Independent technical practice

Executive Cyber Risk Advisory

A fixed-fee, independent account of cyber risk for the people responsible for it, not a report written only for the IT department.

Boardroom table prepared for a technical briefing.

Who we serve

  • Boards
  • CEOs
  • General Counsel
  • Banks
  • Law Firms
  • Healthcare

Scope

What the assessment delivers

  • Board Presentation

    A single session that gives directors a defensible view of the organization's cyber risk.

  • Executive Summary

    Plain-language findings a non-technical executive can act on and minute.

  • Risk Ranking

    Risks ordered by business consequence and likelihood, with the cost of doing nothing stated.

  • Insurance Gap Review

    Where the cyber policy would and would not respond, checked against how the business actually operates.

  • Vendor Risk Review

    The third parties whose failure becomes your incident, and what the contracts say about it.

  • Incident Readiness Review

    Whether the plan, the contacts and the authority to act would survive a real event.

Fixed fee, fixed scope, one presentation to the board at the end of it.

Methodology

How the engagement runs

  1. Frame

    Agree with the board what decisions this assessment has to support.

  2. Review

    Governance, program documentation, insurance, vendors and incident materials.

  3. Interview

    Executives and operators, separately, because the two accounts often differ.

  4. Rank

    Risks scored by business consequence, with remediation sequenced by value.

  5. Brief

    A board session, delivered by the person who did the work.

What counsel receives

A file another examiner could pick up.

Risk statements connect to interviews, records and technical checks, then identify the decision, owner and verification step that follows.

The briefing distinguishes measured exposure from management judgment so a board can see which assumptions it is accepting.

  • Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
  • Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each item.
  • Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
  • Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
  • Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what further work would be required.
  • Exhibits and supporting materialExtracted artifacts, timelines and schedules in a form that can be attached to a filing or a board pack.
  • Board-ready briefing packA short written brief and slide set that state what is known, what is assumed, and what decision is being asked for.

Proof

Board cyber risk assessment, regional financial institution

Directors needed an independent view before renewing cyber coverage. The assessment identified a material gap between the policy's stated conditions and the institution's actual practice, and ranked three remediation items that closed it before renewal.

Credentials & standards

  • Fixed-fee board assessment
  • Independent; no products or resale relationships
  • Governance and insurance reviewed together
  • Delivered by the examiner who did the work

Decision support

From technical facts to executive decisions

Ways an examination can clarify exposure, timing and the next practical decision.

Corporate examinations, run to the same standard

Corporate work has covered suspected intellectual property theft on issued laptops, quantification of exposure after a hacking event, and examination of former staff suspected of passing data to competitors. This work has supported organizations ranging from the largest enterprises to small professional firms in the United States, Europe and South America. Scope is set per matter; there is no standard package.

Link analysis over unstructured data

Acquisition covers hard drives, backup media, removable storage and complex server environments. Correlating documents, email and latent data into timelines and entity relationships is where the chain of events becomes visible to a decision-maker, and tooling built for that step reduces the cost of an examination without reducing its precision.

Exit as a control, not an incident

Imaging and archiving a departing employee's system at exit preserves the record while it still exists, supports retention obligations, and turns a later dispute into a question of reading evidence rather than reconstructing it.

Related

Related services

Frequently asked

Common questions

How long does the assessment take?

Most assessments run three to five weeks from kickoff to the board session, depending on the size of the organization and the availability of executives for interview.

Do you sell the remediation work you recommend?

No. We do not resell security products and we do not staff the remediation program. The finding is the deliverable, which is what makes it usable in a board minute.

Will the board understand the report?

That is the test we write to. Risks are stated in business consequence and cost, technical detail sits in an appendix, and the briefing is delivered by the person who performed the assessment.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.