Packaged advisory engagements across six governance domains.
Each offering stands alone or combines into a full program. Work is selected against the maturity roadmap rather than sold as a fixed package, and enterprise and government engagements are custom-scoped.
Every domain opens the same way
A Current State Assessment establishes the baseline, produces the evidence-based TruMaturity score, and generates that domain’s maturity roadmap.
The roadmap decides the order
Offerings are sequenced against assessed gaps rather than sold as a bundle. Most engagements start with a handful, not the whole menu.
Refreshed, not re-sold
The maturity roadmap is refreshed at each quarterly governance review rather than repurchased as a separate engagement.
The full security governance lifecycle.
From readiness and governance through identity, technical assessment, penetration testing, operations, and resilience. The Security Maturity Roadmap is produced within Offering 1 and refreshed at each quarterly governance review.
Current State Assessment
A comprehensive baseline of security posture across governance, technical controls, and operational readiness. The front-door engagement — stands alone or feeds the rest of the domain.
Security Governance Framework & Charter
Design and documentation of the structures, roles, decision-making processes, and accountability mechanisms needed to govern security across the organization.
Security Policy Framework
Development of the core security policy set — the operational rulebook governing acceptable use, access control, incident response, and third-party security requirements.
Board & Executive Cyber Risk Reporting Program
A reporting program that translates technical security findings into business-relevant metrics, with a repeatable cadence and a materiality framework.
Third-Party & Vendor Risk Management Program
A structured third-party risk program from vendor tiering and assessment methodology through continuous monitoring and contract standards.
Identity & Access Management Strategy
A target-state IAM strategy spanning architecture, privileged access management, access governance, and authentication modernization.
Non-Human & AI Agent Identity Governance
Ownership, access scoping, and lifecycle control for the identities that do not belong to a person — a population that typically outnumbers human accounts.
Cloud Security & Multi-Cloud Risk Assessment
Assessment of security posture across cloud and SaaS environments, addressing the configuration, entitlement, and consistency challenges of multi-cloud and hybrid architectures.
Security Operations Center Strategy & Optimization
Assessment and design of the security operations function — in-house, outsourced, or hybrid — covering operating model, tooling, and detection coverage.
Business Recovery & Continuity Program
Business continuity and disaster recovery capability, from business impact analysis through recovery plan documentation and exercise facilitation.
Identity Recovery & Resilience Testing
A focused resilience program ensuring identity infrastructure itself can be recovered after compromise — a capability most organizations have never documented or tested.
Quantum Readiness Assessment
An early-stage assessment of exposure to quantum computing risk, establishing a cryptographic inventory and a phased migration path toward post-quantum cryptography.
Vulnerability Assessment & Ransomware Readiness
Broad-coverage identification of exploitable weaknesses through automated and manual assessment, paired with a focused evaluation of ransomware-specific exposure.
Penetration Testing Assessment
A hands-on adversarial simulation against network, applications, and workforce to validate whether controls hold up under active exploitation — proving impact rather than flagging theory.
Security Awareness & Culture Change Management
Role-based training, phishing simulation, and a champion network to sustain security-conscious behaviour beyond initial training.
Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.
The full AI adoption lifecycle.
From readiness and governance through agentic risk, cost governance, use case analysis, and workforce strategy. The AI Maturity Roadmap is produced within Offering 1 and refreshed at each quarterly governance review.
Current State Assessment
A baseline assessment of readiness for AI adoption across technology, data, cybersecurity, governance, workforce, and procurement — including a shadow AI review. The front-door engagement.
AI Governance Framework & Charter
Design of the structures, roles, and approval processes needed to govern AI responsibly before deployment begins, including steering committee and advisory council design.
AI Policy Framework
Development of the Enterprise AI Policy — the operational rulebook covering acceptable and prohibited use, data handling, human-in-the-loop requirements, transparency, and vendor standards.
AI Co-Pilot Security Risk Assessment
A targeted assessment of what Co-Pilot can see, whether M365 security controls are hardened, and whether sensitive data is exposed — with prioritized hardening recommendations.
Agentic AI Risk Assessment & Remediation Roadmap
Assessment of what deployed AI agents are authorized to decide and do autonomously, where oversight controls are missing, and what happens when an agent acts on incorrect information.
AI FinOps
Cost governance for AI and GenAI spend — attribution, unit economics, forecasting, and optimization adapted to token pricing, GPU capacity, and training-versus-inference cost structures.
AI Use Case Assessment, Analysis & Prioritization
Structured discovery and evaluation to identify where AI creates genuine operational value, with ROI analysis and business cases for the top pilot candidates.
