Cybersecurity & IT operations · Retained

The cybersecurity team you hire
before you hire a CISO.

We take over the SOC 2 evidence, the detection rules, the laptop fleet, the identity provider and the cloud permissions. One engineer owns it and reports to your CTO every month.

48hrs

From the discovery call to a written scope

1–2wks

From signature to work starting in your stack

7modules

Five core, two add-on. Turn on what you need

1owner

An engineer, with a backup

Our engineers have built systems at

  • ZyngaZynga
  • WalmartWalmart
  • New RelicNew Relic
  • Funding CircleFunding Circle
  • RoutableRoutable
  • Sensity SystemsSensity Systems
  • ShutterflyShutterfly
  • TaggedTagged
  • ifweifwe

Services

What we take off your plate.

Seven modules, plus fixed-scope projects for one-time work. Every module has an owner, a runbook in your repository and a written deliverable.

They ran the SOC 2 while we shipped. We never had to build the function.
Brian Walerius, CTO52 people

SOC 2 Type II

Passed without an in-house cybersecurity hire

2 frameworks

SOC 2 and HIPAA supported

1 year

Annual plan commitment

Retainers

Three levels of ownership.

Priced monthly against headcount and cloud footprint. No per-ticket billing.
How many people
Anything else true

Likely fit

Essentials

One owner for cybersecurity and evidence you can hand a customer.

Essentials

Companies without a cybersecurity owner that need an owner for cybersecurity operations.

Includes: Cybersecurity only

Contact Us

  • Cybersecurity roadmap ownership and quarterly strategy review
  • Identity and access hardening — SSO, MFA, privileged access
  • Customer cybersecurity questionnaire support
  • Cybersecurity metrics and reporting
Scope Essentials

Process

The first 90 days.

What happens between the discovery call and your first quarterly review. No workshop series and no 40-page assessment before anything gets fixed.
  1. Week 0

    Discovery and scope

    A 45-minute call on your stack, headcount, audit date and the last thing that broke. Written scope back within 48 hours.

  2. Week 1

    Access and inventory

    Scoped access to your identity provider, cloud accounts, MDM and repositories. We inventory what exists before changing anything.

  3. Weeks 2–4

    Quick wins

    MFA gaps closed, standing admin roles cut back, leavers removed across SaaS and cloud, MDM baseline pushed, logging switched on.

  4. Weeks 5–12

    Program build

    Policies written, controls mapped to your framework, detection rules deployed to production, evidence collection on a schedule.

  5. Day 90

    First quarterly review

    Risk register walked through with your CTO, open items with owners and dates, and the plan and budget for next quarter.

Before you call

The questions we get asked first.

If yours is not here, put it in the form and we will answer it on the call rather than in a follow-up.

Ask us directly

sales@greywingsecurity.com

Get started

Tell us your audit date and your stack.

We send back a written scope within 48 hours covering the engineer, the modules and the first 30 days of work. If we are not the right firm for you, we will say so on the call.

Two ways in

Book a discovery call

45 minutes. Pick a slot that works — no form before the call.

Send the details instead

Stack, headcount and audit date. We reply the same business day.

Or email sales@greywingsecurity.com