Home › Service directory

Service directory

Every service Data Fiduciaries delivers, organized by practice area. Select a service to review its scope, who it is for, and what you receive.

Security Program and Certification Readiness

Security Program Baseline and Roadmap

Establish where your security program stands and what to fix first: a baseline assessment and a risk-prioritized roadmap aligned to your stack and goals.

SOC 2 Readiness and Acceleration

Reach a clean SOC 2 Type I or Type II report faster, with readiness assessment, control design, evidence architecture, and audit management to report.

ISO 27001 and ISO 27701 Implementation and Certification Readiness

ISMS and PIMS implementation carried through certification: scope, risk assessment, statement of applicability, internal audit, and stage one and two support.

PCI DSS Readiness and Scope Reduction

Reduce PCI DSS scope and cost before you assess: cardholder data environment analysis, segmentation review, gap assessment, and QSA or SAQ preparation.

HITRUST and Sector Certification Readiness

Readiness for HITRUST CSF and the other sector certifications your market requires, with control mapping, gap assessment, and a remediation plan.

Policy, Standard, and Procedure Development

Security policies, standards, and procedures written for how your company actually operates, built to satisfy auditors and customers alike.

Control Design and Implementation

Framework requirements translated into operating controls that fit your technology stack, with evidence designed to be collected automatically.

Security Tooling Strategy and Architecture

Select and sequence the security tools your program needs across identity, endpoint, detection, and data protection, based on total cost to operate.

Compliance Automation Enablement

Get full value from your compliance automation platform: control mapping, integration coverage, evidence automation, and closure of the gaps it leaves.

Audit Management and Auditor Liaison

We manage SOC 2, PCI, ISO, and regulatory audits end to end, drawing on our network of independent audit firms or working with your existing auditor.

Internal Audit Partnership

Outsourced or co-sourced internal audit for security and technology controls, with testing and workpapers that satisfy external auditors and committees.

Customer Assurance and Trust Program

Answer customer security reviews at scale with a trust center, a maintained questionnaire library, security documentation, and a customer audit process.

Enterprise Readiness Acceleration

Remove the security and compliance obstacles blocking named enterprise deals, working from the buyer's actual requirements back to what you must show.

Cyber Risk and Security Maturity

Cybersecurity Maturity Assessment

A capability maturity assessment mapped to NIST CSF 2.0 or the CIS Controls, establishing a defensible baseline and the improvements that matter most.

Periodic Reassessment and Continuous Measurement

Annual or quarterly re-measurement against your baseline, showing progress over time and keeping leadership current on risk and regulatory change.

Cyber Risk Quantification

Express cyber risk in dollars using FAIR: loss exposure ranges for the scenarios that matter, so boards and finance can prioritize security investment.

Enterprise Risk Management Program Design

Build the risk function: taxonomy, methodology, register, appetite statement, treatment and acceptance workflows, and reporting to leadership and the board.

Control Testing and Assurance

Independent testing of control design and operating effectiveness, producing evidence that supports management assertions, filings, and audit efficiency.

Security Metrics and Reporting Program

Design the security measurement layer: key performance and risk indicators, data sources, thresholds, and reporting for operators, executives, and boards.

Board and Executive Advisory Reporting

Board and executive security reporting packages and briefings that support director oversight and disclosure obligations, prepared and delivered for you.

Security Strategy and Investment Planning

A multi-year security strategy aligned to business goals, regulatory trajectory, and budget, including build versus buy decisions and the staffing model.

Cyber Insurance Readiness and Application Support

Improve cyber insurance outcomes with accurate application responses, the control evidence underwriters require, and a coverage review against real risk.

Regulatory and Legal Compliance

Regulatory Technical Control Assessment

Technical controls assessed requirement by requirement against a named statute or regulation, producing findings counsel can rely on with regulators.

Privacy Program Development and Assessment

Build or assess your privacy program: data mapping, records of processing, DPIAs, consent, data subject request workflows, retention, and vendor oversight.

Privacy Regulatory Readiness

Gap assessment against GDPR, the Texas Data Privacy and Security Act, CCPA and CPRA, and other state privacy laws, focused on the differences that matter.

Financial Services Regulatory Assessment

Control assessments for GLBA and the FTC Safeguards Rule, NYDFS Part 500, FINRA, SEC cybersecurity rules, and SOX IT general controls.

Healthcare Regulatory Assessment

HIPAA Security Rule risk analysis and safeguard assessment, business associate review, and a remediation plan focused on the issues regulators cite most.

Government Contractor Compliance

Readiness for CMMC, NIST SP 800-171, DFARS, FedRAMP, StateRAMP, and TX-RAMP, including system security plans, POA&Ms, and authorization packages.

Regulatory Inquiry and Examination Support

Technical support under counsel for inquiries and examinations by state attorneys general, the FTC, HHS OCR, the SEC, and banking regulators.

