Unrisk is a cybersecurity advisory built for organizations that need to move quickly without leaving exposure unmanaged. Audits, penetration testing, virtual CISO leadership, and compliance—anchored in certifications, not jargon.
Most cybersecurity firms sell you a scan and a report. We staff engagements with practitioners who hold CISSP, CISM, CCSP, and CRISC credentials—who have built security programs inside regulated companies before they ever consulted on one.
The result is advice your engineering team will respect, your auditors will accept, and your board will understand. No theater. No boilerplate. Just defensible security work that holds up under scrutiny.
We are built to run alongside your team—advising at the executive level, executing at the technical level, and translating between the two fluently.
Control gap analysis, pre-audit readiness, and full program assessments across ISO 27001, ISO 42001, PCI DSS, SOC 2 Type III, and HIPAA.
See frameworks →Plain-language findings with severity, exploitability, and remediation effort. Built for engineering, board, and auditor audiences—not three different documents.
See methodology →Network, application, cloud, and red-team engagements scoped to your threat model—not a generic checklist. Findings delivered with reproduction steps and effort estimates.
See engagement model →Fractional executive leadership: strategy, board reporting, vendor risk, incident response readiness, and program architecture. The role without the full-time overhead.
Explore vCISO →A vCISO engagement gives you a seasoned security executive in your corner—without the full-time overhead. We work across strategy and execution: building the program, sitting with your board, mentoring your team, and translating technical risk into business decisions.
Multi-year security roadmap, control framework selection, maturity targets, and budget modeling sequenced by risk reduction—not by what is easy to ship.
Quarterly risk reviews, KPI/KRI dashboards, and material incident briefings written for non-technical audiences. Translated, not dumbed down.
Lead auditor interface, evidence management, gap remediation tracking, and continuous compliance posture across the five frameworks we operate in.
Tiered vendor assessments, contractual security requirements, ongoing monitoring programs, and concentration-risk mapping for SaaS supply chains.
Tabletop exercises, runbook authorship, retainer relationships with forensics firms, and post-incident review facilitation. So the first time you use the plan is not the first time you have seen it.
Job description authorship, interview panels, internal security champions program, and on-call rotation design. We make your team better—not dependent on us.
“We do not sell security theater. We do the work that holds up—under audit, under attack, under board scrutiny.”
Readiness assessments, gap remediation, internal audit support, and lead-auditor liaison. We do not just hand you a report—we sit with you through the audit.
Information security management systems. Gap analysis, readiness assessments, internal audit support, and stage 1/2 audit facilitation.
AI management systems. The first certifiable standard for responsible AI governance. Policy authorship, risk assessment, and implementation guidance.
Payment card industry. Scoping, SAQ assistance, ROC development, ASV-style vulnerability validation, and quarterly scan support.
Trust services criteria. Readiness assessments, control authorship, gap remediation, and continuous monitoring for Type II and Type III reports.
Privacy and security rules. Risk analysis, policy and procedure development, BAA management, and OCR-aligned audit response support.
We also support NIST CSF, NIST 800-53, NIST AI RMF, FedRAMP readiness, CIS Controls, and bespoke client security programs.
Ask us →Three practices built for problems that do not fit a checklist—quantitative risk, AI governance, and professional education.
Quantitative risk analysis (FAIR), risk register design, treatment planning, and risk acceptance documentation that holds up under scrutiny.
Model deployment governance, data provenance controls, prompt-injection defenses, and acceptable use policies for LLM tooling and AI features.
Starting with Cybersecurity for Attorneys—a CLE-eligible program covering breach response, attorney-client privilege, and regulatory disclosure obligations.
We start with the question “what are we protecting, and from whom?” rather than a generic checklist. Engagement scoping is threat-led, not template-led.
Documentation review, control walkthroughs, technical testing, and stakeholder interviews. We talk to engineers, not just managers.
Plain-language findings with severity, exploitability, and effort estimates. Built once—shaped for engineering, board, and auditor audiences.
A multi-quarter remediation plan sequenced by risk reduction, not convenience. With effort estimates, owner assignments, and dependency mapping.
Periodic re-testing, control validation, and program maturity tracking. Security is a posture, not a project.
Credentials are not a differentiator in themselves—most firms have a few. They are a baseline. What matters is that the practitioners holding them are the ones actually doing your work, not a junior team they are supervising.
At Unrisk, the CISSP who scopes your engagement is the CISSP who runs it.
Whether you need a vCISO, a penetration test, or a readiness assessment for an upcoming audit—we should talk. Brief consultations are 30 minutes, no obligation, and routed to a senior practitioner.