IT Security & AI Governance
Security your insurer accepts. AI your team can actually use.
Fractional IT and security leadership for organizations that need stronger controls without hiring a full internal team. We assess how your technology, people and vendors actually work together, then leave a prioritized roadmap, working policies, and guardrails for the AI already inside the building.
vCISO · SOC 2 & cyber-insurance readiness · PIPEDA / Law 25 · AI acceptable use
Why this exists
Growing organizations run on trust and defaults.
Admin rights everywhere, tools nobody vetted, and AI already in daily use. None of it feels wrong — until an insurer, an auditor, an enterprise client or an incident asks for proof.
The questionnaire you cannot answer
A cyber-insurance renewal or an enterprise client’s security questionnaire lands, and nobody can say who has access to what, or prove that backups restore.
The AI nobody approved
Staff are already pasting client data into free AI tools. There is no policy saying what is allowed, so in practice everything is.
The part-time nobody
IT is whoever is least afraid of the router. Offboarding means hoping the laptop comes back, and hoping harder that the passwords changed.
What we deliver
Controls you can show. Policies people follow.
Assessment first, always: the risks ranked by what actually matters to your organization, then a roadmap your team can realistically implement. Most engagements combine three or four of the items below.
Talk through your risksFractional IT & security leadership (vCISO): the senior owner your org is missing, in hours instead of headcount
Security risk & control assessments: how your technology, people and vendors actually work together, with risks ranked
IT policies and procedures: standards and runbooks written to be used, not filed — with named owners
Access, vendor & data reviews: who can touch what, which vendors see your data, and offboarding that closes every door
Audit & cyber-insurance readiness: gaps closed and evidence collected for questionnaires, renewals and SOC 2 preparation
Security awareness & phishing resilience: training that measurably changes behaviour, not an annual slideshow
AI governance: AI-use inventory, acceptable-use policy, approved tools, and human-review gates for sensitive work
AI risk assessments: vendor privacy reviews plus prompt-injection and data-leakage checks before sensitive data is exposed
Representative scenarios
Three ways this usually starts.
Your scope gets its own written number after a 30-minute call. These are the shapes we quote most often.
6 TO 10 HRS · $900 TO $1,500
The security baseline
A full assessment across access, devices, vendors and backups. You get the ranked risk list, a 90-day roadmap, and the two-page summary your board or insurer can read.
5 TO 9 HRS · $750 TO $1,350
The AI guardrails
Inventory of where AI is already used, an acceptable-use policy your staff will actually read, an approved-tools list, and human-review gates for sensitive work.
12 TO 20 HRS · $1,800 TO $3,000
Insurance or audit readiness
Control gaps closed in priority order, evidence collected as we go, and the questionnaire answered credibly. SOC 2 preparation is quoted the same way.
Hours billed as actuals against a written cap; you are never billed past the quote. Ongoing fractional leadership after the first engagement is a small block of hours a month, cancellable anytime.
Vendor honesty
We sell hours, not software. That changes the advice.
No reseller agreements, no commissions on security tools. When the right control is a free setting, that is the recommendation. The short version of what we tell people on calls:
| Your situation | Often enough on its own | Where we come in |
|---|---|---|
| Small team, no compliance pressure | MFA everywhere, a password manager, tested backups | One short call to verify the basics, then stop paying us |
| Insurance renewal or client questionnaire | Honest answers — aspirational ones void claims | Close the gaps that matter and evidence what is true |
| Staff already using AI daily | A one-page acceptable-use policy | The inventory, approved tools and review gates behind it |
| Audit or SOC 2 on the horizon | Starting six months early | The readiness roadmap and the remediation, in quoted hours |
Security questions
Asked before most security engagements.
We are twelve people. Do we really need this? +
Maybe not all of it, and we will say so. Attackers automate, so size is no shield, but a twelve-person org often needs six focused hours: access review, backup verification, MFA everywhere and an offboarding runbook. If the basics are already solid, the engagement ends there.
Is this a replacement for hiring a CISO or IT manager? +
It replaces the first years of one. Fractional leadership covers the decisions, policies and reviews that need senior judgment, at hours your budget survives. When your headcount and risk justify a full-time hire, we will tell you, and the documentation becomes their onboarding.
Can you just write us an AI policy? +
We can, but a policy without an inventory and a training pass is a document nobody follows. The smallest scope that actually works is the AI guardrails engagement above: find where AI is used, write the rules, brief the team, name the reviewers. It fits in a single week.
Will new controls slow the team down? +
Controls sized for an enterprise would. Ours are sized to your org: the test we use is that every control must either close a real ranked risk or satisfy a real external requirement. Anything that exists to look thorough gets cut.
What happens after the assessment? +
You own the roadmap either way. Your team can implement it, or we do the remediation at the same flat rate, most items in small quoted blocks. Thirty days of questions after any engagement are free. See pricing.
Bring the questionnaire, the audit letter, or the worry.
Thirty minutes. We will tell you which risks are real, what they cost to close, and what you can safely ignore.
$150/hr flat · scope in writing before you sign · you own everything