Cybersecurity
Framework assurance, infrastructure audits, and the technical procedures that produce evidence rather than opinions.
Everyone has a framework. Nobody has evidence.
A control framework is adopted, mapped to a standard, and presented to the board as coverage. Two years later the mapping is still accurate on paper and nobody can produce evidence that a single control operated in the last quarter — because mapping a control and testing one are different activities, and only the first has ever been budgeted.
Then something happens, and the question is not was there a framework but can you show it worked. That is a different question and it is answered with test evidence or not at all.
Bought as a project. Delivered as a product.
Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.
Six weeks, evidence first.
A framework audit, week by week. The criteria are agreed and printed before fieldwork, so nobody discovers the standard mid-engagement.
The standard you are audited against, agreed in writing, and the control points selected from it.
Partner gateEach control tested twice — could it work as designed, and did it work in the period. Evidenced as we go.
Rated by residual risk before management sees them, then reviewed against the methodology by a second specialist.
Partner gateAn opinion your committee can rely on, plus a remediation plan sequenced by exposure.
Partner gateThe same machine, pointed at your estate.
Cyber work is where the gap between a claim and its evidence is widest, so this is the area where structure matters most.
Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth, including what we hold back and why, on the method page.
Three things, three different buyers.
This is the area where who commissions the work decides what the work is, so it is worth thirty seconds before you pick.
The cybersecurity framework tested for operating effectiveness, design and operation reported separately. An opinion your Audit Committee can rely on — which means your Chief Audit Executive commissions it, not your CISO.
Penetration and vulnerability testing. A procedure produces findings, not an opinion on anyone’s function — so either buyer may commission it, and internal audit can put it inside an audit as evidence.
6 engagements, every box printed.
Tap any one to read its scope box — what we analyze, how scope gets chosen, what is tested, what the report contains, and what the remediation plan does and doesn’t include. Prices come from one published formula.
Family A · Assurance
Assurance — an opinion your Audit Committee can rely on. Bought by the Chief Audit Executive.
C1 Technology System Audit — 45 control points, 5 SoD · 500 credits · $25,000 +
- 01System and interface map — what the application does, what it touches, where data enters and leaves
- 02Configuration review — the settings that enforce policy, tested as configured rather than as documented
- 0345 control points tested — access, change, interface integrity, processing accuracy, and 5 SoD points
- 04Final report — traceable to evidence held in Clarus
- 05Remediation plan — sequenced against the system’s own release calendar, so fixes land where they can be deployed
C2 Active Directory Audit — 35 control points, 5 SoD · 620 credits · $31,000 +
- 01Directory topology and trust review — domains, forests, trusts, and what each implicitly grants
- 02Privileged access analysis — every account with elevated rights, tested against a named human owner
- 0335 control points tested — account lifecycle, group nesting, GPO enforcement, stale and orphaned objects, 5 SoD points on privilege combinations
- 04Final report — findings rated by exploitability, not just by policy deviation
- 05Remediation plan — prioritized to sequence cleanup without breaking access
C3 Remote and VPN Audit — 25 control points · 570 credits · $28,500 +
- 01Remote access inventory — every path into the estate, including the ones not on the diagram
- 02Authentication and posture review — MFA coverage, device posture, split-tunnel and always-on policy as configured
- 0325 control points tested — provisioning, session handling, logging, third-party and vendor access
- 04Final report — with the access paths nobody owned, named
- 05Remediation plan — ordered by exposure, quick closures separated from architectural ones
C4 Cybersecurity Framework Audit — 60 control points, 5 SoD · 920 credits · $46,000 +
- 01Framework selection and criteria agreement — the standard you are audited against, agreed and printed before fieldwork
- 02Control design assessment — whether the control as designed could achieve the objective
- 0360 control points tested for operating effectiveness — designed and operating reported separately, because the difference is where breaches live
- 04Final report — an opinion the Audit Committee can rely on, not a maturity score
- 05Remediation plan — prioritized by residual risk
If you want this for your own function rather than for the committee, you want B1 — and the difference is not cosmetic.
Family B · Assessment
Assessment — a diagnostic, no assurance opinion. Bought by the function’s own head, except where the item is a procedure.
C5 Cyber Framework Maturity Assessment — ~22 domains · 860 credits · $43,000 +
- 01Framework and target-state agreement — the standard and the maturity level you are aiming for, agreed before assessment
- 02Evidence-based scoring across 22 domains — interviews plus artefacts, never self-assessment questionnaires alone
- 03Current-state maturity rating per domain, with the evidence behind each score attached
- 04Gap analysis to target state — costed by effort band, not by wishful thinking
- 05Roadmap — sequenced, dependencies named. An assessment, not an audit — no assurance opinion is expressed
C6 Penetration and Vulnerability Assessment — 4 targets · 560 credits · $28,000 +
- 01Scope and rules of engagement — targets, windows, escalation path and stop conditions, signed before anything starts
- 02Vulnerability assessment across the agreed estate — authenticated where it should be, because unauthenticated scanning flatters everyone
- 03Manual exploitation against 4 targets — chained where chaining is possible, since real attackers do not test controls one at a time
- 04Technical report plus an executive summary a board can read without a translator
- 05Retest of remediated findings — included, within 90 days. A finding isn’t closed because someone said so
One target is one application, one internal segment, or one external perimeter range.
Anything here can join a plan built in any other area — a penetration test can sit inside an internal audit year. Build a plan →
Cyber & Privacy Framework Audits
The framework tested, and the system underneath it. The cybersecurity framework tested for operating effectiveness rather than scored for maturity, and the technology system that carries it audited in the same block.
Same engagements, same menu prices — buying the block as a year changes nothing except that it is worth buying at once. Read the full card, including what it forecloses →
What we do · Cybersecurity
One thing worth knowing before you buy.
Every recurring service we run forecloses the assurance over it. If we keep your framework alive we cannot audit it, and if we audit it we cannot keep it alive. You choose which, we print the consequence before you buy rather than after, and where an Audit Committee relationship already exists we protect it.
Part of the Signify family
Solve · Build · Teach · Sustain. Four properties, one design language — consulting, software, interactive learning and sustained advisory, built in Philadelphia since 2019.
Premium management consulting across strategy, cybersecurity, audit, GRC and regulatory readiness. Every engagement partner-led.
signifysolution.comConsulting, new age. Seven practitioner-built products — the tools that stay behind at clients as running value.
signifyhive.comPlay, test, think. Games, assessments, simulations and Points of View — learn the work by doing it.
signifyinsights.com You are hereConsulting, sustained. Time-boxed, and scope-boxed engagements at transparent rates. Clear pricing. Explicit scope.
signifyimpact.com