The Anchor Path
How we implement your information security and compliance program.
Five phases, each with a clear purpose, clear deliverables, and a clear finish line. Timelines are typical for a small-to-midsize organization pursuing its first framework; we’ll size yours in the first conversation.
01
Discover
Weeks 1–3
We learn how your business makes money, where your sensitive data lives, and what you’ve been asked to prove. Then we tell you candidly where you stand.
What we do
- Stakeholder interviews across leadership, IT, engineering, HR, and operations
- System, data flow, and vendor inventory
- Scope definition for the target framework(s)
- Control-by-control gap assessment
You receive
- Scope statement and system boundary diagram
- Gap assessment report with severity ratings
- Executive readout: where you stand and what it will take
02
Design
Weeks 3–6
We turn findings into a plan your team can execute — prioritized by risk, not by the order the framework happens to list things.
What we do
- Formal risk assessment and risk register
- Unified control set mapped to each framework
- Policy and standards library drafted with your team
- Roadmap sequenced by risk, effort, and audit date
You receive
- Risk register with owners and treatment decisions
- Approved policy set (typically 12–20 documents)
- 12-month program roadmap and RACI
03
Deploy
Months 2–6
We work alongside your people to put controls in place — configuring, documenting, and building evidence into the way work already gets done.
What we do
- Weekly working sessions with control owners
- Access reviews, change management, logging, vulnerability management, vendor risk, training, and incident response stood up
- Procedures and runbooks written with the people who run them
- Evidence captured as each control goes live
You receive
- Implemented, owned controls
- Procedure and runbook library
- Organized evidence repository
- Bi-weekly status reports against the roadmap
04
Demonstrate
Months 5–8
Before an auditor tests anything, we do. Then we stay with you through fieldwork so questions get answered quickly and accurately.
What we do
- Readiness testing with auditor-style sampling
- Mock walkthroughs with control owners
- Auditor or assessor selection and coordination
- Real-time support during fieldwork
You receive
- Readiness test results and final remediation list
- Evidence packages indexed by requirement
- Management responses and corrective action plans
05
Defend
Ongoing
A report is a snapshot. Your risk isn’t. As your vCISO we keep the program running, measured, and improving so next year’s audit is a formality.
What we do
- Continuous risk and control monitoring
- Quarterly risk register reviews
- Annual risk assessment, policy review, and program plan
- Support for new frameworks and customer requests
You receive
- Monthly control health dashboard
- Quarterly executive risk report
- Year-over-year maturity scoring
How we work with you
Principles that don’t change from client to client.
Risk first
Every control earns its place by reducing a risk you actually carry. If it doesn’t, we’ll tell you — even when a checklist says otherwise.
Your team, stronger
We build capability, not dependency. Your people own the controls; we make sure they know why each one matters and how to keep it working.
No surprises
Fixed scope, a visible roadmap, and regular status updates. You’ll know what we’re doing, what it costs, and what’s left at every point.
Ready to find out where you stand?
Most engagements start with a Discover phase. It’s the fastest way to replace uncertainty with a plan.