All offerings

Capability 03

Security Policy & Procedure Development

We write your security policies and procedures around how your firm really works, map them to what your regulator expects, and hand them over ready for your board to approve. Plain enough that your staff will read them, specific enough to hold up under an exam.

When to engage

  • An auditor, examiner, or insurer asked to see your written policies, and what you have is thin or out of date.

  • You downloaded a template years ago, and it no longer matches how you actually work.

  • A client or partner sent a security questionnaire you couldn't confidently answer.

  • It's been over a year since anyone reviewed the policies you have.

How it works

We start by learning how your firm runs day to day, then draft a policy set around that, not a downloaded template. Each policy maps to what your regulator or auditor expects and reads in plain language your staff can follow. We review the draft with you, adjust, and hand over a set ready for your board to approve and your team to use.

What you receive

  • A core set of written policies and procedures: acceptable use (including the AI tools your staff now use), access control, incident response, and the others your obligations require. Grouped so they're easy to navigate, not a wall of twenty separate documents.
  • Each policy and procedure is mapped to the obligations your regulator or auditor cares about, and written in language your team can act on.
  • A short summary your board can approve, and a plan for keeping the set current as things change.

Ways to work together

Starter set

~2 weeks

Scope
A tailored core set: the essential policies, fast
What you get
The must-have policies in writing, ready to adopt
Best for
An audit, exam, or insurance deadline you need to meet
Recommended

Full policy set

4–6 weeks

Scope
A complete set built around your operations and obligations
What you get
Custom policies and procedures, plus a board-ready summary
Best for
Most firms putting a real, defensible policy set in place

Full set + upkeep

Ongoing

Scope
The full set, kept current on a schedule
What you get
Scheduled reviews and updates so the set stays audit-ready
Best for
Firms that need policies to stay live, not go stale

Who does the work

Your policies are written by people who have built and run security programs as CISOs and CTOs, then had to defend them to a board and an auditor. They read like something a person wrote, because one did.

A board-ready policy set in 4–6 weeks.