Devensa Advisory
Get started
Florida

Florida organizations deserve someone to help them own the whole picture.

Continuity
Cybersecurity
Permission to move
AI Governance
One narrative
Risk Management
Defensibility
Compliance
Public trust
Privacy
Capacity
Data Governance

One advisory practice across six governance domains. We meet you where you are, build a roadmap designed to function as one system, and work the gaps in the order that fits your organization.

Request a briefing
Start where you are

The same six domains. A different conversation in each sector.

Select where you sit today.

Preparation windows are longer than compliance windows.

Health systems, physician groups, and post-acute providers preparing for what is coming rather than reacting to it.

Obligations sit across privacy, security, vendor risk, and now clinical AI, usually under separate owners working separate calendars.

The organizations in the least difficulty later tend to be the ones that built the inventory and the cadence before they were asked to produce them.

One inventory, many uses
Assets, systems, data flows, and third parties recorded once and reused.
Clinical AI oversight
Approved use, human review, and escalation defined ahead of deployment.
Evidence on a schedule
Risk analysis and testing that run on a cadence rather than on request.

The standard is adopted. The structure behind it is the open question.

Counties, municipalities, and special districts operating under adopted standards with nothing behind them.

Adopting a standard is a resolution. Operating one is a set of owners, intervals, and records that hold up when somebody asks for them. Most of the distance between the two sits in roles nobody has been assigned.

Commissions and councils ask for assurance in plain terms and on their own schedule. That is a reporting problem before it is a technical one.

Ownership across departments
Named accountability in each domain, so a question has a destination.
Reporting a commission can follow
One consistent risk narrative, in language that needs no translation at the dais.
Evidence kept on a cadence
Records that exist before the audit, the renewal, or the incident, not after.

Student data across more systems than any one office runs.

K-12 school districts, and colleges and universities, each answering to a board for information they do not fully control.

Districts carry student records across dozens of instructional tools with a small internal team. Colleges and universities add research data, decentralized IT, and units that adopt technology on their own.

In both, AI arrives through classrooms and vendors before anyone has defined approved use, and boards expect a plain answer when families or trustees ask.

Student data mapped
Which systems hold student records, under which agreements, and who can reach them.
Approved use for AI
Rules for staff and students, and review of AI features arriving inside licensed software.
Reporting a board can follow
One risk narrative for the school board or trustees, with the same measures every meeting.

Independent boards, independent budgets, shared exposure.

Water, wastewater, ports, aviation, traffic, and utility authorities with their own boards and their own budgets.

Authorities run their own capital plans and answer to their own boards, while the operational technology behind service delivery sits outside most enterprise oversight.

Risk and resilience work already happens on a defined cycle. The question is what holds governance together between cycles.

Operational technology in scope
The automated systems that run service, treated as governed assets.
Reporting your own board can act on
A view built for an authority board, not borrowed from a county model.
Continuity between cycles
Structure that holds in the years between required recertification.

Physical security is disciplined. The technology behind it has not been held to the same terms.

Operators whose physical security is already mature, while AI adoption, technology convergence, and vendor risk have not kept pace.

These operations run structured physical security programs with clear command lines. That same rigor has rarely been applied to the platforms, integrations, and vendors the operation now depends on.

Adoption in guest experience, workforce, and monitoring moves faster than the policy governing it.

Physical and technical, one model
A single oversight structure and a single reporting line across both.
Vendor and integration risk
Third parties governed on the same terms as systems you run yourself.
AI in guest and workforce operations
Approved use, human oversight, and a record of who decided what.

Obligations you did not write, arriving through the contract.

Firms that inherit governance obligations through contracts, procurement, and client demands.

Selling into government, healthcare, and critical infrastructure means taking on requirements written into procurement language, flow-down clauses, and client security reviews.

The requirement is rarely the hard part. Demonstrating it consistently, across every contract, is.

Flow-down mapped to controls
Obligations traced from the clause to the control that answers it.
Answers ready before the review
Documentation current when a client asks, not assembled afterward.
One posture, every client
A single structure built to satisfy several procurement regimes at once.

