Cybersecurity and AI governance for organizations that have to prove they are in control.

Two practices for banks, credit unions, insurers, and mortgage lenders and servicers. Mortgage is the specialization, and the work travels.

The question (who performed your last independent test), the artifact (the report, its scope and dates), where it lives (the vendor file, a named owner), and its review date, which most programs lack.

Where to start depends on the situation.

By situation
The situationWhere to start
An examination is on the calendar.Examination and Evidence Readiness
A finding has a date on the response.
A counterparty, carrier or customer asked us to prove something.
A rule changed; the board needs a paper on it.The board packet
The board asked which AI is in use and who approved it.AI Governance Assessment
Somebody found an AI tool running that nobody approved.
A vendor switched on AI inside a system we use.AI Vendor and Third Party Review
A model already touches a lending, underwriting or claims decision.AI in Regulated Decisions
Internal audit or the audit committee raised it.Security Assessment
Something happened; what must we report, and to whom?Cyber Defense. Call 888-260-7050 if it is happening now.

Industry shaped? Mortgage, Financial Services or Insurance. None of these? The Security Assessment.

Two practices; neither is a component of the other.

Cybersecurity: offensive security and cyber defense. AI governance: the record a model's decisions leave. Each is bought on its own and answers to different instruments.

The security answer and the AI answer are made to the same supervisor, out of the same file, and this firm builds both.

Why one firm holds both practices

Five instruments already put both subjects in one file:

The last two, in force since March and August 2026, require a Seller/Servicer using AI to hold a written governance framework for it. Status of each: Sources.

This firm builds the program and the evidence to the shape the instrument requires. Counsel confirms the legal reading for your state.

Three sizes of first step.

  1. Smallest: the Platform Review, one platform, read only; the AI Vendor and Third Party Review, one vendor.
  2. Published scope: the Security Assessment, Core or Full; the AI Governance Assessment.
  3. Continuing: Advisory and vCISO, the vulnerability program, the AI Governance Program.

Eight commitments, in writing.

  • Fee and duration in writing before you sign.
  • We reply within one business day and answer your date.
  • One round of verification of remediated findings, included on testing and assessment engagements.
  • No assessment or test of a program we own as virtual CISO, for the same client in the same period.
  • If an engagement stops, you keep everything produced to that point.
  • No subcontractor without telling you first; you can decline.
  • We will tell you within two business days of becoming aware of any incident affecting your material.

  • References at proposal stage, under NDA, on request.

In full: Trust and Assurance.