About

Cybersecurity execution for teams
too small for a cybersecurity team.

Grey Wing gives growth-stage companies practical cybersecurity, IT operations, and infrastructure support inside the tools and accounts they already use.

The problem

Customer questions arrive before process does.

The work falls to a founder or engineering lead unless someone carries it directly.

Customers ask for a SOC 2 report or a completed cybersecurity questionnaire before they sign. Investors ask about MFA coverage and vendor risk before they wire a check.

Grey Wing takes that work into the client's tools and accounts. Controls, evidence, and decisions stay where the team can operate them.

Mission and vision

Mission and vision.

Mission

Grey Wing carries cybersecurity and IT operations inside client systems, including identity providers, endpoint consoles, SaaS administration, cloud accounts, and code repositories.

Grey Wing records the changes it makes, reports what it finds at the severity it actually is, and lists the gaps Grey Wing created alongside every other open risk.

Vision

A client should be able to reconstruct everything Grey Wing did in their systems from the monthly report alone.

The report identifies the systems Grey Wing touched, the accounts and permissions it changed, the controls it tested, the findings it opened, and the decisions that remain.

Nothing absent from that report is absent by choice.

What we work on

The work reaches into the systems that keep a company running.

Compliance is one reason clients call. The controls and operating work extend further.

DevOps and cloud

Architecture reviews, identity permissions, infrastructure-as-code changes, network paths, and recovery testing.

Explore DevOps and cloud

IT operations

Identity, endpoint management, SaaS administration, onboarding, offboarding, and access-change workflows.

Explore IT operations

Detection and response

Log coverage, alert tuning, incident response steps, detection gaps, and tested response scenarios.

Explore Detection and response

How we operate

Scope around the risk, then carry the work.

The engagement stays tied to the milestone in front of the company.

Scope around business risk and near-term milestones.

Execute implementation directly with your team.

Report outcomes in language leadership can use.

Standards

Grey Wing holds standing admin access inside client systems.

What that means in practice.

What goes in the monthly report

Open risk stays listed until it is closed or the client accepts it in writing. Risks that trace back to something Grey Wing configured are listed the same way as everything else.

Severity is rated on what an attacker can do with the gap, including when Grey Wing created it.

Findings name the control that failed. Attribution to a named individual is scoped to the engagement, an insider-threat investigation, or a legal obligation.

The fixed fee absorbs the estimate risk

Grey Wing quotes a fixed fee in 48 hours on partial information. Work that turns out larger than the proposal said is finished at the quoted price, unless the environment differs materially from what the client described at scoping.

No labor charge appears on an invoice that was not approved in advance.

A scope that is going to miss its 48-hour deadline gets a revised date before hour 48.

Retainers Grey Wing cannot staff are declined and referred out.

Access is inventoried and handed back

Every Grey Wing account in a client tenant is named and scoped to the work it exists for. The account list ships in the monthly report.

At the end of a retainer, Grey Wing delivers that list and asks the client to disable each account in writing.

Client architecture, findings, and incident details stay inside Grey Wing and its listed subprocessors, and go beyond that only where a contract, a court, a regulator, or our insurer requires.

No client environment appears in a talk, a case study, or a sales anecdote, named or anonymized, without written permission. A flaw found in a third-party product is reported to that vendor without identifying the client.

Questions about how we work?

Bring us the systems, deadline, or control that needs a practical answer.