Cybersecurity
We agree the baseline before we start. That can be a NIST CSF 2.0 profile, a CIS Controls and benchmark plan, a cloud posture review, or a combination. We build the current picture from interviews and evidence, then agree a target with leadership. The gap becomes a roadmap, ordered by risk and by what your team can take on each quarter. Every finding points to the file that supports it.
Engagement brief
Fixed scope
AccountableYour named owner
ResponsibleA Truvara practitioner
Drafts and citesCASK
Phases
We confirm scope and timing after a first call.
When teams call us
The board asked how your security program compares to a recognized framework
A new security lead needs a baseline in their first quarter
A customer or cyber insurer asked for your NIST CSF profile
You want a roadmap before you commit budget to new tools
What you receive
Drag the divider. On the left, where the work usually starts. On the right, the files you receive.
What you receive
The files from this engagement
Gap assessment
Implementation
Before the engagement
What we usually find on day one
A score with no asset under it and no order to the work.
What it works against
CASK maps every requirement to evidence in the workspace, so scoping starts from what already exists and what is missing.
Key areas covered
How it runs
One sequence, from the records you already have to the outcome in your hands.
Agree scope
Agrees with leadership which business units are in scope and how ambitious the target is.
Interview and verify
Interviews owners across the six CSF functions and asks for proof behind each answer.
Set the target
Runs a workshop to set the target profile against your risks and obligations.
Order the roadmap
Orders the work by risk and team capacity, then presents it to leadership.
What we need from you
Questions