What we do · Cybersecurity
Cybersecurity · Boxes printed
What we do·Cybersecurity

Cybersecurity

Framework assurance, infrastructure audits, and the technical procedures that produce evidence rather than opinions.

What actually breaks

Everyone has a framework. Nobody has evidence.

A control framework is adopted, mapped to a standard, and presented to the board as coverage. Two years later the mapping is still accurate on paper and nobody can produce evidence that a single control operated in the last quarter — because mapping a control and testing one are different activities, and only the first has ever been budgeted.

Then something happens, and the question is not was there a framework but can you show it worked. That is a different question and it is answered with test evidence or not at all.

The comparison

Bought as a project. Delivered as a product.

Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.

How this is normally bought
A maturity score, presented as assurance
A questionnaire the security team completes about itself
A penetration test whose findings nobody maps to controls
The same firm building the programme and assessing it
How it works here
Design and operation tested separately, and reported separately, because the gap between them is where breaches live
Evidence-based testing — artefacts and transactions, not self-assessment
Findings that land in a register with an owner and a retest date
Published foreclosure — if we maintain your posture we cannot audit it, and we say which we are doing
The schedule

Six weeks, evidence first.

A framework audit, week by week. The criteria are agreed and printed before fieldwork, so nobody discovers the standard mid-engagement.

Week 1
Criteria and scope lock

The standard you are audited against, agreed in writing, and the control points selected from it.

Partner gate
Weeks 2–4
Design and operating tests

Each control tested twice — could it work as designed, and did it work in the period. Evidenced as we go.

Week 5
Findings and peer review

Rated by residual risk before management sees them, then reviewed against the methodology by a second specialist.

Partner gate
Week 6
Opinion and readout

An opinion your committee can rely on, plus a remediation plan sequenced by exposure.

Partner gate
Why it repeats

The same machine, pointed at your estate.

Cyber work is where the gap between a claim and its evidence is widest, so this is the area where structure matters most.

2
tests per control — designed, and operating
6
engagements in this area, every box printed
3
partner gates on every one
0
maturity scores sold as assurance

Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth, including what we hold back and why, on the method page.

Engagements

6 engagements, every box printed.

Tap any one to read its scope box — what we analyze, how scope gets chosen, what is tested, what the report contains, and what the remediation plan does and doesn’t include. Prices come from one published formula.

Family A · Assurance

Assurance — an opinion your Audit Committee can rely on. Bought by the Chief Audit Executive.

C1  Technology System Audit — 45 control points, 5 SoD · 500 credits · $25,000 +
The box500 credits · $25,000
  • 01System and interface map — what the application does, what it touches, where data enters and leaves
  • 02Configuration review — the settings that enforce policy, tested as configured rather than as documented
  • 0345 control points tested — access, change, interface integrity, processing accuracy, and 5 SoD points
  • 04Final report — traceable to evidence held in Clarus
  • 05Remediation plan — sequenced against the system’s own release calendar, so fixes land where they can be deployed
Count agreed at scope lock, before fieldworkThe formula never moves
C2  Active Directory Audit — 35 control points, 5 SoD · 620 credits · $31,000 +
The box620 credits · $31,000
  • 01Directory topology and trust review — domains, forests, trusts, and what each implicitly grants
  • 02Privileged access analysis — every account with elevated rights, tested against a named human owner
  • 0335 control points tested — account lifecycle, group nesting, GPO enforcement, stale and orphaned objects, 5 SoD points on privilege combinations
  • 04Final report — findings rated by exploitability, not just by policy deviation
  • 05Remediation plan — prioritized to sequence cleanup without breaking access
Count agreed at scope lock, before fieldworkThe formula never moves
C3  Remote and VPN Audit — 25 control points · 570 credits · $28,500 +
The box570 credits · $28,500
  • 01Remote access inventory — every path into the estate, including the ones not on the diagram
  • 02Authentication and posture review — MFA coverage, device posture, split-tunnel and always-on policy as configured
  • 0325 control points tested — provisioning, session handling, logging, third-party and vendor access
  • 04Final report — with the access paths nobody owned, named
  • 05Remediation plan — ordered by exposure, quick closures separated from architectural ones
Count agreed at scope lock, before fieldworkThe formula never moves
C4  Cybersecurity Framework Audit — 60 control points, 5 SoD · 920 credits · $46,000 +
The box920 credits · $46,000
  • 01Framework selection and criteria agreement — the standard you are audited against, agreed and printed before fieldwork
  • 02Control design assessment — whether the control as designed could achieve the objective
  • 0360 control points tested for operating effectiveness — designed and operating reported separately, because the difference is where breaches live
  • 04Final report — an opinion the Audit Committee can rely on, not a maturity score
  • 05Remediation plan — prioritized by residual risk
Count agreed at scope lock, before fieldworkThe formula never moves

If you want this for your own function rather than for the committee, you want B1 — and the difference is not cosmetic.

Family B · Assessment

Assessment — a diagnostic, no assurance opinion. Bought by the function’s own head, except where the item is a procedure.

C5  Cyber Framework Maturity Assessment — ~22 domains · 860 credits · $43,000 +
The box860 credits · $43,000
  • 01Framework and target-state agreement — the standard and the maturity level you are aiming for, agreed before assessment
  • 02Evidence-based scoring across 22 domains — interviews plus artefacts, never self-assessment questionnaires alone
  • 03Current-state maturity rating per domain, with the evidence behind each score attached
  • 04Gap analysis to target state — costed by effort band, not by wishful thinking
  • 05Roadmap — sequenced, dependencies named. An assessment, not an audit — no assurance opinion is expressed
Count agreed at scope lock, before fieldworkThe formula never moves
C6  Penetration and Vulnerability Assessment — 4 targets · 560 credits · $28,000 +
The box560 credits · $28,000
  • 01Scope and rules of engagement — targets, windows, escalation path and stop conditions, signed before anything starts
  • 02Vulnerability assessment across the agreed estate — authenticated where it should be, because unauthenticated scanning flatters everyone
  • 03Manual exploitation against 4 targets — chained where chaining is possible, since real attackers do not test controls one at a time
  • 04Technical report plus an executive summary a board can read without a translator
  • 05Retest of remediated findings — included, within 90 days. A finding isn’t closed because someone said so
Count agreed at scope lock, before fieldworkThe formula never moves

One target is one application, one internal segment, or one external perimeter range.

Anything here can join a plan built in any other area — a penetration test can sit inside an internal audit year. Build a plan →

Bought as a bundle

Cyber & Privacy Framework Audits

The framework tested, and the system underneath it. The cybersecurity framework tested for operating effectiveness rather than scored for maturity, and the technology system that carries it audited in the same block.

Composition
C4 · C1
Credits
1,420 cr
At base rate
$71,000

Same engagements, same menu prices — buying the block as a year changes nothing except that it is worth buying at once. Read the full card, including what it forecloses →

What we do · Cybersecurity

One thing worth knowing before you buy.

Every recurring service we run forecloses the assurance over it. If we keep your framework alive we cannot audit it, and if we audit it we cannot keep it alive. You choose which, we print the consequence before you buy rather than after, and where an Audit Committee relationship already exists we protect it.