Independent counsel for security leaders

The senior second every CISO needs, and rarely has.

Keystone Executive gives your security leader independent senior counsel — and carries the reporting, evidence and assurance work that lands on them, and no one else. Alongside your team, under your name.

Deputy CISO, Chief of Staff to the CISO, or no title at all — you choose what fits your structure.

Request a conversation Fifteen minutes, peer to peer.
01 What we do

Every security team carries three loads. We carry the fourth.

Reporting, metrics, evidence, assurance — the work that is neither strategy nor operations. It has no owner, it lands on the CISO, and it is the layer your whole programme is judged through.

Strategy

Where the programme is going

Delivery

The projects that get it there

Operations

Running it — and absorbing incidents

The fourth load — ours to carry

Reporting · Metrics · Evidence · Chasing · Maturity · Spend · Questionnaires · Committee papers  —  done properly, so your team stays on the other three.

02 How we help

Judgment when you need it. Delivery when you don’t have time for it.

Counsel

A senior, independent voice to test a position against before you commit it to a board or a regulator.

Capacity

The fourth load carried to an agreed outcome and a date — the work finished, not the findings handed back.

Coverage

Where it helps, someone credible alongside you with auditors, regulators and vendors. At your direction, under your name.

03 How we work

One accountable partner. The rest is ours to run.

under your name directs delivery You · the CISO set scope & priorities Your partner accountable · by name does not rotate off Delivery bench ours to resource WeeklyMonthlyQuarterly working contactwritten reviewscope & outcomes

Outcomes, with dates

Scoped as results, never in hours.

Never per head

How we resource it is ours to manage.

Held to our dates

Not delivered means not invoiced.

A clean exit

Notice either side, everything handed over.

04 Why Keystone

What makes us different.

01

A second, not a substitute

under your name CISO Keystone

We support the leader you have — never a replacement pitched over your head.

02

The work, finished

Finding Done ≈ 200 hrs — ours

Not the action list. The two hundred hours after it, carried to done.

03

One name, four markets

One lead US SG AU IN

Working rights in four jurisdictions, follow-the-sun delivery behind them.

· What comes off your desk
01

Board & committee packs.

Built, with the story behind every number — ready before you’re asked, in language the room already speaks.

Scroll for a sample

Board-ready metric scorecard

Sample · Illustrative
16/25
metrics within target
5
breaching, all owned
71
protection level index
<1 day
to produce the pack

Outcome-driven metrics against target

MetricNowTargetTrendStatus
Critical assets patched ≤ 14 days62%85%Breach
Mean time to detect (hrs)9.44.0Breach
Mean time to respond (hrs)2624Watch
Endpoints with EDR coverage94%98%Watch
Privileged accounts under PAM58%90%Breach
Backups restore-tested in period81%75%Met
Staff completing phishing training96%95%Met

Protection level index by quarter

target 80 52586671 Q1Q2Q3Q4
Every cell is one click from its evidence, its owner and its blocker. Export to board format on demand.
Illustrative. Every number traces to evidence you can defend.
02

Security operating model.

How your security function is structured, staffed and run — capabilities mapped, decision rights clear, and the gap between today’s model and the one your risk demands made explicit.

Scroll for a sample

Security operating model — current vs target

Sample · Illustrative
24
capabilities mapped
2.6/5
operating-model maturity
9
capabilities below target
41%
decision rights defined

Capability maturity — current vs target

Governance & riskSecurity architectureIdentity & accessThreat & vuln mgmtDetection & responseThird-party riskAwareness & culture Current Target

The shift — today to target

DimensionTodayTarget
StructureCISO-centricFederated + RACI
Decision rightsUndefinedDocumented ARB
SourcingAll in-houseCore + managed SOC
CoverageReactiveService catalogue
ReportingMonthly scrambleBoard-ready, automated
TalentKey-person riskRoles, not heroes
Illustrative. The function designed as a model — not a set of people holding it together.
03

Compliance & maturity.

Scored against NIST CSF and the SCF, with the gaps heat-mapped by business unit so budget goes where it moves the needle.

Scroll for a sample

Enterprise compliance & maturity

Sample · Illustrative
68%
NIST CSF 2.0 compliance
2.4/5
weighted maturity
17
critical gaps open
41/60
policies migrated

Control maturity · CSF function × business unit

RetailPayCorpDigitalShared GovernIdentifyProtectDetectRespondRecover Critical Watch Managed Strong

Current vs. target maturity

GovernIdentifyProtectDetectRespondRecover Current Target
Illustrative. Red is where budget and headcount go first.
04

Audit & regulator evidence.

Collected once, kept current, reused across every framework you report to — so audit season is retrieval, not assembly.

Scroll for a sample

Audit evidence readiness

Sample · Illustrative
84%
controls with current evidence
21 days
median evidence age
12
open findings, 2 repeats
<6 days
audit prep, was 6 weeks

Evidence coverage by framework

NIST CSFISO 27001SOC 2PCI DSSInternal 88%84%91%76%82%

Control reuse across frameworks

Control familyFrameworksEvidence
Access control & review5Current
Change management5Current
Vulnerability management4Current
Encryption & key handling4Stale
Logging & monitoring4Current
Backup & restore testing3Stale
Supplier management3Missing
Illustrative. One control, tested once, answers four frameworks.
05

Third-party risk.

Tiered, chased and assessed — and the concentration exposure no single vendor review will ever show you.