Consulting Expert Services

Privileged technical analysis for counsel as a consulting expert: evaluating positions, supporting discovery on technical matters, and case preparation.

Expert Witness Services

Testifying expert services on security practice, control adequacy, incident causation, and industry standards, including reports, deposition, and trial.

Reasonable Security Opinions

A written assessment of whether your program meets the reasonable security standard of a statute, regulation, or contract, prepared for reliance by counsel.

Law Firm Security Program

Security for law firms: outside counsel guideline compliance, client security audits, confidentiality obligations, and matter-level data segregation.

Contract and Data Protection Agreement Review

Technical review of security exhibits, DPAs, SLAs, audit rights, and breach notice terms, confirming your controls meet what you have promised.

AI Governance

AI Governance Program Development

Design an AI governance program on the NIST AI RMF and ISO/IEC 42001: decision rights, policy, use case intake, risk assessment, oversight, and monitoring.

AI Regulatory Readiness Assessment

Gap assessment against the EU AI Act, the Colorado AI Act, the Texas Responsible AI Governance Act, and sector expectations for AI accountability.

AI System Inventory and Use Case Risk Classification

Discover and catalog the AI systems in use across your organization, whether built, bought, or embedded, and classify each use case by risk.

Shadow AI Discovery and Governance

Find unsanctioned AI use, measure the data exposure it creates, and replace it with sanctioned tools, acceptable use standards, and technical controls.

AI Vendor and Model Assessment

Evaluate AI providers and models for data handling, training provenance, security, reliability, contract protections, and regulatory obligations.

AI Product Security and Assurance

Assess the AI features in your product for prompt injection, data leakage, output handling, access control, tenant isolation, and evaluation practice.

AI Risk Assessment and Ongoing Monitoring

Recurring assessment of deployed AI systems for fairness, reliability, transparency, security, and regulatory fit, with the documentation regulators expect.

Product and Application Security

Product Security Assessment

A comprehensive security assessment of your SaaS product or in-house application, from development practice and architecture to fraud and resilience.

Secure Development Lifecycle Assessment

Measure development practice against OWASP SAMM and embed security into the engineering workflow rather than bolting it on at release.

Application Architecture Review and Threat Modeling

Structured review of application architecture, trust boundaries, and data flows, with formal threat models and a repeatable practice for your teams.

Secure Code Review

Expert review of source code where scanners fall short: authorization logic, authentication flows, cryptography, business logic, and untrusted input.

Application Security Testing Program

Design and tune SAST, DAST, IAST, and SCA in your pipeline, with triage workflows and remediation service levels engineering teams can sustain.

Software Supply Chain Security

Assess dependency and build pipeline risk: open source components, SBOM, artifact signing and provenance, and CI/CD pipeline security.

Identity, Authentication, and Authorization Review

Review MFA, sessions, SSO, tokens, account recovery, and object-level authorization, where the most exploited application weaknesses are found.

Abuse and Fraud Risk Assessment

Assess account takeover, bot abuse, card testing, refund, promotion, and trial abuse, with an abuse case catalog mapped to preventive and detective controls.

Credential Attack Defense Program

Stop credential stuffing and account takeover with layered defenses: breached password screening, adaptive login, bot mitigation, and recovery hardening.

Availability and Denial of Service Resilience

Assess resistance to volumetric and application-layer DDoS across edge, CDN, WAF, rate limiting, autoscaling, and your contractual recovery objectives.

Multi-Tenant Isolation and Application Data Protection

Verify tenant separation, encryption and key management, data residency, logging hygiene, and retention as actually implemented in your application.

API Security Assessment

Inventory and test your API surface, including undocumented endpoints, authorization enforcement, rate limits, data exposure, and partner integrations.

Cloud and Infrastructure Security Assessment

Assess AWS, Azure, or Google Cloud and supporting infrastructure against CIS Benchmarks: IAM, network, workloads, IaC, secrets, logging, and drift.

Penetration Testing

Network, web, mobile, API, cloud, wireless, and social engineering penetration testing, scoped to your risk profile and certification evidence needs.

Vulnerability Assessment and Management Program

Assess your vulnerability position and build a program with risk-based prioritization, remediation service levels, exception governance, and metrics.

Adversary Simulation and Red Team

Objective-based adversary simulation that tests detection and response rather than control inventory, with optional purple team collaboration.

Responsible Disclosure and Bug Bounty Program Design

Establish a responsible disclosure or bug bounty program with policy, safe harbor, scope, triage workflow, reward criteria, and remediation handoff.

Developer Security Training and Security Champions

Secure coding training built on the vulnerabilities in your own codebase, plus a security champions program that spreads capability across engineering.

Financial Crime and Transaction Risk Assessment

For fintech and financial services: assess AML, KYC, sanctions screening, transaction monitoring, and fraud detection as working technical controls.

