Risk Assessment

A structured review of your cybersecurity posture, data handling practices, and vendor relationships — with findings in plain language.

Policy Development

Practical, right-sized policies your team can actually use: data classification, incident response, acceptable use, and more.

Vendor Risk Review

Evaluation of third-party tools and vendors you rely on, with prioritized recommendations and a usable inventory.

AI & Data Governance

Guidance on responsible AI use, data governance frameworks, and managing third-party tools your staff has adopted.

Compliance Guidance

Alignment guidance for HIPAA, FERPA, NIST CSF, and other frameworks relevant to your organization type.

Staff Awareness

Short educational sessions to help your team recognize and respond to common threats — tailored to your context.

Your deliverables

—Intake assessment and scoping call
—Written risk findings summary
—Prioritized recommendations report
—At least one tailored policy document
—Vendor risk inventory worksheet
—Optional follow-up check-in at 60 days

Your commitment

—2–3 hours for intake and interviews
—Access to relevant documents and vendor contracts
—A primary point of contact at your organization
—Timely feedback on draft deliverables
—Participation in a final findings review

Every clinic engagement runs through our clinic workspace platform — intake, scoping, the supervised work itself, a practitioner review, delivery, and an optional 60-day check-in are all tracked there, so nothing reaches you unreviewed. Nate Butler, CISM, our Director of Security Services, serves as the practitioner anchor of the clinic model: he or a designated reviewing practitioner signs off on every deliverable before it is sent to your organization.

Your files and engagement records are visible only to your organization's point of contact and the assigned clinic team in that workspace. If you're a returning partner, you can log in directly: Partner Login →

What this is — and isn't: The clinic delivers a structured risk review and practical recommendations performed by supervised participants under practitioner oversight. It is a starting point for strengthening your organization's posture, not a certified compliance audit, a penetration test, or a legal determination of regulatory compliance. Where a certified or third-party audit is required, we'll tell you so directly.

Tell us about your organization. A member of our team will follow up within 5 business days.

✓ Received — we will follow up within 5 business days.
Something went wrong. Please try again.