1

Discovery

We start by understanding your business, your industry, and your security concerns. This phase is about gathering the information we need to give you the most relevant, actionable assessment possible.

📝
Quick Intake Form

Complete a short online form (5 minutes) so we understand your company size, industry, and what triggered your interest in an assessment.

📋
Technical Questionnaire

We send you an 11-section questionnaire covering your current technology, security tools, policies, and compliance needs. This is the foundation of our assessment.

🎯
Tier Recommendation

Based on your responses, we recommend the assessment tier that best fits your needs and budget. No upselling, just the right fit.

📞
30-Minute Kickoff Call

After payment and SOW acknowledgment, we schedule a brief kickoff call to clarify your questionnaire responses and set expectations for the engagement.

2

Assessment

This is where the real work happens. We conduct a thorough review of your security posture using industry-standard frameworks, tailored to your specific tier.

🔍
Technical Review

We analyze your systems, networks, access controls, and security tools against established frameworks (CIS Controls v8, NIST, HIPAA, etc.).

📊
Gap Analysis

Every control is scored for maturity. We identify what's in place, what's partially implemented, and what's completely missing.

⚠️
Risk Prioritization

Not all gaps are equal. We prioritize findings by business impact so you know what to fix first, second, and what can wait.

🏗️
Founder-Led

Your assessment is conducted by John Codis personally, not a junior analyst. You get senior-level expertise from start to finish.

3

Deliverables

You receive everything you need to understand your security posture and take action. No vague recommendations. Every finding includes specific, practical next steps.

📄
Assessment Report

A clear, detailed report with an executive summary, maturity scores for each control area, and specific findings with evidence.

🗓️
30/90-Day Action Plan

A prioritized roadmap with immediate quick wins (30 days) and longer-term improvements (90 days), ranked by risk and effort.

📑
Policy Templates

Where we identify policy gaps, we provide templates you can customize and implement immediately. No starting from scratch.

Implementation Guidance

Recommendations written for companies without a security team. Clear language, specific tools, realistic timelines.

4

Debrief & Next Steps

We don't just drop a report in your inbox and disappear. We walk you through every finding, answer your questions, and make sure you have a clear path forward.

💬
30-Minute Debrief Call

A live walkthrough of your report findings, risk priorities, and action plan. Ask anything. This is your time.

🔄
Optional Ongoing Advisory

If you want ongoing support implementing recommendations, our CyberReady Guard vCISO retainer is available month-to-month. No pressure, no lock-in.

How long does it take?

From kickoff to report delivery, here's what to expect for each tier.

5 days
Security Essentials
10 days
CyberReady Snapshot
20 days
AI-Ready Zero Trust
15 days
Compliance Readiness

All timelines measured in business days from kickoff call.

Ready to get started?

Complete our quick intake form and we'll be in touch within one business day with a recommendation.

Get Your Free Consultation → Call 631-987-8215