Third-Party Risk and Transaction Advisory

Third-Party Risk Assessment

Vendor and service provider security assessments scaled to criticality, covering controls, attestations, contracts, fourth parties, and monitoring.

Third-Party Risk Management Program Design

Build a TPRM program: vendor inventory, tiering, assessment methodology, onboarding and renewal workflow, contract requirements, and monitoring.

Vendor Diligence Operations

Ongoing vendor security reviews performed on your behalf, absorbing assessment volume while keeping a consistent standard of evaluation.

Cyber Due Diligence for Acquisitions

Buy-side cyber due diligence on security posture, compliance, hidden compromise, product security, and remediation cost, framed for valuation.

Sell-Side Readiness and Vendor Due Diligence

Prepare for buyer security diligence: find and fix the issues that reduce valuation or delay close, and assemble a diligence package that moves fast.

Post-Close Integration Assessment

Plan and manage security integration after close: identity consolidation, network connection risk, control harmonization, and compliance scope.

Portfolio Company Security Assessment

Standardized cybersecurity assessments across a private equity or venture portfolio, with comparable scoring and portfolio-wide risk visibility.

Incident Response and Crisis Management

Incident Response Retainer

Contract before the crisis: a committed response time, prepaid response hours, and a responder who already knows your environment.

Incident Command and Executive Advisory

Incident command and decision support for executives and boards, coordinating counsel, insurers, forensics, and technical teams under pressure.

Digital Forensics and Investigation

Forensic investigation that establishes what happened: defensible evidence preservation, timeline, initial access, lateral movement, and exfiltration.

Ransomware and Extortion Response

End-to-end ransomware and extortion response: threat actor assessment, negotiation, sanctions analysis, settlement facilitation if chosen, and recovery.

Breach Notification Analysis

Determine breach notification obligations across states and regimes, identify affected parties, and meet statutory deadlines in coordination with counsel.

Post-Incident Assessment and Root Cause Analysis

Independent post-incident review of root cause, control failures, and response performance, with findings suitable for boards, regulators, and insurers.

Post-Incident Remediation Program Management

Direct remediation after an incident, from containment and hardening to root cause fixes, with the evidence trail regulators and customers expect.

Incident Response Plan and Playbook Development

An incident response plan and scenario playbooks for ransomware, business email compromise, exfiltration, insider events, and third-party compromise.

Tabletop Exercises

Technical, executive, and board tabletop exercises built on realistic scenarios from your environment, exposing decision gaps before an incident does.

Ransomware Readiness Assessment

Test your resistance to and recoverability from ransomware: access vectors, privileged access, backup isolation, recovery time, and decision framework.

Business Continuity and Disaster Recovery Assessment

Evaluate continuity and recovery capability, including business impact analysis, tested recovery objectives, dependency mapping, and exercise programs.

Threat Intelligence and Exposure Monitoring

Monitor leaked credentials, extortion site mentions, brand impersonation, and attack surface changes, with threat briefings relevant to your sector.

vCISO and Fractional Leadership

Virtual Chief Information Security Officer

Fractional CISO leadership scaled to your needs, from strategic advisory to hands-on program ownership, board representation, and customer assurance.

Interim Chief Information Security Officer

Full-time interim CISO coverage during a leadership transition, maintaining program continuity, regulatory standing, and team stability through handover.

Fractional Compliance Officer

Ongoing ownership of your compliance function: audit calendar, control monitoring, evidence operations, regulatory change, and reporting between audits.

Fractional Privacy Officer and Data Protection Officer

A named privacy officer or data protection officer where law or contract requires one, covering regulator liaison, assessment oversight, and governance.

Board and Director Advisory

Help boards and audit committees oversee cyber risk: director education, evaluation of management reporting, disclosure briefings, and independent views.

Security Program Management

Dedicated program management for certification efforts, security initiatives, and remediation, so your roadmap is executed and not just published.

Security Organization Design and Talent Advisory

Design the security function: structure, roles, seniority mix, build versus outsource decisions, hiring support, and mentoring for leaders in place.

Human Risk and Security Awareness

Security Awareness Program Development

Awareness programs built on the behaviors that reduce incidents, with role-based content and measurement of real behavior rather than completion rates.

Phishing and Social Engineering Simulation

Phishing, voice, and text simulation calibrated to real attacker tradecraft, with trend reporting and follow-up that educates rather than punishes.

Executive and High-Risk Individual Protection

Reduce the exposure of executives, finance staff, and administrators through footprint reduction, account security, payment controls, and impersonation defense.

Start with a confidential conversation

Every engagement is scoped individually and begins with a conversation about where your program stands and where it needs to be. Work is conducted under a nondisclosure agreement and a master services agreement.

Consultations are available Monday to Friday, 9:00am to 3:00pm Central.