Security Consulting
Maturity assessments, threat and risk assessments (STRA / SOAR) and compliance readiness against ISO 27001, SOC 2 and NIST CSF 2.0. Written for the people who have to act on it.
What the practice does.
Most security programs do not fail for lack of controls. They fail because nobody can say, in one page, where the organization stands, what the real risks are, and what to do first.
We assess against a framework you choose, in your language, and leave you with a prioritised roadmap, a risk register your leadership will read, and the evidence an auditor will accept.
Deliverables.
Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.
Maturity assessment
Current state scored against NIST CSF 2.0, ISO 27001:2022 or CIS Controls, with a target state agreed with leadership and the gap between the two sequenced into a roadmap.
Threat and risk assessment (STRA / SOAR)
Security threat and risk assessments and statements of acceptable risk for systems, projects and vendors, in the structure public sector and healthcare organizations expect.
Compliance readiness
Gap analysis, control mapping and evidence planning for ISO 27001 and SOC 2, with a realistic path to the audit date rather than a template policy pack.
Policies and standards
Policies your teams will actually follow: short, mapped to controls, with the standards and procedures that make them operational.
Board and executive reporting
A one-page position, a risk register in business terms, and the budget case for what comes next.
The four steps, applied.
The method is the same for every practice. This is what each step means here.
Framework, systems in scope, stakeholders and the decisions the assessment needs to support, agreed before interviews begin.
Document review, interviews and technical sampling. We check that controls operate, not just that they are written down.
Every rating is backed by evidence a second consultant reviews. Disagreements are resolved before you see the draft.
Scores, gaps, risk register and roadmap, with a readout for executives and a working session for the team that owns the fixes.
The situations this is built for.
You need to answer a framework question honestly
A customer, regulator or board has asked where you stand against ISO 27001, SOC 2 or NIST CSF 2.0, and the honest answer is that nobody has checked.
A system or project needs a signed STRA
Public sector and healthcare organizations need threat and risk assessments and statements of acceptable risk completed to a standard, on a schedule, by someone independent.
An audit date is set
Certification or attestation is on the calendar and the gap between policy and practice has not been measured.
Asked before most engagements.
Which frameworks do you work with?
ISO 27001:2022, SOC 2, NIST CSF 2.0, CIS Controls, and the public sector security standards used in British Columbia and across Canada. If you have a customer questionnaire or a contract schedule instead of a framework, we map to that.
Do you write policies?
Yes, and we keep them short. Policies are mapped to the controls they satisfy and paired with the standards and procedures that make them real.
Can you help us get certified?
We run readiness, remediation planning and the internal audit. We do not act as your certification body; independence matters to us and to your auditor.
How is this different from a fractional CISO?
Consulting delivers a defined assessment or document set. A fractional CISO runs the program over time. Many clients start with an assessment and continue with a fractional CISO who owns the roadmap.
Often paired with this.
Fractional CISO
A named security leader inside your leadership team, part-time: strategy, budget, board reporting and vendor decisions without the full-time hire.
Technology Rationalization
An inventory of every security tool you pay for, what each actually covers, where they overlap, and a consolidation plan with the savings priced.
Tabletop Exercises
Incident response, business continuity and disaster recovery exercises for executives and technical teams, scored against your own plans and run on RiskTrace.
Tell us what you need tested, assessed or governed.
A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.
Start on Frontier VerifyReceived. A consultant will reply within one business day.
You will get a written scope and a fixed price, not a call booking link.