Cybersecurity advisory for law firms, RIAs & SaaS

Whatever forced the question, there is an engagement that answers it.

Most engagements start on one of three rungs: a scored maturity assessment, then remediation and documentation, then an ongoing virtual CISO retainer. Everything below is available on request, scoped, fixed-price, and delivered personally by Teddy Mutterperl.

Where engagements start

Security Maturity Assessment

Scored against NIST CSF 2.0, with the gaps ranked.

$3,000 – $8,000

Remediation & Documentation

The policies and evidence a reviewer actually asks for.

$3,500 – $7,500

Virtual CISO Retainer

A named senior when reviews and questionnaires keep arriving.

From $3,000/mo
Core engagements

Security Maturity Assessment

A NIST CSF 2.0 assessment of where your security program stands today, scored across the six Functions of the Framework plus supply chain and AI governance, against your size and sector, with a prioritized 12-month roadmap.

$3,000–$8,000fixed scope

Remediation & Documentation

Audit-ready policies mapped to SOC 2 and NIST CSF, an incident response plan, and the evidence package clients and insurers ask for.

$3,500–$7,500fixed scope

Virtual CISO Retainer

Senior security leadership on retainer: client reviews, board reporting, questionnaires, and on-call guidance.

From $3,000/moretainer
Focused engagements

Not every problem needs a full assessment. When something specific is on your desk, these are scoped and quoted individually, usually within a week of the first call.

Security Questionnaire Support

An enterprise client sent a questionnaire and the deal is waiting on it. We draft the responses, build the evidence index, and handle the follow-up round if the reviewer comes back with questions.

Quotedon request

Cyber Insurance Readiness Review

Your renewal application is due and the questions are harder than last year. We identify which answers will affect your premium or coverage, close what can be closed before submission, and prepare defensible language for what cannot.

Quotedon request

Incident Response Tabletop Exercise

A facilitated exercise that puts your leadership team through a realistic scenario built for your firm and sector. Produces a written after-action report with findings, which is also the artifact insurers and examiners ask to see.

Quotedon request

Security Awareness & Phishing Program

A running program rather than an annual video. Baseline simulation, targeted training, quarterly cadence, and reporting your board or your insurer will accept as evidence.

Quotedon request

AI Governance Quick Start

Your clients are beginning to ask what your AI policy is. Acceptable use provisions, a tool inventory, data handling boundaries, and the governance language enterprise procurement is starting to require.

Quotedon request

Policy Development

Individual policies drafted to your environment and mapped to the framework you are being held to, when you need three documents rather than a full program.

Quotedon request
Also scoped on request

SOC 2 readiness, ransomware readiness, data privacy impact assessments, board and executive briefings, and a reusable questionnaire response library. Each is quoted against your situation on the first call.

Book a call

Not sure which engagement fits?

Bring the questionnaire or the deadline. We'll scope the shortest credible path in a 15-minute call.

TRM Solutions is an independent advisory practice not affiliated with, endorsed by, or sponsored by any current or former employer. Employer names describe professional experience only. Engagements are conducted in a personal capacity and do not involve employer systems, data, clients, vendors, or confidential information. Client engagements are covered by NDA. Assessments and templates provide directional guidance and are not a penetration test, audit, certification, or guarantee of security.