AI Organizational Impact Assessment
How AI adoption changes the operating model — which roles and workflows are augmented, displaced, or created, and how service delivery changes as a result.
AI Workforce Strategy & Change Management
A workforce readiness assessment and change management plan covering role-based proficiency targets, training strategy by tier, and an AI champion network.
AI POC Development and Execution
Hands-on build, deployment, and execution of approved pilots through to measured results and a go/no-go recommendation.
Governed Intelligence Platform Advisory
For software platform and product teams building AI-assisted features into their own products: context architecture, model routing, evaluation, guardrails, and audit-ready telemetry.
Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.
Grounded in the COSO ERM Framework.
From readiness and governance through quantitative risk modeling, operational resilience, third-party risk, emerging risk, crisis management, and insurance strategy. The Risk Maturity Roadmap is produced within Offering 1.
Current State Assessment
A baseline against the COSO ERM Framework’s five components — governance and culture, strategy and objective-setting, performance, review and revision, and information and communication.
Risk Governance Framework & Charter
Design of the governance structures, reporting lines, and operating model that embed risk management into board oversight and daily decision-making.
Risk Policy Framework
Risk appetite and tolerance statements by category, escalation thresholds, and the risk acceptance and exception process.
Risk Identification & Register Program
Building or refreshing the enterprise risk register through structured workshops tied explicitly to strategic objectives.
Quantitative Risk Assessment & Modeling
Quantitative modeling of prioritized risks, translating register entries into dollar-denominated exposure ranges that support risk-informed decisions.
Business Impact Analysis & Operational Resilience Assessment
An enterprise-level impact analysis covering people, facilities, suppliers, and processes — complementing rather than duplicating technical BC/DR work.
Third-Party & Enterprise Vendor Risk Program
An enterprise view of financial, operational, and concentration risk from suppliers and partners — the risk counterpart to technical vendor security assessment.
Emerging Risk & Horizon Scanning Program
A recurring process for identifying and assessing emerging technology, geopolitical, regulatory, climate, and workforce risks before they become register entries.
Crisis Management & Scenario Planning
Crisis management capability and scenario-based stress testing of the risk profile against severe-but-plausible events.
Insurance & Risk Transfer Strategy
A review of insurance program adequacy relative to quantified exposure, with recommendations for risk transfer and financing strategy.
Risk Culture & Workforce Risk Literacy Program
Training and culture work that builds risk-aware decision-making among department leads and reinforces accountability for risk ownership.
Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.
Grounded in the DOJ ECCP.
Covering readiness, governance, risk assessment, regulatory gap analysis, training, whistleblower protection, and third-party and M&A due diligence. The Compliance Maturity Roadmap is produced within Offering 1.
Current State Assessment
A baseline against the ECCP’s three fundamental questions — is the program well designed, is it adequately resourced and empowered, and does it work in practice.
Compliance Governance Framework & Charter
Design of the compliance function’s structure, reporting lines, independence, resourcing adequacy, and audit committee reporting cadence.
Compliance Policy & Procedure Framework
The code of conduct and a policy library mapped to applicable regulatory obligations, with a defined lifecycle and attestation process.
Compliance Risk Assessment Program
Design and execution of the compliance risk assessment methodology, incorporating the DOJ’s current emphasis on emerging technology and AI risk.
Regulatory Gap Analysis & Controls Testing
Framework-by-framework gap analysis with sample-based controls testing to validate that documented controls operate effectively in practice.
Training & Communications Program
A training program that is accessible and role-appropriate rather than a one-size-fits-all module, with effectiveness measurement beyond completion tracking.
Confidential Reporting, Investigations & Whistleblower Program
Design of the confidential reporting mechanism, investigation standards, and anti-retaliation controls, reflecting heightened regulatory focus on reporting culture.
Third-Party Compliance Risk & Due Diligence Program
Third-party risk tiering, due diligence standards by tier, sanctions screening, contract clause standards, and ongoing monitoring.
M&A / Post-Acquisition Compliance Integration
Compliance due diligence and post-acquisition integration process, including the post-acquisition audit that surfaces inherited issues in time to act.
Compliance Data & Technology Resourcing Assessment
Whether compliance has adequate access to relevant data, and whether the analytics used for monitoring are validated for accuracy — a growing area of regulatory scrutiny.
Compliance Culture, Incentives & Discipline Program
Review and design of incentive structures and disciplinary consistency, so compliant behaviour is rewarded and misconduct is addressed regardless of seniority.
Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.
Grounded in the NIST Privacy Framework.