Scroll for a sample

Third-party risk

Sample · Illustrative
412
third parties in register
67%
tier-1 assessments current
23
critical findings open
61%
critical services on 4 vendors

Assessment currency by tier

Tier 1Tier 2Tier 3 4622883314083 Current Overdue

Suppliers requiring attention

SupplierTierPosition
Core payments processor1Concentration
Managed hosting provider1Overdue
Customer data platform14 findings
Payroll & HR SaaS1No exit plan
Contact centre outsourcer1Overdue
Marketing automation2Breach notice
Logistics integration24th-party
Illustrative. Concentration is the question a regulator asks first.
06

Identity & access.

Standing privilege reduced, orphaned accounts reconciled, leavers actually gone — the work that is always next quarter.

Scroll for a sample

Identity & access posture

Sample · Illustrative
412→68
standing privileged accounts
1,930→0
orphaned accounts
4 hrs
leaver revocation, was 11 days
99.2%
workforce MFA coverage

Privileged accounts by platform — before & after

Windows ADLinuxCloudDatabase Before After

Exceptions requiring a decision

  • Shared service accounts in Payments
    14 accounts, no named owner
  • Contractors with permanent access
    61 identities past contract end
  • Break-glass never tested
    9 accounts across 4 platforms
  • Direct-assigned entitlements
    24% of estate outside the role model
  • Legacy app without SSO
    11 apps, local credentials only
Illustrative. The two numbers an auditor opens with, closed.
07

Cloud security.

Assessed, remediated and re-assessed across every account and workload — the delta proven, not asserted.

Scroll for a sample

Cloud security posture

Sample · Illustrative
132→19
critical misconfigurations
89%
CIS benchmark, from 61%
4/6
landing zones live
71%
workloads on secure pattern

Posture across assess → remediate → re-assess

61748389 BaselineRemediateLanding zonesRe-assess CIS benchmark % Workloads on secure pattern %

Top findings & disposition

FindingSevStatus
Public storage buckets in DigitalCritClosed
Break-glass accounts without MFACritClosed
0.0.0.0/0 ingress on 41 SGsHighIn flight
Logging disabled, 3 prod subsHighClosed
Unencrypted snapshots (Payments)HighIn flight
Stale IAM keys > 365 daysMedBacklog
Illustrative. Each step attributable to a specific piece of work.
08

Security operations.

The two metrics your board actually asks for — mean time to detect and respond — produced, tracked and improved. We run the reporting so your SOC can run the response.

Scroll for a sample

Security operations

Sample · Illustrative
4.2 hrs
mean time to detect, was 9.4
26 hrs
mean time to respond, target 24
78%
MITRE ATT&CK coverage
12%
false-positive rate, was 34

Alert funnel — last 7 days

AlertsAuto-triagedAnalyst-reviewedEscalatedIncidents 12,40011,900460426

Detection coverage by ATT&CK tactic

Initial AccessExecutionPersistencePriv. EscalationLateral MovementExfiltration 82%74%68%71%63%80%
Illustrative. Detection and response, measured and improving — the numbers a board understands.
09

Security engineering.

We don’t hand the finding back — we build and ship the control. Guardrails, automation and detections engineered into your stack, not added to your backlog.

Scroll for a sample

Security engineering delivery

Sample · Illustrative
47
controls shipped this quarter
6 days
mean time to remediate, was 41
92%
IaC guardrail coverage
18
detections shipped as code

Open remediation items — burndown

2101509248 Sprint 1Sprint 2Sprint 3Sprint 4
Not a findings register that grows. A backlog that closes, because the fix ships.

Controls delivered this quarter

ControlLayerStatus
IaC guardrails — deny public storageCloudShipped
CI/CD secret scanningPipelineShipped
Privileged session recordingIdentityShipped
Detection: impossible travelSIEMShipped
Egress filtering baselineNetworkIn build
Auto-revoke stale access keysIdentityIn build
Golden image hardeningComputeShipped
Illustrative. The control built and shipped, not the recommendation handed back.
10

AI governance.

Turn AI governance from a policy document into controls you can deploy, monitor and prove — across every model you build, buy and run.

Scroll to see how

AI governance, operationalized

How it works
1
Govern
Decide & record

Classify what the AI can see, decide and do. Assign a risk tier and record the decision.

2
Architect
Design the controls

Select the right controls across ten pillars, crosswalked to the major AI standards.

3
Engineer
Build on your stack

Turn each control into build-and-deploy code for your stack — IaC, policy, config.

4
Detect
Watch it hold

Generate detections so security operations can see the controls actually holding.

5
Red Team
Prove the exposure

Score real attack paths against your live controls. Mapped to OWASP LLM & MITRE ATLAS.

Aligned to NIST AI RMF · ISO/IEC 42001 · EU AI Act · OWASP LLM · MITRE ATLAS Proof, not paperwork.
11

Incident response & tabletop.

Rehearse the breach before you have one — unannounced, distributed, and written up as a board paper with named owners and dates.

Scroll for a sample

Exercise after-action report

Sample · Illustrative
14
decisions required, 9 made
22 min
to first exec decision, target 15
Missed
regulatory clock, drafted at T+68h
9/9
gaps with a named owner

Executive readiness by capability

Detect & escalateDecideContainCommunicateRegulatoryRecover Observed Required

Top gaps, owners & dates

Gap identifiedOwnerDue
No agreed threshold to take a platform offlineCOO30 days
Regulator notification not pre-delegatedGC30 days
Holding statement not pre-draftedComms45 days
Out-of-band comms channel untestedCIO45 days
Cyber insurer notification path unknownCFO60 days
No criteria to declare recovery completeCIO60 days
Illustrative. Every gap an executive owner, every owner a date — a board paper, not a workshop summary.
05 Enquiries

Fifteen minutes, peer to peer, and no deck.

Tell us what is on your desk this month. If we can take it off you, we will say how — and if it’s not us you need, we will point you to who is.