How we work
Who does the review, what we will not do, and the scale every finding is rated on.
Independence
We resell nothing, deploy nothing, and take no commissions from any vendor, insurer, or provider whose work we evaluate. The findings are yours to take to your own team or providers. If you want our help afterward, that is separate work, agreed separately. If we help plan or design a change, any later closure check records our involvement and is advisory, not independent assurance.
Who does the work
Every assessment is conducted by a CISM-certified security practitioner with a background in security operations, detection engineering, vulnerability and exposure management, identity security, and governance. The practitioner is a United States Army veteran.
Prospective clients can verify credentials and background under mutual NDA before an engagement begins. We do not publish personal identities on this site.
Our position on AI
No client documents, email, configuration data, or other client material enters any AI system, public or private. We do not mask or de-identify client material for AI use, because a client cannot verify that. Every analysis, finding, and report is performed and written by a person. AI tools support only general research and drafting against public material. This is firm policy, not a case-by-case decision.
Review and corrections
Before the report is final, the client and participating providers can correct factual errors or provide relevant records. We name the evidence cutoff, missing records, and any material disagreement. Insufficient evidence or a domain outside scope is reported as such; neither becomes a maturity score of zero.
The scale
Where the evidence supports a rating, a domain gets a status and a maturity score. The status (Defensible, At Risk, Critical Gap) is the finding. The maturity score, on our own 0 to 5 scale below, describes how the control is managed. It is not a NIST certification or maturity tier. Findings carry a severity, and each severity has a remediation window. How we test shows six of the checks in full.
| Score | Label | What it means |
|---|---|---|
| Score 0 | Nonexistent | No control exists. The risk is unmanaged and unowned. |
| Score 1 | Initial | The control exists in an ad hoc, undocumented, person-dependent form. |
| Score 2 | Repeatable | The control is applied consistently but relies on informal habits, not a written process. |
| Score 3 | Defined | The control is documented, assigned an owner, and applied on a known schedule. |
| Score 4 | Managed | The control is measured. Someone reviews its effectiveness on a regular cadence. |
| Score 5 | Optimized | The control is measured, reviewed, and actively improved based on what the measurements show. |
| Severity | Remediation window |
|---|---|
| Critical | 0-30 days |
| High | 30-90 days |
| Medium | 90-180 days |
| Low | 180+ days |
The windows guide planning. An active threat or an exposed recovery path can need action the same day, and the finding says so.
See it applied to your business
Tell us what you need to understand about your security arrangements, and we will discuss scope before proposing an engagement.
Contact us about a review