Covering readiness, governance, data mapping, impact assessment, rights fulfillment, cross-border transfer, incident response, and AI privacy risk. The Privacy Maturity Roadmap is produced within Offering 1.
Current State Assessment
A baseline against the NIST Privacy Framework’s five functions — Identify-P, Govern-P, Control-P, Communicate-P, Protect-P — mapped to applicable regulatory obligations.
Privacy Governance Framework & Charter
Design of the structures, roles, and accountability mechanisms needed to govern privacy responsibly.
Privacy Policy Framework
The core privacy policy set — public-facing notices, internal handling standards, consent mechanisms, and vendor and processor contractual requirements.
Data Mapping & Records of Processing Activities
Technical mapping of personal data flows across systems, vendors, and processes, producing the ROPA required under GDPR and equivalent documentation elsewhere.
Privacy Impact & DPIA Program
A repeatable PIA/DPIA methodology and execution of initial assessments for identified high-risk processing activities.
Data Subject Rights & DSAR Program
The end-to-end process for receiving, verifying, and fulfilling access, deletion, correction, and opt-out requests across applicable regulations.
Cross-Border Data Transfer & Processor Risk Program
Assessment and governance of personal data transfers across borders and through processors, ensuring lawful transfer mechanisms and contractual safeguards.
Privacy Incident Response & Breach Notification Program
Privacy incident response capability including breach detection, assessment, and regulatory and individual notification procedures.
AI & Automated Decision-Making Privacy Risk Assessment
Privacy risk arising from AI systems and automated decision-making — profiling disclosure obligations and opt-out rights — coordinated with the AI Governance domain.
Privacy Organizational Impact Assessment
How embedding privacy-by-design changes existing workflows across product, engineering, and business functions.
Privacy Workforce Training & Culture Change Management
Training and change management so the workforce understands privacy obligations and is equipped to act on them.
Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.
Grounded in the DAMA-DMBOK framework.
Covering readiness, governance, architecture, master data, quality, metadata, integration, analytics enablement, and data ethics. The Data Maturity Roadmap is produced within Offering 1.
Current State Assessment
A baseline across the DAMA-DMBOK’s eleven knowledge areas, anchored on Data Governance at the centre of the DAMA Wheel.
Data Governance Framework & Charter
Design of the Data Governance Council, the steward and owner network, and the decision-making structure that anchors every other knowledge area.
Data Policy Framework
The core data policy set — classification scheme, retention and lifecycle policy, access standards, and quality standards.
Data Architecture & Modeling Assessment
A technical assessment of data architecture and modeling practices — reference architecture, data models, and alignment to business strategy.
Master & Reference Data Management Program
An MDM program establishing golden-record standards for core business entities such as customer, product, vendor, and employee.
Data Quality Program
Design and initial execution of a data quality program — measurement, monitoring, and remediation prioritization across priority data domains.
Metadata Management & Data Catalog Program
A metadata management program and data catalog approach, providing the searchable inventory that underpins governance, quality, and AI-readiness work.
Data Integration & Interoperability Assessment
How data moves between systems — integration architecture, API standards, and the interoperability gaps that affect quality and availability.
Data Warehousing & Analytics Enablement
Assessment and design recommendations for the warehousing and analytics platform, so governed data supports reliable self-service reporting.
Data Stewardship & Workforce Literacy Program
Training and change management that builds data literacy across the workforce and stands up the steward network.
Data Ethics & AI-Readiness Program
Assessment of data ethics practices and preparation of governed data pipelines to support AI use cases responsibly, coordinated with the AI Governance domain.
Where offerings are purchased in combination, overlapping scope — data mapping, regulatory review, stakeholder interviews — is identified and deducted so the same work is not scoped twice.
How the work is packaged.
Your overall TruMaturity™ score indicates the tier; the domain scores decide the order.
Establish the governance baseline: ownership, assessment, charter, and the core policy set in the domain under the most pressure.
Integrate the governance functions so evidence, reporting, and review cadence are shared across domains instead of duplicated.
Enterprise governance architecture: quantified risk, cross-domain measurement, and reporting that feeds decisions rather than describing them.
Each domain has an executive counterpart — vCISO, vCAIO, vCRO, vCCO, vCPO, vCDO. A standing seat is available where the roadmap calls for someone accountable week to week, rather than as the default engagement model.
Hour ranges and rates are provided in a written proposal against the scope drivers for each offering. Enterprise and government engagements are always custom-scoped.
Not sure where to start?
A working session walks your priorities across the six domains and names the first engagements worth scoping.