Each sector arrives with a different starting point. The first conversation is how we find yours.

Request a briefing
The gap

Fragmented oversight is the real exposure.

01

Security is reactive.

Work is triggered by incidents, audits, and renewals rather than by a cycle the organization sets for itself.

02

AI initiatives move ahead of policy.

Tools arrive through departments and vendors and enter daily use before anyone has defined approved use.

03

Compliance functions operate in silos.

The same evidence is gathered more than once, in different formats, for different audiences.

04

Boards receive inconsistent risk narratives.

Each report reflects whoever prepared it, so trend and priority are difficult to read across meetings.

Devensa integrates these functions into one executive model. We do not add complexity. We design operating architecture.

Six governance domains, run as one practice

What each domain is actually for.

Governance, compliance, and risk read as cost and process to most leadership teams. Stated as outcomes, they are terms leadership already cares about. Work one domain at a time and close its gaps, or run several in parallel. Each one closes into the same structure.

Cybersecurity 01

Continuity

Service keeps running through the week that would otherwise have stopped it. Recovery is a plan, not an improvisation.

  • Security program charter, ownership, and executive reporting cadence
  • Control framework selection and security architecture review
  • Incident response structure, playbooks, and tabletop exercises
Operational resilience
Continuity of operations planning, tabletop exercises, recovery, and crisis decision support.
AI Governance 02

Permission to move

Staff can adopt new tools because the rails already exist. Policy stops arriving after the tools do.

  • Use case inventory and risk tiering across the organization
  • Acceptable use policy, human oversight, and escalation paths
  • Model and vendor review requirements before adoption
Risk Management 03

One narrative

The board or commission hears the same risk story each time it meets, with the same measures behind it.

  • Risk register design with named owners and review intervals
  • Risk appetite, tolerance thresholds, and escalation criteria
  • A consistent reporting format for boards and commissions
Compliance 04

Defensibility

When an auditor, an insurer, or a funding agency asks, the answer is documented, current, and owned.

  • Obligation mapping across statute, contract, and funding conditions
  • Internal control design and routine evidence collection
  • Audit readiness and a structure for remediating findings
Privacy 05

Public trust

Residents, patients, and students can see how their information is held and who is answerable for it.

  • Personal data inventory and records of processing
  • Notice, consent, and individual rights procedures
  • Third party and processor oversight, from intake to exit
Data Governance 06

Capacity

Data becomes something departments can build on rather than something nobody wants to own.

  • Data ownership and stewardship model across departments
  • Classification, retention, and quality standards
  • A modernization roadmap for platforms and reporting

We meet each client where they are and build a roadmap that is designed to function as one system for improved maturity. That integration is the difference.

How it works

A sequence you can start, pause, and resume at your speed and budget.

01

Educate

Build executive and workforce understanding of value, limits, threats, and approved use.

02

Assess

Inventory use cases and systems. Evaluate data, identity, integrations, and third-party exposure, then score maturity in each domain.

03

Plan

Sequence the gaps into a roadmap with owners, budget, and a defined order of work.

04

Execute

Work the roadmap in sequence: controls, policy, and testing, with monitoring and response playbooks behind them.

05

Govern

Hold attestation-ready evidence, review cadence, and reporting so the structure stays in place.

Scored on TruMaturity™

Assessment is scored on the proprietary TruMaturity™ framework, which produces a maturity score for each domain and an overall TruMaturity™ score. Those scores are structured to guide budget allocation discussions and to prioritize which gaps are addressed first.

Built for a budget cycle

The sequence is designed to fit how public bodies actually fund work: one domain at a time, with a scored before and after, so each request carries its own justification and each completed step raises the same overall measure.

The decision

How Devensa Advisory compares with the alternatives.

Four common ways to close a governance gap, compared side by side on what each covers and what remains once the work ends. Only one covers all six domains on a single scale.

Hire the function

Coverage

Depth in one domain, on one salary line.

