How it works
Four steps. Then you can actually use the work.
I keep engagements small on purpose. You should always know what is in scope — dashboards, security work, or both — what landed this week, and that you are talking to me.
01
A conversation
A short call so I can understand whether you need dashboards and reporting, GRC or SOC work, or both — and what is already in place. No pitch deck.
Useful to have to hand: the tools you use today, where the numbers currently live, which questions a useful dashboard would answer — or which audit or GRC question you need answered.
02
Scope
We agree — in writing — what is in. For dashboards: which packs, which measures, how often they refresh. For security work: which GRC or SOC work is in, and what is out. I do not assume anything that is not written down.
I write the scope in ordinary English. If something is not on the list, I do not assume it.
03
Build
Dashboards land quickly, then I tighten them with you. Security work is the same idea: first a usable picture of controls or evidence, then we refine. The aim is something you will actually use, not a perfect model that never ships.
04
Handover and review
You should be able to use the dashboards, packs or findings without a walkthrough every week. I check in, cut what is not useful, and adjust as the business changes.
Ready when you are. A first conversation is a call or an email to me — not a proposal marathon.
Book that conversation