Cleared & federal contractor
A program that exists only on paper
Situation
A 40-person federal IT firm, scaling fast, holds a facility clearance. Its National Industrial Security Program Operating Manual (NISPOM) program was written once and shelved. The Facility Security Officer (FSO) is buried, cleared hires arrive monthly, and a Defense Counterintelligence and Security Agency (DCSA) review is coming.
Assessment
Scores "on paper." No escalation path, no manager training, onboarding silent on insider risk, no record of how past concerns were handled.
Workshop
Half a day with the FSO, Information System Security Manager (ISSM), program managers, and team leads — the precursor framework plus a one-page escalation playbook a concern can actually travel through.
Retainer
Mock DCSA reviews, insider-threat training built into onboarding, quarterly tuning as the firm grows.
Outcome
A program that runs in practice and proves itself on demand — and leadership that walks into the review confident.
Healthcare practice
A near-miss that never got documented
Situation
A 22-provider medical group has grown through two acquisitions. Front-desk and clinical staff share broad EHR access for convenience. A staff member's record-snooping incident surfaces informally — no one is sure who was supposed to handle it.
Assessment
No workforce security policy under the HIPAA Security Rule, no offboarding checklist, no record of how the snooping incident was reviewed or resolved.
Workshop
Half a day with the practice manager, front-desk lead, and clinical staff — the precursor framework adapted to EHR access, plus a one-page escalation plan tied to HIPAA's administrative safeguards.
Retainer
Quarterly access reviews, refreshed onboarding and offboarding checklists, mock-audit prep ahead of any OCR inquiry.
Outcome
A documented, defensible process — and a practice manager who finally knows who owns this.
Law firm
An associate leaves, and nobody's sure what left with them
Situation
A 30-attorney litigation firm has an associate resign abruptly to join opposing counsel's firm. Partners want to know what they had access to and whether anything walked out the door — but there's no offboarding process to check against.
Assessment
Document management system permissions are years out of date. No matter-level access review has ever been run. Model Rule 1.6 obligations exist on paper, not in practice.
Workshop
A session for partners and staff — the precursor framework adapted to matter access and departures, plus a one-page escalation path everyone actually knows before the next departure.
Retainer
Standing offboarding checklist, quarterly DMS access reviews, incident-response readiness the managing partner can point to.
Outcome
A real answer for the partnership — and a process that catches the next departure before it's a crisis.
Financial advisor / RIA
The exam is coming, and the policy has never been tested
Situation
A 15-person RIA has a written cybersecurity policy that's never been exercised. The Chief Compliance Officer — who also runs operations and half the client relationships — just learned the SEC's 2026 exam priorities name employee access controls directly.
Assessment
Access into the CRM and custodial platforms is broader than anyone tracked. No documented review of who can see which client accounts, and no incident-response program under the amended Regulation S-P.
Workshop
A session for advisors, ops, and compliance — the precursor framework adapted to client access and departing advisors, plus a one-page escalation path the CCO can point to under exam.
Retainer
Ongoing access reviews, a tested incident-response program, and exam-readiness prep ahead of the next cycle.
Outcome
A policy that's actually been exercised — and a CCO who isn't guessing what examiners will ask.