Skip to content

How we work

Who does the review, what we will not do, and the scale every finding is rated on.

Independence

We resell nothing, deploy nothing, and take no commissions from any vendor, insurer, or provider whose work we evaluate. The findings are yours to take to your own team or providers. If you want our help afterward, that is separate work, agreed separately. If we help plan or design a change, any later closure check records our involvement and is advisory, not independent assurance.

Who does the work

Every assessment is conducted by a CISM-certified security practitioner with a background in security operations, detection engineering, vulnerability and exposure management, identity security, and governance. The practitioner is a United States Army veteran.

Prospective clients can verify credentials and background under mutual NDA before an engagement begins. We do not publish personal identities on this site.

Our position on AI

No client documents, email, configuration data, or other client material enters any AI system, public or private. We do not mask or de-identify client material for AI use, because a client cannot verify that. Every analysis, finding, and report is performed and written by a person. AI tools support only general research and drafting against public material. This is firm policy, not a case-by-case decision.

Review and corrections

Before the report is final, the client and participating providers can correct factual errors or provide relevant records. We name the evidence cutoff, missing records, and any material disagreement. Insufficient evidence or a domain outside scope is reported as such; neither becomes a maturity score of zero.

The scale

Where the evidence supports a rating, a domain gets a status and a maturity score. The status (Defensible, At Risk, Critical Gap) is the finding. The maturity score, on our own 0 to 5 scale below, describes how the control is managed. It is not a NIST certification or maturity tier. Findings carry a severity, and each severity has a remediation window. How we test shows six of the checks in full.

Maturity scale
Score 0NonexistentNo control exists. The risk is unmanaged and unowned.
Score 1InitialThe control exists in an ad hoc, undocumented, person-dependent form.
Score 2RepeatableThe control is applied consistently but relies on informal habits, not a written process.
Score 3DefinedThe control is documented, assigned an owner, and applied on a known schedule.
Score 4ManagedThe control is measured. Someone reviews its effectiveness on a regular cadence.
Score 5OptimizedThe control is measured, reviewed, and actively improved based on what the measurements show.
Remediation windows
SeverityRemediation window
Critical0-30 days
High30-90 days
Medium90-180 days
Low180+ days

The windows guide planning. An active threat or an exposed recovery path can need action the same day, and the finding says so.

See it applied to your business

Tell us what you need to understand about your security arrangements, and we will discuss scope before proposing an engagement.

Contact us about a review