Cybersecurity Advisory · vCISO · Compliance

Measured risk.
Defensible security.

Unrisk is a cybersecurity advisory built for organizations that need to move quickly without leaving exposure unmanaged. Audits, penetration testing, virtual CISO leadership, and compliance—anchored in certifications, not jargon.

Specifications
Practitioner-led
The CISSP who scopes your engagement runs your engagement. No bait-and-switch to juniors.
Response window
72-hour incident response SLA on retainer. 24/7 reach for material incidents.
Frameworks
ISO 27001 · ISO 42001 · PCI DSS · SOC 2 Type III · HIPAA.
Audits/ Findings & reporting/ Penetration testing/ Virtual CISO/ Risk advisory/ AI security policy/ Cybersecurity for Attorneys
CISSP· CISM· CCSP· CRISC· CISA· CEH· OSCP· ISO 27001 LA· ISO 42001 LA· PCI QSA· HCISPP· GIAC·
Who we are

Senior practitioners.
Not a sales layer.

Most cybersecurity firms sell you a scan and a report. We staff engagements with practitioners who hold CISSP, CISM, CCSP, and CRISC credentials—who have built security programs inside regulated companies before they ever consulted on one.

The result is advice your engineering team will respect, your auditors will accept, and your board will understand. No theater. No boilerplate. Just defensible security work that holds up under scrutiny.

5
Compliance
frameworks
12+
Practitioner
certifications
100+
Audits &
assessments
72h
Incident
response SLA
What we do

Four disciplines.
One coherent program.

We are built to run alongside your team—advising at the executive level, executing at the technical level, and translating between the two fluently.

01 Assess

Audits & Assessments

Control gap analysis, pre-audit readiness, and full program assessments across ISO 27001, ISO 42001, PCI DSS, SOC 2 Type III, and HIPAA.

See frameworks
02 Report

Security Findings & Reporting

Plain-language findings with severity, exploitability, and remediation effort. Built for engineering, board, and auditor audiences—not three different documents.

See methodology
03 Test

Penetration Testing

Network, application, cloud, and red-team engagements scoped to your threat model—not a generic checklist. Findings delivered with reproduction steps and effort estimates.

See engagement model
04 Lead · Flagship

Virtual CISO

Fractional executive leadership: strategy, board reporting, vendor risk, incident response readiness, and program architecture. The role without the full-time overhead.

Explore vCISO
Virtual CISO · Flagship practice

Executive security leadership, scaled to your stage.

A vCISO engagement gives you a seasoned security executive in your corner—without the full-time overhead. We work across strategy and execution: building the program, sitting with your board, mentoring your team, and translating technical risk into business decisions.

Engagement shape
Retainer Monthly · typical
Time commitment 20–60 hrs/mo
Onboarding 2–3 weeks
Reporting cadence Monthly + quarterly
IR availability 24/7 retainer line
01 Strategy

Strategy & Program Architecture

Multi-year security roadmap, control framework selection, maturity targets, and budget modeling sequenced by risk reduction—not by what is easy to ship.

02 Reporting

Board & Executive Reporting

Quarterly risk reviews, KPI/KRI dashboards, and material incident briefings written for non-technical audiences. Translated, not dumbed down.

03 Compliance

Regulatory & Compliance Liaison

Lead auditor interface, evidence management, gap remediation tracking, and continuous compliance posture across the five frameworks we operate in.

04 Third-party

Vendor & Third-Party Risk

Tiered vendor assessments, contractual security requirements, ongoing monitoring programs, and concentration-risk mapping for SaaS supply chains.

05 Response

Incident Response Readiness

Tabletop exercises, runbook authorship, retainer relationships with forensics firms, and post-incident review facilitation. So the first time you use the plan is not the first time you have seen it.

06 People

Team Mentoring & Hiring

Job description authorship, interview panels, internal security champions program, and on-call rotation design. We make your team better—not dependent on us.

