidence a supervisory review expects to find. - [AI risk appetite statements and KRIs for US banks](https://www.thedataexperts.us/writing/ai-risk-appetite-statements-kris-banks.html): How US banks write a defensible AI risk appetite statement and calibrate the ten-indicator KRI framework that makes it operational. Covers the five appetite dimensions (model performance, fair lending, third-party concentration, data protection, operational resilience), the Green/Yellow/Red threshold structure, how the appetite statement connects to SR 26-2 model risk guidance and NIST AI RMF 1.0, and the board reporting cadence that turns the document into an active governance instrument. - [Colorado AI Act for banks and fintechs (SB 26-189)](https://www.thedataexperts.us/writing/colorado-ai-act-financial-services-banks-fintechs.html): What Colorado SB 26-189, effective January 1, 2027, requires of banks, credit unions, mortgage lenders, and fintechs: which AI systems are in scope for consequential-decision obligations, practical exemptions for AML, fraud prevention, sanctions screening, and identity verification tools, and the four compliance actions (website disclosure, advance consumer notice, adverse-outcome notice within 30 days, and human review on request). Covers how the Colorado Act differs from SR 26-2 model risk management and how it intersects with NIST AI RMF 1.0. - [US Treasury Financial Services AI Risk Management Framework: a practical guide for banks](https://www.thedataexperts.us/writing/treasury-financial-services-ai-risk-management-framework-banks.html): The February 2026 Treasury FS AI RMF explained for banks: its four components, how the 230-control-objective risk and control matrix maps to SR 26-2 and the NIST AI RMF, a five-step prioritization sequence, and what an audit-ready posture looks like. Covers why the framework is soft law that is already shaping examiner and internal-audit expectations, how it fills the governance gap for generative and agentic AI that SR 26-2 explicitly excludes, and the evidence an examiner expects to find. - [What a cybersecurity risk assessment includes and costs](https://www.thedataexperts.us/writing/cybersecurity-risk-assessment-what-it-includes-cost.html): The four outputs that define a credible cybersecurity risk assessment (scoping statement, evidence register, Current and Target Profiles against NIST CSF 2.0, severity-ranked findings, prioritized roadmap), the evidence it runs on, the boundary against audits, certifications, penetration tests, and continuous monitoring, and the drivers that actually move price — scope breadth, evidence readiness, regulatory overlay (FTC Safeguards Rule 16 CFR 314.4, HIPAA Security Rule 45 CFR Part 164 Subpart C), depth of validation, deliverable audience, and remediation support. Published anchors: entry Security Posture Assessment from $1,500 for a standardized small-business scope and a $1,250-$1,500 Atlanta Security Readiness Check; deeper national scopes quoted after scoping. Point-in-time advisory work — not an audit, certification, attestation, or guarantee of any compliance or insurance outcome. - [Microsoft 365 security assessment checklist](https://www.thedataexperts.us/writing/microsoft-365-security-assessment-checklist.html): The evidence checklist for a point-in-time manual advisory review of a Microsoft 365 and Microsoft Entra ID tenant, across five surfaces — authentication (MFA coverage by population, legacy authentication, security defaults versus Conditional Access, which is enforced only after first-factor authentication), privilege (standing admin role membership, just-in-time activation, application and service-principal permissions), mail flow and data egress (forwarding rules, SPF/DKIM/DMARC, sharing and anonymous-link policy, out-of-band payment verification), logging and retention (unified audit log, 180-day standard retention), and recovery (holds, external copies, last restore test). References Microsoft Learn documentation, CISA's SCuBA secure configuration baselines and the no-cost ScubaGear assessment tool, and the FBI IC3 2025 Internet Crime Report. Advisory and evaluation only: no automated scan, no hardening, no monitoring, no license resale, no partner or certification status. - [How to prove your backups will actually restore](https://www.thedataexperts.us/writing/prove-backups-restore-before-ransomware.html): Why a green backup job is not evidence and a restore test is, the five properties a drill has to prove (completeness, integrity, isolation from the production identity estate, recovery time, and application-layer operability), how to set RTO and RPO per business process using the NIST SP 800-34r1 definitions, a seven-step drill design, and the one-page restore-test record that later answers an insurer, an acquirer, or a board. Anchored to NIST CSF 2.0 PR.DS-11 and RC.RP-03, CISA's #StopRansomware Guide, and the FBI IC3 2025 Internet Crime Report backup recommendations. Readiness work — not live DFIR, malware eradication, a 24/7 retainer, or a guarantee that recovery will succeed. - [Incident response planning without a security team](https://www.thedataexperts.us/writing/incident-response-planning-without-security-team.html): How an organization with no internal security function builds a working incident response plan — four decision rights with named alternates and written thresholds, the current NIST SP 800-61r3 model (finalized April 3, 2025) that replaces the four-phase life cycle with one built on the six CSF 2.0 Functions, a one-page first-hour guide (isolate rather than power off, start a written timeline, preserve rather than clean, call in order, contain what is understood), the offline contact sheet including the carrier breach hotline and a named DFIR specialist, the written-plan and 30-day notification duties under FTC Safeguards Rule 16 CFR 314.4(h) and (j), and a cheap tabletop cadence. Planning and facilitation only — not live DFIR, breach counsel, or 24/7 response. - [vCISO vs MSP vs MDR: who owns what](https://www.thedataexperts.us/writing/vciso-vs-msp-vs-mdr-who-owns-what.html): A RACI dividing security responsibility across fractional security leadership (risk register, roadmap, policy, board reporting, provider selection), managed IT (endpoint, patching, identity administration, backup operation), and managed detection (24/7 monitoring, triage, contracted containment), plus the two rows organizations usually leave blank — who performs live digital forensics and who accepts residual risk. Covers the three seams where failures cluster, a buying order for 50-to-500-person firms, and the contract terms to hold each provider to. Anchored to NIST CSF 2.0 GV.SC-02 and GV.SC-08 and CISA's Cross-Sector Cybersecurity Performance Goals 2.0. DSE is the direction layer: it does not operate a SOC or MDR, does not perform live DFIR, and does not inherit any provider's detection SLA; provider selection is vendor-neutral and referral relationships are disclosed. - [Cyber insurance evidence readiness checklist](https://www.thedataexperts.us/writing/cyber-insurance-evidence-readiness-checklist.html): The eight artifact bundles that answer a cyber insurance underwriting questionnaire accurately — identity and access, backup and restore-test evidence, endpoint and email controls, payment and social-engineering process controls, governance, testing and vulnerability management, incident response, and third parties — plus why a qualified yes with a remediation date beats an unsupported yes, and how to organize the pack against CIS Critical Security Controls v8.1 Implementation Group 1 (56 Safeguards, essential cyber hygiene) or CISA's Cross-Sector Cybersecurity Performance Goals 2.0. The same pack answers enterprise customer questionnaires and diligence requests. Not insurance advice, not a broker service, and not a guarantee of coverage, premium, or claim outcome. - [NIST CSF 2.0 roadmap for 50 to 500 employees](https://www.thedataexperts.us/writing/nist-csf-2-0-roadmap-50-500-employees.html): A four-quarter adoption sequence for mid-market organizations — Q1 scope one Profile plus GOVERN and the asset and data inventory, Q2 PROTECT led by identity then backup and platform hygiene, Q3 logging and response decision rights before evaluating managed detection, Q4 RECOVER, third-party risk, and the re-profile. Covers the three artifacts CSF 2.0 asks for (Current Profile, Target Profile, action plan), NIST's five-step Organizational Profile process, and picking an honest Tier (Partial, Risk Informed, Repeatable, Adaptive) rather than a declared one. Effort sizing and quarter structure are DSE practitioner judgment, not NIST prescriptions; CSF 2.0 is voluntary and has no certification regime. - [Vendor security review checklist for SaaS buyers](https://www.thedataexperts.us/writing/vendor-security-review-checklist-saas-buyers.html): Conventional SaaS and service-provider security review — tiering by data exposure and operational dependency before assessing, reading an independent audit report properly (scope, type and period, testing exceptions, and the complementary user entity controls the customer must operate), the short question set that matters at critical tier, the contract terms that outlive the questionnaire (breach-notification window mapped against downstream obligations, sub-processor notice, evidence rights, certified data return, incident cooperation), and post-signature monitoring and exit planning. Anchored to NIST CSF 2.0 GV.SC-01 through GV.SC-10, the CSF 2.0 C-SCRM quick start guide, NIST SP 800-161r1, FTC Safeguards Rule 16 CFR 314.4(f), and HIPAA at 45 CFR Part 164. Deliberately distinct from third-party AI vendor risk review, which adds model governance, training-data handling, and foundation-model concentration questions. ## Contact - [Engage DSE](https://www.thedataexperts.us/engage.html): Scope a fixed-fee AI governance readiness or AI security engagement.