Devensa Advisory
Get started
The services menu

Packaged advisory engagements across six governance domains.

Each offering stands alone or combines into a full program. Work is selected against the maturity roadmap rather than sold as a fixed package, and enterprise and government engagements are custom-scoped.

01

Every domain opens the same way

A Current State Assessment establishes the baseline, produces the evidence-based TruMaturity score, and generates that domain’s maturity roadmap.

02

The roadmap decides the order

Offerings are sequenced against assessed gaps rather than sold as a bundle. Most engagements start with a handful, not the whole menu.

03

Refreshed, not re-sold

The maturity roadmap is refreshed at each quarterly governance review rather than repurchased as a separate engagement.

Cybersecurity

The full security governance lifecycle.

From readiness and governance through identity, technical assessment, penetration testing, operations, and resilience. The Security Maturity Roadmap is produced within Offering 1 and refreshed at each quarterly governance review.

Grounded in
NIST CSF, CIS Controls, and applicable sector regulation
Open the Cybersecurity domain →
01

Current State Assessment

Security Readiness & Maturity

A comprehensive baseline of security posture across governance, technical controls, and operational readiness. The front-door engagement — stands alone or feeds the rest of the domain.

02

Security Governance Framework & Charter

Organizational Structure, Decision Rights & Accountability

Design and documentation of the structures, roles, decision-making processes, and accountability mechanisms needed to govern security across the organization.

03

Security Policy Framework

Acceptable Use, Access Control, Incident Response & Vendor Standards

Development of the core security policy set — the operational rulebook governing acceptable use, access control, incident response, and third-party security requirements.

04

Board & Executive Cyber Risk Reporting Program

KRI/KPI Dashboards, Reporting Cadence & Director Education

A reporting program that translates technical security findings into business-relevant metrics, with a repeatable cadence and a materiality framework.

05

Third-Party & Vendor Risk Management Program

Tiering, Assessment & Continuous Monitoring

A structured third-party risk program from vendor tiering and assessment methodology through continuous monitoring and contract standards.

06

Identity & Access Management Strategy

Architecture, Privileged Access & Governance

A target-state IAM strategy spanning architecture, privileged access management, access governance, and authentication modernization.

07

Non-Human & AI Agent Identity Governance

Service Accounts, Bots & AI Agents

Ownership, access scoping, and lifecycle control for the identities that do not belong to a person — a population that typically outnumbers human accounts.

08

Cloud Security & Multi-Cloud Risk Assessment

Posture Management, CIEM & SaaS Security

Assessment of security posture across cloud and SaaS environments, addressing the configuration, entitlement, and consistency challenges of multi-cloud and hybrid architectures.

09

Security Operations Center Strategy & Optimization

Operating Model, Tooling & Detection Coverage

Assessment and design of the security operations function — in-house, outsourced, or hybrid — covering operating model, tooling, and detection coverage.

10

Business Recovery & Continuity Program

BCP/DR Planning, Business Impact Analysis & Testing

Business continuity and disaster recovery capability, from business impact analysis through recovery plan documentation and exercise facilitation.

11

Identity Recovery & Resilience Testing

Active Directory, Entra ID & AI Agent Permission Recovery

A focused resilience program ensuring identity infrastructure itself can be recovered after compromise — a capability most organizations have never documented or tested.

12

Quantum Readiness Assessment

Cryptographic Inventory & Post-Quantum Migration Roadmap

An early-stage assessment of exposure to quantum computing risk, establishing a cryptographic inventory and a phased migration path toward post-quantum cryptography.

13

Vulnerability Assessment & Ransomware Readiness

Exploitability Triage & Ransomware Resilience

Broad-coverage identification of exploitable weaknesses through automated and manual assessment, paired with a focused evaluation of ransomware-specific exposure.

14

Penetration Testing Assessment

Network, Application & Social Engineering

A hands-on adversarial simulation against network, applications, and workforce to validate whether controls hold up under active exploitation — proving impact rather than flagging theory.

15

Security Awareness & Culture Change Management

Workforce Training, Phishing Simulation & Champion Network

Role-based training, phishing simulation, and a champion network to sustain security-conscious behaviour beyond initial training.

Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.

Engagement tiers

How the work is packaged.

Your overall TruMaturity™ score indicates the tier; the domain scores decide the order.

Foundation

Establish the governance baseline: ownership, assessment, charter, and the core policy set in the domain under the most pressure.

Operational

Integrate the governance functions so evidence, reporting, and review cadence are shared across domains instead of duplicated.

Orchestration

Enterprise governance architecture: quantified risk, cross-domain measurement, and reporting that feeds decisions rather than describing them.

Fractional executive leadership

Each domain has an executive counterpart — vCISO, vCAIO, vCRO, vCCO, vCPO, vCDO. A standing seat is available where the roadmap calls for someone accountable week to week, rather than as the default engagement model.

Scoping and pricing

Hour ranges and rates are provided in a written proposal against the scope drivers for each offering. Enterprise and government engagements are always custom-scoped.

Not sure where to start?

A working session walks your priorities across the six domains and names the first engagements worth scoping.

Get started Ask a question