CYBERSECURITY AND RISK
A Security Program the Board Can Stand Behind
Most companies have security tools and no security program: policies no one has read, training no one has taken, an incident plan no one has rehearsed, and a SOC 2 request from a customer that no one owns. Tirith provides CISO-level leadership for the program itself: governance, policies, processes, practices, training, and compliance. Tirith does not run scanning tools or penetration tests. That work is done by technical specialists, and the program says when it is needed.
WHEN CEOS CALL
The Situations That Bring a CEO to Tirith
- The board has asked how exposed the company is, and the answer came back as a list of tools.
- A customer has asked for a SOC 2 report, or a security questionnaire, and no one owns the answer.
- The cyber insurance renewal asks about controls the company cannot show.
- Policies exist on paper, and no one can say whether they are followed.
- There is no one accountable for security at the leadership level.
WHAT IT COVERS
What the Program Covers
Governance. Who is accountable for security, how the board hears about risk, and how security decisions get made and recorded. Output: a governance structure with named owners and a reporting rhythm to the board.
Policies, processes, and practices. The policies the company needs, written so people follow them; the processes behind them, for access, vendors, changes, and incidents; and the practices that show whether they are followed. Output: the policy set, the processes behind it, and the evidence.
Training. A program that reaches every employee, with more for the people who hold elevated access. Output: the training program and its record.
Compliance. SOC 2 and the other obligations that customers, insurers, and regulators bring: what applies, where the gaps are, and the path to the report. Output: a gap analysis and a compliance roadmap.
HOW IT RUNS
How the Engagement Runs
- Discovery. Structured interviews with the CEO, the leaders who own the risk, and the people who run the technology, plus a read of the policies, the customer and insurer requirements, the contracts, the incident history, and the tools already in place and who runs them.
- Working sessions. One or more sessions with the leadership team to agree on the program and what comes first.
- Assessment and roadmap. A written assessment of where the program stands, presented directly to the CEO, with the roadmap and a board-ready risk statement. Weeks, not months.
From there the company runs the program itself, or Tirith runs it in a fractional CISO role.
THE MODEL
Advisory First, a CISO When One Is Needed
Security advisory. The assessment, the written recommendations, and the roadmap. All decisions remain with the CEO.
Fractional CISO. Introduced when the company needs someone accountable for the program at the leadership level: the policies, the training, vendor oversight, compliance, and the reporting to the board. Scope and authority are defined in advance. The role ends when a permanent leader is in place or the program runs steadily on its own.
WHAT YOU RECEIVE
What the CEO Receives
From the assessment, in weeks:
- A plain statement of where the security program stands, written for board review.
- The gaps, ranked, with what comes first and who should own it.
- A roadmap to the posture the company needs, SOC 2 and the other obligations included.
The roadmap names what the program needs built: the governance structure with owners and a reporting rhythm, the policy set and the processes behind it, the training program and its record, the compliance evidence. Whether Tirith builds them, in an advisory or fractional CISO role, or the company builds them itself, is a separate decision, made with the roadmap in hand.
WHO DOES THE WORK
The Practitioner Who Scopes It Delivers It
Tirith’s practitioners have held CIO, CTO, and CISO roles at operating companies. Val Thomas has spent more than forty years in technology, starting as a coder, and close to three decades as a CIO and CTO across public companies, private enterprises, and startups. At Lincoln Educational Services, a publicly traded company, he advised the board on cybersecurity posture, AI governance, and capital allocation while running enterprise technology strategy.
Tirith sells no security products and has no vendor relationships behind its recommendations. Where the program calls for a tool, a service, or a technical test, the company chooses its own provider.
Tirith Strategies is based in Warren, New Jersey, and works with companies globally.
QUESTIONS
Questions CEOs Ask
No. Tirith does not run scanning tools or penetration tests. The work is the security program: governance, policies, processes, practices, training, and compliance. Where the program calls for technical testing, it says so, and the company chooses a specialist to run it.
Tirith runs the readiness side: which controls apply, where the gaps are, the policies and the evidence, and the path to the audit. The audit itself is performed by a licensed CPA firm, which the company chooses.
A plain statement of where the program stands: who owns what, which risks are accepted and which are being fixed, and how the board will hear about it from now on. It holds up in front of an insurer or a customer as well.
The provider runs the tools. The program decides what the tools should be doing, checks that they do it, and owns the policies, the training, and the compliance the provider does not. Both are needed.
Someone accountable for the security program at the leadership level, part time, with scope and authority written down in advance. A company needs one when there is no such person and the program cannot wait for a hire. Advisory always comes first; the fractional role is a separate decision.
A senior practitioner who has held the CIO or CISO role. The person who scopes the engagement is the one who delivers it. There is no junior team behind the conversation.
Let’s Start the Conversation.
The next step is a no-charge discovery call: a direct conversation with Val about the situation and whether the program assessment is the right first step.
