Services
Every engagement follows the same arc: Assess to find out where you stand, Remediate to fix what matters, and Manage to keep it that way. Most clients start with an assessment — the six service lines below can be engaged individually or as a program.
Cyber Risk Assessments
A structured assessment of your security posture against recognized frameworks — CIS Controls v8, NIST CSF 2.0, and the CIS M365 Foundations Benchmark. Not a compliance checkbox: a clear picture of your real-world risk with a prioritized path forward.
Who this is for
Leadership teams who need to know where they actually stand before deciding what to fix first.
What you get
- Prioritized findings report
- Risk ratings by severity and business impact
- Executive summary leadership can act on
- Remediation roadmap
Audit Readiness
We prepare you for audits and compliance requirements — SOC 2, HIPAA, PCI DSS, cyber insurance questionnaires, and customer security reviews. Your biggest customer just sent a 200-question security questionnaire, or your insurance renewal requires MFA and EDR attestation. We get you ready.
Who this is for
Companies facing a specific audit, questionnaire, or insurance deadline.
What you get
- Gap analysis against the target framework
- Evidence preparation
- Policy and control documentation
- Remediation tracking
Incident Response Planning
The worst time to figure out your response is during the incident. We author and tailor incident response plans and run tabletop exercises so leadership and IT are ready before something happens.
Who this is for
Organizations without a documented, tested plan for a breach or outage.
What you get
- Incident response plan with roles and responsibilities
- Escalation paths and communication templates
- Regulatory notification requirements
- Tabletop exercise with leadership and IT
Security Gap Remediation
Many consultants hand you a report and leave. Orah stays and does the work — hardening identity (MFA, conditional access), closing configuration gaps in M365 and cloud environments, fixing patching processes, and applying least-privilege access.
Who this is for
Teams with a findings report — from us or someone else — and no bandwidth to act on it.
What you get
- Identity hardening (MFA, conditional access)
- M365 / cloud configuration fixes
- Patch and network segmentation improvements
- Least-privilege access cleanup
Security Tool Implementation
Vendor-neutral selection, deployment, and configuration of security tooling — endpoint protection/EDR, email security, identity protection, privileged access management (PAM), SIEM/logging, and backup. We recommend what fits your size and budget, not what pays the biggest commission.
Who this is for
Companies that know they need tooling but not which tooling, or that have tools deployed but poorly configured.
What you get
- Vendor-neutral tool recommendations
- Deployment and configuration
- Integration with existing environment
- Documentation of setup and ownership
Managed Security Services
A fractional security team for companies too small to hire one. Ongoing monitoring, alert triage, patch and vulnerability management, user lifecycle and identity hygiene, monthly posture reporting, and quarterly reviews.
Who this is for
Organizations that have assessed and remediated and now need ongoing coverage.
What you get
- Monitoring and alert triage
- Patch and vulnerability management
- User lifecycle / identity hygiene
- Monthly posture reporting and quarterly reviews
Ready to see where you stand?
Most new clients start with a cyber risk assessment. Let's talk about what makes sense for you.