Security for established companies
A lot of cyber security work starts with an outside request. A customer sends a questionnaire during contract review. An insurer asks about controls at renewal. An auditor asks for evidence nobody has pulled together before.
Digital Consulting, Inc. works with companies that handle customer, personal, health, or financial information and have no full-time security team. We scope the work around the immediate requirement and put that scope in writing before we start. The documentation stays with you, written so your own team can use it later.
Working alongside your IT provider
Your IT provider keeps doing what they already do. We do not replace them, compete for their work, or take over daily operations. The helpdesk, the monitoring, the patching, and the on-call rota stay where they are.
We look at what is already in place and identify the gaps. Then we help you put together an answer you can support with evidence. If the fix belongs with your IT provider, we write it up so they know what needs to change and you can verify it afterwards.
We sell no security products and take no commission from any vendor. Nothing in a recommendation depends on you buying something afterwards.
- Built for
- Companies that handle sensitive information but do not have a full-time security team.
- Engagement model
- Fixed-fee projects, plus monthly advisory for companies that need ongoing security leadership.
- Your IT provider
- Keeps operating your systems. We assess, advise, and help coordinate the security work around them.
Already have a date to meet? Contact us to discuss.
Fixed-scope starting points
Every engagement is scoped in writing before work begins. The scope says what is included, what we will deliver, and what sits outside the engagement. Each one is a defined first project drawn from the broader services we offer.
A customer has sent security requirements, a questionnaire, or a contract schedule, and expects an answer by a date.
Customer security requirements response
We work through the request with whoever knows the systems and processes involved. That may include management, internal technical staff, and your IT provider. We have spent a lot of time on the other side of this process, answering enterprise customer security reviews and supporting the answers with evidence.
Customers often come back with follow-up questions: access control, how customer data is kept separate, what is logged, who can reach production. If those are holding up the contract, we can include them in the scope.
If an answer cannot be supported, we say so. We don't treat an undocumented or unverified control as complete.
- You receive
- The completed response, a reusable answer library, an evidence index, and a short list of gaps likely to matter in the next customer review.
You want to know where the company stands before a customer, an insurer, an auditor, or a regulator asks.
Security baseline and roadmap
We focus on the security practices that matter for the systems and data your business actually relies on, including systems an outside provider operates. You get a prioritized list of issues instead of a maturity score, so it is clear what needs attention now and what can reasonably wait.
If an outside requirement is driving the work, we can structure the review around the relevant framework. Findings are still prioritized against your environment and your obligations.
This work can help you prepare for an outside assessment, but it is not the assessment. Nothing we produce will be described as a certification, an audit, or a formal conformity assessment.
- You receive
- A current-state summary, prioritized findings, and a roadmap organized around the next 30, 60, and 90 days.
Your systems run in the cloud, operated by your own team or by a provider, and nobody has reviewed the configuration against the risk you carry.
Cloud and infrastructure security review
We usually start with identity and privileged access. From there we look at network exposure, environment separation, logging and alerting, and the configuration of the systems in scope. The exact scope depends on what the company runs and who operates it.
This is a configuration and architecture review. We also look at what a compromised account, endpoint, or service could reach, and what would contain the damage. Testing against your live systems is not part of it unless it is scoped separately and agreed in writing.
When possible, we review the configuration directly through read-only access or an export. If that is not available, we rely on documentation and interviews, and the report says so.
- You receive
- Prioritized findings written so whoever operates the systems can act on them, the business risk each one creates, and a record of what was examined and what was not.
Staff are already using AI tools and nothing states which ones are approved, for what work, or with what data.
AI use policy and tool review
In many companies people start using AI tools before anyone has decided what is allowed. We turn that into a practical policy covering approved tools, data handling, review requirements, and exceptions.
We can also review a specific AI service before you adopt it. That review can cover data handling, contract terms, security controls, administration, and the way you plan to use it. Ideally it happens before the company commits to the tool.
- You receive
- A written AI use policy sized to how the organization already works, handling rules for company and customer information, and a tool review memo documenting the decision, the conditions of use, and what to check again later.
You have an incident response process, formal or informal, and nobody has tested how it would actually hold up.
Incident readiness review
We look at how a cyber security incident would actually be handled. Who gets called, what information they would have in front of them, what your IT provider can do, and which decisions still belong to management. We then run a tabletop exercise based on a realistic scenario for your business.
Where an outside provider handles part of the response, the exercise includes that handoff and the decisions that stay internal.
- You receive
- A readiness assessment, a playbook sized to your environment, and a written record of what the tabletop exposed.
The company needs continuing security ownership and is not ready to hire a full-time security leader.
Security program advisory
This is ongoing security leadership for companies that need someone responsible for the security program but are not ready for a full-time hire. It doesn't include running your IT, operating a managed security service, or staffing a helpdesk.
You work with the same security lead on a regular schedule. The work can include maintaining the roadmap and risk register, helping with customer or insurer reviews, and coordinating assessments. It can also cover supplier reviews and reporting to management or the board.
- You receive
- Continuing security leadership, a maintained roadmap and risk register, documented decisions, and regular updates to management.
Other work we can scope
We also take on application and API security reviews, vulnerability intake and remediation process design, threat modeling, and other technical security assessments. If your need does not fit one of the starting points above, contact us with what you need and any deadline you are working against.
Inside a deliverable
Each finding says what we found and why it matters. It includes the supporting evidence, the realistic impact, and the recommended next step. Where it matters, we also identify who owns the decision and who owns the fix. If the issue is deferred, the report states the remaining risk.
Technical teams and service providers get enough detail to understand the issue and change the system. Management gets the business impact, priority, expected effort, and the risk of leaving it unresolved.
Learn more about how our deliverables are structured.
Experience behind the work
Engagements are led by Edward Bonver, CTO of Digital Consulting, Inc., CISSP and CSSLP. Relevant employment history, publications, standards work, and community leadership are listed on the About page, with links to the original sources.
Work we do not take on
We don't run your IT, operate a security operations center, monitor your systems, patch your servers, or answer your helpdesk. Recommendations are based on your requirements, your existing environment, and what is practical for the company.
If penetration testing is needed, we can help define the scope and select a specialist provider. We can also help you review and work through the findings. The testing itself is done by that provider.
Regulatory work is limited to readiness and advisory support. We do not certify, audit, or issue conformity assessments.
You keep everything produced during an engagement. We write it so your team, your IT provider, or a future security hire can keep using it without depending on us.
Fees and scope changes
Each fixed-scope service is quoted as a fixed fee. Program advisory is billed monthly. Scope, fees, assumptions, and deliverables are agreed in writing before work begins, which is step two of the engagement process. If we find additional work along the way, we discuss it with you before the scope or the cost changes.
Starting a conversation
Tell us what prompted the security work, what you have been asked to provide, and when it is due. You can send the questionnaire, the renewal form, the contract requirement, or the email that started it. We will tell you whether it fits one of the engagements above or whether a smaller custom scope makes more sense. You don't need to define the scope before contacting us.