What remains after

The role, for as long as the person stays.

Retain a project consultant

Coverage

Expert judgment inside a defined scope.

What remains after

A report, and the question of who operates it.

Buy a tool

Coverage

The loudest problem, addressed directly.

What remains after

A tool to administer, and five domains unmeasured.

Devensa Advisory

Coverage

All six domains, scored on one scale.

What remains after

Measurable maturity across all six domains, and the structure your own team runs to hold it.

Request a briefing
Bryan J. Langley, Executive Advisor, Critical Infrastructure, Devensa Advisory
In Florida

Bryan J. Langley

Executive Advisor, Critical Infrastructure, Devensa Advisory

LinkedIn profile

Bryan J. Langley spent his career at the intersection of public safety, critical infrastructure, and government leadership before joining Devensa Advisory as Executive Advisor, Critical Infrastructure.

He was appointed Senior Advisor at Cyber Florida, where he led and coordinated public and private efforts to develop the state’s critical infrastructure risk assessment, including a report to the Governor, the Legislature, and the Cybersecurity Advisory Council on protecting Florida’s critical infrastructure from major cybersecurity incidents.

What is driving this now

What is already in writing.

Section 282.3185, Florida Statutes

Counties and municipalities are required to adopt NIST-aligned cybersecurity standards, provide tiered employee training, and report incidents on defined timelines.

America’s Water Infrastructure Act, Section 2013

Community water systems above a defined population threshold are required to assess risk and resilience, including the security of the automated systems they operate, and recertify every five years.

HIPAA Security Rule

A proposed overhaul would add mandatory risk analysis cadence, asset inventory, network mapping, and defined testing schedules. Preparation windows are longer than compliance windows.

Artificial intelligence

Florida has not adopted an AI mandate. Obligations arrive instead through duties that already exist: public records, procurement terms, privacy requirements, and contracts already signed. Adoption commonly moves ahead of the policy governing it.

Straight answers

The questions we are asked first.

How is this different from what our IT team already does?

It complements the work IT is already doing. IT carries the systems. Devensa works across all six domains, at the executive level and in the delivery itself, naming owners across departments, building policy and controls, and defining what gets reported and to whom. Several of those domains reach past IT into legal, procurement, operations, and clinical or field leadership, which is why the work sits above any single function.

What do you actually deliver?

A comprehensive menu across all six governance domains: program design, policy and control build, architecture and process review, testing and exercises, training, recurring review, and fractional executive leadership where it fits. Work is selected against your maturity roadmap rather than sold as a fixed package.

Are you selling a tool?

No. Devensa Advisory does not resell or implement third-party security products, and takes no position on which ones you run.

Can you work alongside the vendors and consultants we already use?

Yes. Devensa works alongside the providers already in place, and nothing here requires changing them. In most cases the engagement clarifies what each one is accountable for and where the remaining work sits.

Do we have to start with all six domains?

No. Most organizations start with one domain and add others as capacity and budget allow. Because the work in every domain is sequenced against the same maturity roadmap, each piece raises the same overall measure instead of becoming a separate program.

How does this fit a public budget cycle?

Each domain carries a scored position before and after, so a request can be justified on its own terms. The sequence is built to pause at a fiscal year boundary and resume without rework.

What does a board or commission actually see?

One risk narrative, using the same measures at every meeting, with the domain breakdown sitting behind a single overall score.

We already have an assessment on file.

Good. An assessment describes a point in time. What we look at is whether ownership, cadence, and reporting exist to carry its findings forward, and what happens to them between cycles.

Start with a conversation, not a proposal.

Devensa offers a no-fee leadership or board briefing on governance structure in your sector. No pitch, no assessment required.

What you leave with
  • A plain description of how your six domains are governed today
  • Where accountability is currently unassigned
  • A sequence you can take into a budget conversation

Working with organizations across Florida, including Tampa Bay, Orlando, Jacksonville, Miami, and Tallahassee.

Interested in continuous attestation on the Devensa AI platform? Join the early access list

Request a briefing