IT Security & AI Governance

Security your insurer accepts. AI your team can actually use.

Fractional IT and security leadership for organizations that need stronger controls without hiring a full internal team. We assess how your technology, people and vendors actually work together, then leave a prioritized roadmap, working policies, and guardrails for the AI already inside the building.

vCISO · SOC 2 & cyber-insurance readiness · PIPEDA / Law 25 · AI acceptable use

Shadow AI Shared logins Unvetted vendors Assessed & governed policies training controls Audit-ready evidence on file
Every tool, login and AI use accounted for: assessed once, governed by policies people actually follow, and ready to show an insurer or auditor.

Why this exists

Growing organizations run on trust and defaults.

Admin rights everywhere, tools nobody vetted, and AI already in daily use. None of it feels wrong — until an insurer, an auditor, an enterprise client or an incident asks for proof.

The questionnaire you cannot answer

A cyber-insurance renewal or an enterprise client’s security questionnaire lands, and nobody can say who has access to what, or prove that backups restore.

The AI nobody approved

Staff are already pasting client data into free AI tools. There is no policy saying what is allowed, so in practice everything is.

The part-time nobody

IT is whoever is least afraid of the router. Offboarding means hoping the laptop comes back, and hoping harder that the passwords changed.

What we deliver

Controls you can show. Policies people follow.

Assessment first, always: the risks ranked by what actually matters to your organization, then a roadmap your team can realistically implement. Most engagements combine three or four of the items below.

Talk through your risks

Fractional IT & security leadership (vCISO): the senior owner your org is missing, in hours instead of headcount

Security risk & control assessments: how your technology, people and vendors actually work together, with risks ranked

IT policies and procedures: standards and runbooks written to be used, not filed — with named owners

Access, vendor & data reviews: who can touch what, which vendors see your data, and offboarding that closes every door

Audit & cyber-insurance readiness: gaps closed and evidence collected for questionnaires, renewals and SOC 2 preparation

Security awareness & phishing resilience: training that measurably changes behaviour, not an annual slideshow

AI governance: AI-use inventory, acceptable-use policy, approved tools, and human-review gates for sensitive work

AI risk assessments: vendor privacy reviews plus prompt-injection and data-leakage checks before sensitive data is exposed

The state we leave behind: controls with owners, an access review that catches what offboarding missed, and AI use split into approved, blocked and under review.

Representative scenarios

Three ways this usually starts.

Your scope gets its own written number after a 30-minute call. These are the shapes we quote most often.

6 TO 10 HRS · $900 TO $1,500

The security baseline

A full assessment across access, devices, vendors and backups. You get the ranked risk list, a 90-day roadmap, and the two-page summary your board or insurer can read.

5 TO 9 HRS · $750 TO $1,350

The AI guardrails

Inventory of where AI is already used, an acceptable-use policy your staff will actually read, an approved-tools list, and human-review gates for sensitive work.

12 TO 20 HRS · $1,800 TO $3,000

Insurance or audit readiness

Control gaps closed in priority order, evidence collected as we go, and the questionnaire answered credibly. SOC 2 preparation is quoted the same way.

Hours billed as actuals against a written cap; you are never billed past the quote. Ongoing fractional leadership after the first engagement is a small block of hours a month, cancellable anytime.

How engagements run: scope in writing, shipped in weeks

Vendor honesty

We sell hours, not software. That changes the advice.

No reseller agreements, no commissions on security tools. When the right control is a free setting, that is the recommendation. The short version of what we tell people on calls:

Your situationOften enough on its ownWhere we come in
Small team, no compliance pressureMFA everywhere, a password manager, tested backupsOne short call to verify the basics, then stop paying us
Insurance renewal or client questionnaireHonest answers — aspirational ones void claimsClose the gaps that matter and evidence what is true
Staff already using AI dailyA one-page acceptable-use policyThe inventory, approved tools and review gates behind it
Audit or SOC 2 on the horizonStarting six months earlyThe readiness roadmap and the remediation, in quoted hours
Related reading: what we let AI do with customer email, and what we do not

Security questions

Asked before most security engagements.

We are twelve people. Do we really need this? +

Maybe not all of it, and we will say so. Attackers automate, so size is no shield, but a twelve-person org often needs six focused hours: access review, backup verification, MFA everywhere and an offboarding runbook. If the basics are already solid, the engagement ends there.

Is this a replacement for hiring a CISO or IT manager? +

It replaces the first years of one. Fractional leadership covers the decisions, policies and reviews that need senior judgment, at hours your budget survives. When your headcount and risk justify a full-time hire, we will tell you, and the documentation becomes their onboarding.

Can you just write us an AI policy? +

We can, but a policy without an inventory and a training pass is a document nobody follows. The smallest scope that actually works is the AI guardrails engagement above: find where AI is used, write the rules, brief the team, name the reviewers. It fits in a single week.

Will new controls slow the team down? +

Controls sized for an enterprise would. Ours are sized to your org: the test we use is that every control must either close a real ranked risk or satisfy a real external requirement. Anything that exists to look thorough gets cut.

What happens after the assessment? +

You own the roadmap either way. Your team can implement it, or we do the remediation at the same flat rate, most items in small quoted blocks. Thirty days of questions after any engagement are free. See pricing.

Bring the questionnaire, the audit letter, or the worry.

Thirty minutes. We will tell you which risks are real, what they cost to close, and what you can safely ignore.

$150/hr flat · scope in writing before you sign · you own everything