Fortellar

Someone has to own security. This practice is how that gets decided, built, and staffed.

Four services covering the whole arc: read the program as it actually runs, put an executive in the seat, build the layers underneath, and integrate what an acquisition just brought in.

Why This Matters

Most security programs aren't failing. They were never designed, and no one owns them.

In the mid-market, security usually starts as a set of tasks attached to whoever had capacity: an IT director carrying policy, a controller carrying vendor questionnaires, an MSP carrying the tooling. It works until a board member, an auditor, an acquirer, or an incident asks who owns the program and the honest answer is nobody.

This practice answers that question in whatever form it arrives. A time-boxed diagnostic when leadership needs a defensible current-state read. An experienced executive in the seat when the role is real but the hire isn't. A build when the roadmap exists but the layers don't. Integration when a deal doubled the estate overnight.

By the Numbers
68%
of breaches involve a non-malicious human element, failures of process, policy, or training. The program is what closes those gaps; the tools cannot.
Verizon Data Breach Investigations Report
$10.22M
average cost of a data breach in the United States in 2025, the highest of any country tracked.
IBM · Cost of a Data Breach Report 2025
1 in 4
executives have experienced a cybersecurity incident during or shortly after a transaction. 58% of those say it impaired the combined entity's ability to hit its post-deal financial targets.
FTI Consulting · CISO Redefined
Services in this practice

Four services: Assess, Lead, Build, Integrate.

Most engagements start with the diagnostic or the seat. What follows depends on whether the gap turns out to be the plan, the people, or the program itself.

Start where you are

Four moments bring people here. Each one has a different first step.

You don't need to know which service you need. Find the sentence that sounds like your quarter, and start there.

The moment
What's actually at risk
Where to start

A new security leader just started

“I'm ninety days in and the board wants a strategy. What I inherited is a vendor list.”

The first ninety days set the next three years of budget and credibility. Building the plan on the team's narrative, or last year's audit, is not a defensible starting point.

Start hereStrategic Security Posture

Fixed scope, fixed fee, ends inside the window.

The seat is empty and the search is slow

“We've been recruiting a CISO for seven months. Meanwhile nobody signs off on anything.”

An empty seat is not a pause. Decisions accumulate, vendors go unmanaged, and audit responses get written by whoever is least busy.

Start hereFractional CISO

In seat in weeks; bridges to a permanent hire.

A regulator, insurer, or enterprise customer wants the program on paper

“They asked for our security program documentation. We have policies from 2021 and no evidence.”

Policy without controls and evidence reads as an unmanaged program. The gap is construction, not documentation.

Start hereSecurity Program Build

Pairs with Compliance Audit Readiness on a deadline.

An acquisition just closed

“We own their environment as of Monday and we've never seen inside it.”

Inherited risk is immediate and undocumented: unmanaged admin access, unknown data, and two control sets that contradict each other.

Start herePost-Merger Security Integration

Day-one containment first, integration plan second.

How the practice operates

Six things every engagement in this practice does.

Whether we are assessing, leading, building, or integrating, the discipline is the same.

01

A named senior owner

Every engagement is led by a partner who signs the work. No pyramid staffing, no anonymous deliverables, no findings nobody will defend in a board room.

02

Evidence behind every claim

Current-state statements are backed by artifacts and interviews, not the team's self-assessment. It's the difference between a document and a diagnostic.

03

Sequenced to your calendar

Roadmaps are ordered against the audit cycle, the budget cycle, and the board calendar you already have, not a generic maturity ladder.

04

Board and fiduciary language

What's covered, what isn't, what changes, when, and what it costs. Written so the CFO and the audit committee can underwrite it.

05

Built to be operated

Governance forums, policies, and controls come with owners, cadences, and reporting. A program nobody can run is a document, not a program.

06

One continuous thread

The diagnostic feeds the build. The build feeds the fractional executive. Nothing restarts, and no engagement begins with rediscovery.

What this practice covers

What the program is built against, and what it reaches.

Frameworks & obligations

The standards the program is mapped to

Programs are constructed against the frameworks you actually carry, so one control set answers every audience asking.

NIST CSF 2.0NIST 800-53NIST RMFSOC 2HIPAA Security RuleHITRUST CSFISO 27001PCI DSSNYDFS Part 500CIS Controls v8
Program domains

What the assessment and the build cover

Thirteen security domains and five technology operations domains, read together, because the program fails where they meet.

Governance & policyRisk managementIdentity & accessData protectionVulnerability managementIncident responseThird-party riskBusiness continuitySecurity architectureMetrics & reportingTechnology operations
Expertise This Work Draws On

The expertise behind this practice.

Cybersecurity & Compliance

GRC Program Design

Governance, risk, and compliance operated as one framework with a single control set, designed by former auditors and GRC leaders who know what fieldwork asks for.

See expertise
Cybersecurity & Compliance

Security Engineering & Architecture

The architectural read behind the roadmap: where the defensive backbone is built on modern principles like Zero Trust, and where it only looks that way on paper.

See expertise
Technology & Security Operations

Identity & Access Management

Joiner-mover-leaver, privileged access, and access certification — the controls auditors test first and programs most often lack an owner for.

See expertise
Cloud & Technology Infrastructure

Cloud Security & Governance

Where the program meets the platform: landing zones, guardrails, and the cloud controls the roadmap has to sequence.

See expertise

Bring us the board question, the empty seat, or the environment you just acquired.

We'll tell you which of the four services you actually need, what it would take, and where you're already covered.