Whatever forced the question, there is an engagement that answers it.
Most engagements start on one of three rungs: a scored maturity assessment, then remediation and documentation, then an ongoing virtual CISO retainer. Everything below is available on request, scoped, fixed-price, and delivered personally by Teddy Mutterperl.
Security Maturity Assessment
Scored against NIST CSF 2.0, with the gaps ranked.
Remediation & Documentation
The policies and evidence a reviewer actually asks for.
Virtual CISO Retainer
A named senior when reviews and questionnaires keep arriving.
Security Maturity Assessment
A NIST CSF 2.0 assessment of where your security program stands today, scored across the six Functions of the Framework plus supply chain and AI governance, against your size and sector, with a prioritized 12-month roadmap.
Remediation & Documentation
Audit-ready policies mapped to SOC 2 and NIST CSF, an incident response plan, and the evidence package clients and insurers ask for.
Virtual CISO Retainer
Senior security leadership on retainer: client reviews, board reporting, questionnaires, and on-call guidance.
Not every problem needs a full assessment. When something specific is on your desk, these are scoped and quoted individually, usually within a week of the first call.
Security Questionnaire Support
An enterprise client sent a questionnaire and the deal is waiting on it. We draft the responses, build the evidence index, and handle the follow-up round if the reviewer comes back with questions.
Cyber Insurance Readiness Review
Your renewal application is due and the questions are harder than last year. We identify which answers will affect your premium or coverage, close what can be closed before submission, and prepare defensible language for what cannot.
Incident Response Tabletop Exercise
A facilitated exercise that puts your leadership team through a realistic scenario built for your firm and sector. Produces a written after-action report with findings, which is also the artifact insurers and examiners ask to see.
Security Awareness & Phishing Program
A running program rather than an annual video. Baseline simulation, targeted training, quarterly cadence, and reporting your board or your insurer will accept as evidence.
AI Governance Quick Start
Your clients are beginning to ask what your AI policy is. Acceptable use provisions, a tool inventory, data handling boundaries, and the governance language enterprise procurement is starting to require.
Policy Development
Individual policies drafted to your environment and mapped to the framework you are being held to, when you need three documents rather than a full program.
SOC 2 readiness, ransomware readiness, data privacy impact assessments, board and executive briefings, and a reusable questionnaire response library. Each is quoted against your situation on the first call.