Capability 03
Security Policy & Procedure Development
We write your security policies and procedures around how your firm really works, map them to what your regulator expects, and hand them over ready for your board to approve. Plain enough that your staff will read them, specific enough to hold up under an exam.
When to engage
An auditor, examiner, or insurer asked to see your written policies, and what you have is thin or out of date.
You downloaded a template years ago, and it no longer matches how you actually work.
A client or partner sent a security questionnaire you couldn't confidently answer.
It's been over a year since anyone reviewed the policies you have.
How it works
We start by learning how your firm runs day to day, then draft a policy set around that, not a downloaded template. Each policy maps to what your regulator or auditor expects and reads in plain language your staff can follow. We review the draft with you, adjust, and hand over a set ready for your board to approve and your team to use.
What you receive
- A core set of written policies and procedures: acceptable use (including the AI tools your staff now use), access control, incident response, and the others your obligations require. Grouped so they're easy to navigate, not a wall of twenty separate documents.
- Each policy and procedure is mapped to the obligations your regulator or auditor cares about, and written in language your team can act on.
- A short summary your board can approve, and a plan for keeping the set current as things change.
Ways to work together
Starter set
~2 weeks
- Scope
- A tailored core set: the essential policies, fast
- What you get
- The must-have policies in writing, ready to adopt
- Best for
- An audit, exam, or insurance deadline you need to meet
Full policy set
4–6 weeks
- Scope
- A complete set built around your operations and obligations
- What you get
- Custom policies and procedures, plus a board-ready summary
- Best for
- Most firms putting a real, defensible policy set in place
Full set + upkeep
Ongoing
- Scope
- The full set, kept current on a schedule
- What you get
- Scheduled reviews and updates so the set stays audit-ready
- Best for
- Firms that need policies to stay live, not go stale
Who does the work
Your policies are written by people who have built and run security programs as CISOs and CTOs, then had to defend them to a board and an auditor. They read like something a person wrote, because one did.