Services · Core module

Cybersecurity Program

Owns cybersecurity architecture, identity, access reviews, vulnerability tracking, awareness, metrics, and the roadmap.

Replaces
Cybersecurity Manager
Where it sits
Included in Essentials, Managed, Complete

Scope

What we own.

Every line is work an engineer carries, reports on monthly, and hands over documented if the retainer ends.
  • Cybersecurity roadmap and quarterly strategy review
  • Cybersecurity architecture review on new systems and major changes
  • Identity and access hardening — SSO, MFA, privileged access
  • Quarterly access reviews and recertification
  • Attack surface and external exposure monitoring
  • Vulnerability management and remediation tracking (infra and endpoint)
  • Email Security — DMARC, SPF, DKIM, gateway policy
  • Phishing simulation and cybersecurity awareness program
  • Cybersecurity questionnaire and customer diligence support
  • Annual tabletop exercise
  • Cybersecurity metrics and monthly reporting

Boundaries

What this does not cover.

Stated up front so the scope in your proposal matches what actually gets done.
  • This module owns infrastructure and endpoint vulnerabilities. Code and dependency vulnerabilities belong to Application Security. See Application Security.
  • This module coordinates and escalates incidents. Detection & Response investigates and responds. Without Detection & Response, nobody is watching the logs. See Detection & Response.
  • Cybersecurity Program runs the work and reports monthly. vCISO is the named accountable cybersecurity officer. See vCISO.

Talk through Cybersecurity Program.

Bring the systems, the role this has to cover, and the deadline. We come back inside 48 hours with a written scope.