Operating principle
“We do not sell security theater. We do the work that holds up—under audit, under attack, under board scrutiny.”
— Unrisk operating principle
Compliance frameworks

Advisory and assessment
across five frameworks.

Readiness assessments, gap remediation, internal audit support, and lead-auditor liaison. We do not just hand you a report—we sit with you through the audit.

Framework 01

ISO
27001

Information security management systems. Gap analysis, readiness assessments, internal audit support, and stage 1/2 audit facilitation.

ISMS · Annex A.5–A.18
Framework 02

ISO
42001

AI management systems. The first certifiable standard for responsible AI governance. Policy authorship, risk assessment, and implementation guidance.

AIMS · NEW
Framework 03

PCI
DSS

Payment card industry. Scoping, SAQ assistance, ROC development, ASV-style vulnerability validation, and quarterly scan support.

v4.0 · SAQ A–D
Framework 04

SOC 2
Type III

Trust services criteria. Readiness assessments, control authorship, gap remediation, and continuous monitoring for Type II and Type III reports.

TSP · Security C
Framework 05

HIPAA

Privacy and security rules. Risk analysis, policy and procedure development, BAA management, and OCR-aligned audit response support.

45 CFR · 164.308–312
Beyond the five

Different
framework?

We also support NIST CSF, NIST 800-53, NIST AI RMF, FedRAMP readiness, CIS Controls, and bespoke client security programs.

Ask us
Specialized advisory

Where security
meets new ground.

Three practices built for problems that do not fit a checklist—quantitative risk, AI governance, and professional education.

A

Risk Management & Advisory

Quantitative risk analysis (FAIR), risk register design, treatment planning, and risk acceptance documentation that holds up under scrutiny.

FAIR · NIST RMF · ISO 31000
B

AI Security Policy

Model deployment governance, data provenance controls, prompt-injection defenses, and acceptable use policies for LLM tooling and AI features.

NIST AI RMF · ISO 42001 · EU AI Act
C

Professional Education

Starting with Cybersecurity for Attorneys—a CLE-eligible program covering breach response, attorney-client privilege, and regulatory disclosure obligations.

CLE-eligible · On-site or virtual
How we engage

A method that respects
your team's time.

01

Scope & Threat Model

We start with the question “what are we protecting, and from whom?” rather than a generic checklist. Engagement scoping is threat-led, not template-led.

02

Evidence & Discovery

Documentation review, control walkthroughs, technical testing, and stakeholder interviews. We talk to engineers, not just managers.

03

Findings & Severity

Plain-language findings with severity, exploitability, and effort estimates. Built once—shaped for engineering, board, and auditor audiences.

04

Strategy & Roadmap

A multi-quarter remediation plan sequenced by risk reduction, not convenience. With effort estimates, owner assignments, and dependency mapping.

05

Continuous Monitoring

Periodic re-testing, control validation, and program maturity tracking. Security is a posture, not a project.

What you receive
01
Findings report
PDF + live dashboard
02
Risk register
Tracked, owned, dated
03
Remediation roadmap
Multi-quarter, sequenced
04
Evidence package
Auditor-ready
05
Executive summary
Board-ready
06
Walkthrough session
Live, recorded
Credentials

The certifications behind the work.

Credentials are not a differentiator in themselves—most firms have a few. They are a baseline. What matters is that the practitioners holding them are the ones actually doing your work, not a junior team they are supervising.

At Unrisk, the CISSP who scopes your engagement is the CISSP who runs it.

Team certifications
CISSP CISM CCSP CRISC CISA CEH OSCP ISO 27001 LA ISO 42001 LA PCI QSA HCISPP GIAC
Start a conversation

Let's talk about
your risk.

Whether you need a vCISO, a penetration test, or a readiness assessment for an upcoming audit—we should talk. Brief consultations are 30 minutes, no obligation, and routed to a senior practitioner.

Direct
[email protected]
Response window
Within one business day
For incident response
24/7 retainer line
Domain
unrisk.us