the practice
a structural analogy
No contractor can credibly serve as their own assurance function. Large construction projects accepted this decades ago and instituted a distinct seat for it.
The Owner's Engineer writes the brief, governs the RFP, oversees delivery against the spec, and signs off commissioning. They do not pour concrete. They do not draw the plans. They make sure the right concrete is poured against the right plans, and that there is a record of it.
Our work in cybersecurity programmes is the same shape. The reference points and the artefacts are different. The seat is identical.
i — readiness
Most programmes are won or lost before the first statement of work is signed. The buyer either knows what good looks like, or they don't, and the implementer responds accordingly.
We translate the regulatory exposure into a defensible target operating model — not an aspirational one, not a vendor's reference architecture, but a model the firm can plausibly run after we are gone. We scope what is and is not in the programme, because what is excluded matters as much as what is included. We qualify implementers against the brief, not against each other's deck. We validate the procurement package before it leaves the building.
The output is a buyer who has done their prior work. Implementers respond to that buyer differently.
deliverables
ii — decision facilitation
A live programme generates decisions faster than the buyer can absorb them. The implementer is paid to move. The buyer is paid to be right. Those two clocks do not synchronise on their own.
We sit between the buyer and the implementer, and we frame decisions cleanly. What is being decided. What the alternatives are. What each alternative costs — in money, in time, and in residual risk. What the recommendation is, and why. What the dissenting view is, and from whom.
The artefact is a steering minute that reads, eighteen months later, like a record a sensible person would stand behind. That is harder than it sounds, and it is the work.
deliverables
iii — stabilisation
Go-live is not the end of a programme. It is the beginning of the period the auditor will eventually examine. Most programmes never produce the document they will need at that point.
We rehearse the operating cadence with the team that will run it. We close out residual risk against the original target, not against a quietly relaxed version of it. We assemble the control-evidence binder while the evidence is still warm, and we hand over a pack the firm can give its auditor twelve months later without flinching.
This is the work most often skipped, and the work most often regretted.
deliverables