Keystone Executive gives your security leader independent senior counsel — and carries the reporting, evidence and assurance work that lands on them, and no one else. Alongside your team, under your name.
Deputy CISO, Chief of Staff to the CISO, or no title at all — you choose what fits your structure.
Reporting, metrics, evidence, assurance — the work that is neither strategy nor operations. It has no owner, it lands on the CISO, and it is the layer your whole programme is judged through.
Reporting · Metrics · Evidence · Chasing · Maturity · Spend · Questionnaires · Committee papers — done properly, so your team stays on the other three.
A senior, independent voice to test a position against before you commit it to a board or a regulator.
The fourth load carried to an agreed outcome and a date — the work finished, not the findings handed back.
Where it helps, someone credible alongside you with auditors, regulators and vendors. At your direction, under your name.
Scoped as results, never in hours.
How we resource it is ours to manage.
Not delivered means not invoiced.
Notice either side, everything handed over.
We support the leader you have — never a replacement pitched over your head.
Not the action list. The two hundred hours after it, carried to done.
Working rights in four jurisdictions, follow-the-sun delivery behind them.
Built, with the story behind every number — ready before you’re asked, in language the room already speaks.
| Metric | Now | Target | Trend | Status |
|---|---|---|---|---|
| Critical assets patched ≤ 14 days | 62% | 85% | ▲ | Breach |
| Mean time to detect (hrs) | 9.4 | 4.0 | ▲ | Breach |
| Mean time to respond (hrs) | 26 | 24 | ▲ | Watch |
| Endpoints with EDR coverage | 94% | 98% | ▲ | Watch |
| Privileged accounts under PAM | 58% | 90% | ▬ | Breach |
| Backups restore-tested in period | 81% | 75% | ▲ | Met |
| Staff completing phishing training | 96% | 95% | ▲ | Met |
How your security function is structured, staffed and run — capabilities mapped, decision rights clear, and the gap between today’s model and the one your risk demands made explicit.
| Dimension | Today | Target |
|---|---|---|
| Structure | CISO-centric | Federated + RACI |
| Decision rights | Undefined | Documented ARB |
| Sourcing | All in-house | Core + managed SOC |
| Coverage | Reactive | Service catalogue |
| Reporting | Monthly scramble | Board-ready, automated |
| Talent | Key-person risk | Roles, not heroes |
Scored against NIST CSF and the SCF, with the gaps heat-mapped by business unit so budget goes where it moves the needle.
Collected once, kept current, reused across every framework you report to — so audit season is retrieval, not assembly.
| Control family | Frameworks | Evidence |
|---|---|---|
| Access control & review | 5 | Current |
| Change management | 5 | Current |
| Vulnerability management | 4 | Current |
| Encryption & key handling | 4 | Stale |
| Logging & monitoring | 4 | Current |
| Backup & restore testing | 3 | Stale |
| Supplier management | 3 | Missing |
Tiered, chased and assessed — and the concentration exposure no single vendor review will ever show you.
| Supplier | Tier | Position |
|---|---|---|
| Core payments processor | 1 | Concentration |
| Managed hosting provider | 1 | Overdue |
| Customer data platform | 1 | 4 findings |
| Payroll & HR SaaS | 1 | No exit plan |
| Contact centre outsourcer | 1 | Overdue |
| Marketing automation | 2 | Breach notice |
| Logistics integration | 2 | 4th-party |
Standing privilege reduced, orphaned accounts reconciled, leavers actually gone — the work that is always next quarter.
Assessed, remediated and re-assessed across every account and workload — the delta proven, not asserted.
| Finding | Sev | Status |
|---|---|---|
| Public storage buckets in Digital | Crit | Closed |
| Break-glass accounts without MFA | Crit | Closed |
| 0.0.0.0/0 ingress on 41 SGs | High | In flight |
| Logging disabled, 3 prod subs | High | Closed |
| Unencrypted snapshots (Payments) | High | In flight |
| Stale IAM keys > 365 days | Med | Backlog |
The two metrics your board actually asks for — mean time to detect and respond — produced, tracked and improved. We run the reporting so your SOC can run the response.
We don’t hand the finding back — we build and ship the control. Guardrails, automation and detections engineered into your stack, not added to your backlog.
| Control | Layer | Status |
|---|---|---|
| IaC guardrails — deny public storage | Cloud | Shipped |
| CI/CD secret scanning | Pipeline | Shipped |
| Privileged session recording | Identity | Shipped |
| Detection: impossible travel | SIEM | Shipped |
| Egress filtering baseline | Network | In build |
| Auto-revoke stale access keys | Identity | In build |
| Golden image hardening | Compute | Shipped |
Turn AI governance from a policy document into controls you can deploy, monitor and prove — across every model you build, buy and run.
Classify what the AI can see, decide and do. Assign a risk tier and record the decision.
Select the right controls across ten pillars, crosswalked to the major AI standards.
Turn each control into build-and-deploy code for your stack — IaC, policy, config.
Generate detections so security operations can see the controls actually holding.
Score real attack paths against your live controls. Mapped to OWASP LLM & MITRE ATLAS.
Rehearse the breach before you have one — unannounced, distributed, and written up as a board paper with named owners and dates.
| Gap identified | Owner | Due |
|---|---|---|
| No agreed threshold to take a platform offline | COO | 30 days |
| Regulator notification not pre-delegated | GC | 30 days |
| Holding statement not pre-drafted | Comms | 45 days |
| Out-of-band comms channel untested | CIO | 45 days |
| Cyber insurer notification path unknown | CFO | 60 days |
| No criteria to declare recovery complete | CIO | 60 days |
Tell us what is on your desk this month. If we can take it off you, we will say how — and if it’s not us you need, we will point you to who is.