§ DSE Security·cyber risk & resilience

Business protection, not IT help.

We reduce the chance of email fraud, ransomware, credential theft, vendor risk, and unsafe AI use, and we give leadership a clear plan to fix the gaps that matter most. Most security incidents at companies this size do not come from sophisticated attackers. They come from the basics being undone. We give you a clear, prioritized picture, the policies and baseline to close the gaps, and ongoing senior leadership to keep them closed. Federal-grade rigor, scaled to a growing company's budget and stage.

NIST CSF CIS Controls NIST AI RMF OWASP LLM Top 10 RMF / ATO CMMC-aware
Book a free 30-minute Cyber Risk Check See the division catalog → for growing and mid-market companies across the United States

The basics, undone, cause most incidents.

An executive without MFA, a backup nobody has tested, a contractor with standing access nobody revoked, an employee pasting client data into a public AI tool. This is the division built for the person who owns security risk, whether that is a dedicated security lead or CISO, or the COO, VP of Engineering, or owner carrying that load at a company without one. Growing and mid-market companies (roughly 50 to 500 employees) and funded startups, without a full internal security team and not ready to hire one, but past the point where "we'll deal with it later" is safe.

5 to 10
business days for the Security Baseline Assessment, the first paid step that turns the catalog into one prioritized picture. Leadership knows the risk is there. They just do not have a clear, prioritized picture of where it sits or what to fix first.
§ The paid wedge·Security Baseline Assessment · six named deliverables
01
Cyber Risk Assessment

Your security posture mapped against the NIST Cybersecurity Framework and CIS Controls, based on configuration review, interviews, and observable evidence. A ranked gap list: what is most likely to hurt you, and why.

control and configuration assessment · based on what is observable. Not a penetration test and does not claim to find every vulnerability.
02
Email & Identity Hardening Review

MFA coverage and gaps, privileged and executive account protection, and account-takeover exposure across Microsoft 365 or Google Workspace, with prioritized fixes.

03
Vendor & Connected-App Review

Third-party tools, contractors, and OAuth-connected apps that touch your data, with the high-risk grants flagged for removal or tightening.

04
Ransomware & Backup Resilience Check

Backup coverage review plus a restore test or tabletop to confirm recovery actually works, and recommendations to reduce blast radius.

05 · crossover
Secure AI Use Summary

A focused read on where AI tools are creating data exposure, with rules anchored to the NIST AI RMF and OWASP LLM Top 10. The full version is the AI-path offer; here it is the security-lens summary.

Go deeper on the AI front door →
06
Prioritized Remediation Roadmap

Your next three security moves, plus a 90-day plan sequenced by risk and effort. The document leadership uses to decide where to spend, and it sets up the remediation sprint and the fractional engagement.

§ Method & credibility·federal-grade rigor, by the person doing the work

Delivered by a senior Solutions Architect whose security experience comes from regulated financial services and federal environments, where controls are not optional and an audit clock is always running. That background includes authority-to-operate (ATO) documentation under the NIST Risk Management Framework, CMMC-aware federal delivery, cloud security on AWS, and identity and access (IAM) and least-privilege architecture as a core discipline. On the AI side, it includes red-teaming of agentic workflows (prompt injection, tool abuse, data exfiltration) and governance under the NIST AI RMF. You are getting federal-grade security rigor and genuine AI-security depth, applied at a growing company's scale. Not a junior analyst with a template.

§ Offer ladder·from free door to recurring
Free door
30-Minute Cyber Risk Check
Identify highest-risk gaps and your next three moves.
Free
The sprint
Security Baseline Assessment
The fixed-fee sprint above. Tiered by company size and complexity.
$2,500 to $5,000
Execute
30-Day Remediation Sprint
Execute the top priorities from the roadmap. Scoped and fixed-fee off the findings.
from $7,500
Ongoing
Fractional Security Leadership
Ongoing senior security ownership, typically 10 to 20 hours per week.
$5,000 to $10,000 / mo
Assessment tiers · fixed fee, no time-and-materials · 50% on kickoff, 50% on delivery
TierScopeInvestment
EssentialsSingle environment, team under ~75. All six deliverables, written readout.$2,500
FoundationUp to ~250 employees. Adds deeper vendor and supply-chain review and a live leadership readout.$3,750
Foundation+Up to ~500 employees or a regulated environment. Adds a board-ready deck and a 30-day check-in.$5,000

Priced as an approvable expense, not a procurement event.

§ What is out of scope·boundaries are a credibility signal

Assessment and advisory, not a SOC.

§ Two front doors·cybersecurity help or AI help

Looking for AI help, not just security?

This page is the security front door. If your week is mostly about employees pasting client data into public AI tools and a governance posture you need on the record, start at the AI front door instead. The Secure AI Use Review is the deliberate crossover point, so wherever you start, you can reach it.

Safe AI & Security Foundation →

Would your backups actually restore? Find out in 30 minutes.

Most companies your size are one tested backup, one MFA gap, or one over-permissioned vendor away from a bad week. No pitch, just your top gaps and next three moves.

Book a free 30-minute Cyber Risk Check Scope a call →