🛡️ Cybersecurity

Cybersecurity

Security governance and assurance work — new artifacts in development.

11 artifacts

Cybersecurity artifacts

Risk & Assurance3

Assess cyber risk, quantify impact, and audit controls against the standards.

Interactive Tool Interactive

Cyber Risk Assessment

A structured, standards-aligned method for identifying assets, threats, and vulnerabilities, then rating each risk by likelihood and impact. Risk levels calculate automatically using the NIST SP 800-30 model.

Cyber RiskNIST SP 800-30Assessment
Interactive Tool Interactive

Cybersecurity Audit Checklist

A complete controls audit covering all 18 CIS Critical Security Controls v8.1 — 153 safeguards — cross-mapped to NIST CSF 2.0 and ISO/IEC 27001:2022. Score implementation and filter by Implementation Group to scope to your maturity.

CIS ControlsNIST CSFISO 27001Audit
Interactive Tool 🔒 By request

Cyber Impact Assessment (BIA)

$3,500 USD · includes walkthrough

Quantify the business consequences of a cyber incident across five impact dimensions, set recovery objectives (RTO/RPO/MTD), and tier each process by criticality. Ratings follow the worst-case rule and feed directly into continuity and recovery planning.

Business ImpactBIARecovery Objectives

Architecture & Infrastructure3

Design and harden the estate — zero trust, networks, and operational technology.

Interactive Tool Interactive

Security Architecture & Zero Trust

Assess and mature a zero-trust architecture across the five CISA pillars — identity, devices, networks, applications and workloads, and data — plus cross-cutting capabilities. Aligned to NIST SP 800-207 and the CISA Zero Trust Maturity Model 2.0.

Zero TrustNIST SP 800-207CISAArchitecture
Interactive Tool 🔒 By request

Network Security Hardening — Templates & How-Tos

$3,500 USD · includes walkthrough

Practical, standards-aligned hardening across eight domains — architecture, firewalls, remote access, wireless, device hardening, monitoring, and access control. Each domain pairs best-practice guidance with a step-by-step how-to and a trackable checklist.

Network SecurityHardeningCISACIS
Interactive Tool 🔒 By request

OT / ICS / IoT Security

$3,500 USD · includes walkthrough

Secure operational technology, industrial control systems, and IoT — segmentation and the Purdue model, IEC 62443 zones and conduits, secure remote access, OT-aware patching and monitoring, safety systems, and IoT device hardening.

OT SecurityICSIEC 62443IoT

Cloud & Application Security2

Secure what you build and what you run in the cloud.

Interactive Tool 🔒 By request

Application Security & Secure SDLC

$3,500 USD · includes walkthrough

Embed security across the software lifecycle — requirements, threat modeling, secure implementation, testing, release, CI/CD, and AI/LLM applications. Aligned to OWASP ASVS 5.0, the OWASP Top 10:2025, and SAMM.

AppSecOWASPSecure SDLCLLM Security
Interactive Tool 🔒 By request

Cloud Security Assessment

$3,500 USD · includes walkthrough

Assess and harden cloud posture across nine control areas — shared responsibility, identity, data, network, logging, workloads, secrets, and cloud incident response. Aligned to CSA CCM v4.1, CIS Foundations Benchmarks, and provider best practice.

Cloud SecurityCSA CCMCIS Benchmarks

Threat & Cryptography2

Understand the adversary and protect data in transit and at rest.

Interactive Tool 🔒 By request

Cryptography & Key Management

$3,500 USD · includes walkthrough

Govern cryptography end to end — approved algorithms, the key-management lifecycle, PKI and certificate management, transport security, post-quantum readiness, and crypto governance. Aligned to NIST SP 800-57, FIPS 186-5, and the 2024 post-quantum standards.

CryptographyKey ManagementPKIPost-Quantum
Interactive Tool 🔒 By request

Threat Intelligence & Threat Modeling

$3,500 USD · includes walkthrough

Build a threat-informed defense — the intelligence lifecycle and tiers, MITRE ATT&CK, Kill Chain and Diamond models, STIX/TAXII sharing, structured threat modeling with STRIDE and PASTA, and operationalizing intelligence into detection and hunting.

Threat IntelligenceMITRE ATT&CKThreat Modeling

Resilience1

Keep operating through disruption, and recover when it happens.

Interactive Tool 🔒 By request

Business Continuity & Disaster Recovery

$3,500 USD · includes walkthrough

Build organizational resilience — a continuity program, business impact analysis, recovery strategy and backups, continuity and DR plans, testing and exercises, and plan maintenance. Aligned to ISO 22301 and NIST SP 800-34.

Business ContinuityDisaster RecoveryISO 22301