WHO
A head of security GRC under the CISO, with an established SOC 2 programme and a prior audit to compare against. You already have a platform, a register and an auditor. What you do not have is a consequential answer to whether the controls you report on still deliver the protection your programme relies on.
THE FOUR WINDOWS
01 recon
Free discovery, 45 minutes. We start from your risk register as it is, even stale, and enrich it with breaches at comparable companies, breaches involving your vendors, the data you hold and, where you authorise it, your incident records. Each top risk becomes a handful of concrete scenarios, attack and failure paths alike, and each scenario names the protection it requires and the controls that claim to provide it, whether or not your framework lists them. Output: which claims to hunt, for which systems and period, and where the evidence gaps are.
02 hunt
Fixed fee, the full agreed SOC 2 scope, two stages across the audit period. Each control claim is marked into positions and each position is attacked with your own records under scoped, time-bounded, authorised access. Population completeness, period coverage, the intended protection, and exceptions and bypass paths are part of every procedure. Documents, interviews and observation stay in the method where an API cannot answer.
03 challenge
A named reviewer attacks our answer before you see it: favourable conclusions, false alarms, procedure adequacy. Missing evidence stays an unknown and is never counted as a pass. “Procedure completed, but no conclusion was issued” is a legitimate result, and you will see it when it is the true one.
04 debrief
One assessment, several views. Your team gets broke, held and open per control with confidence printed and a remediation order. Risk owners get the positions, which are the assumptions inside your register, with what held and what did not. The board gets material findings, uncertainty and progress on one page. Engineering gets the trace: exact payload, exact record, exact assertion, so AppSec and infrastructure can reperform it and argue with it.
THEN
You remediate; we retest once within the agreed window and record the change without erasing the original finding. You finish with a complete handover and no retainer. When your auditor arrives, they get the handover package and decide what to reuse.
YOURS
Your GRC platform, your risk register, your control operation, risk acceptance and remediation decisions. We take responsibility for the examination and its conclusions, and we are paid for completed examination whatever it finds.
NOT
A tool to operate, continuous monitoring, a hosted trust centre, remediation done for you, a penetration test, or an attestation. If you want software, this is the wrong product.
WHY A TEAM BUYS IT
- Readiness with evidence instead of a checklist: the claim, the position, the payload and the result, in that order.
- A credible answer for technical leadership, because every result is reperformable from the trace.
- A remediation list ordered by what actually broke against a real risk, not by control count.
- A named human accountable for the answer, and a second one accountable for attacking it.