Our Approach

The Anchor Path: how we implement your information security and compliance program, phase by phase.

The Anchor Path

How we implement your information security and compliance program.

Five phases, each with a clear purpose, clear deliverables, and a clear finish line. Timelines are typical for a small-to-midsize organization pursuing its first framework; we’ll size yours in the first conversation.

01

Discover

Weeks 1–3

We learn how your business makes money, where your sensitive data lives, and what you’ve been asked to prove. Then we tell you candidly where you stand.

What we do

  • Stakeholder interviews across leadership, IT, engineering, HR, and operations
  • System, data flow, and vendor inventory
  • Scope definition for the target framework(s)
  • Control-by-control gap assessment

You receive

  • Scope statement and system boundary diagram
  • Gap assessment report with severity ratings
  • Executive readout: where you stand and what it will take

02

Design

Weeks 3–6

We turn findings into a plan your team can execute — prioritized by risk, not by the order the framework happens to list things.

What we do

  • Formal risk assessment and risk register
  • Unified control set mapped to each framework
  • Policy and standards library drafted with your team
  • Roadmap sequenced by risk, effort, and audit date

You receive

  • Risk register with owners and treatment decisions
  • Approved policy set (typically 12–20 documents)
  • 12-month program roadmap and RACI

03

Deploy

Months 2–6

We work alongside your people to put controls in place — configuring, documenting, and building evidence into the way work already gets done.

What we do

  • Weekly working sessions with control owners
  • Access reviews, change management, logging, vulnerability management, vendor risk, training, and incident response stood up
  • Procedures and runbooks written with the people who run them
  • Evidence captured as each control goes live

You receive

  • Implemented, owned controls
  • Procedure and runbook library
  • Organized evidence repository
  • Bi-weekly status reports against the roadmap

04

Demonstrate

Months 5–8

Before an auditor tests anything, we do. Then we stay with you through fieldwork so questions get answered quickly and accurately.

What we do

  • Readiness testing with auditor-style sampling
  • Mock walkthroughs with control owners
  • Auditor or assessor selection and coordination
  • Real-time support during fieldwork

You receive

  • Readiness test results and final remediation list
  • Evidence packages indexed by requirement
  • Management responses and corrective action plans

05

Defend

Ongoing

A report is a snapshot. Your risk isn’t. As your vCISO we keep the program running, measured, and improving so next year’s audit is a formality.

What we do

  • Continuous risk and control monitoring
  • Quarterly risk register reviews
  • Annual risk assessment, policy review, and program plan
  • Support for new frameworks and customer requests

You receive

  • Monthly control health dashboard
  • Quarterly executive risk report
  • Year-over-year maturity scoring

See the full risk monitoring plan →

How we work with you

Principles that don’t change from client to client.

Risk first

Every control earns its place by reducing a risk you actually carry. If it doesn’t, we’ll tell you — even when a checklist says otherwise.

Your team, stronger

We build capability, not dependency. Your people own the controls; we make sure they know why each one matters and how to keep it working.

No surprises

Fixed scope, a visible roadmap, and regular status updates. You’ll know what we’re doing, what it costs, and what’s left at every point.

Ready to find out where you stand?

Most engagements start with a Discover phase. It’s the fastest way to replace uncertainty with a plan.