780.235.5413 Ian@secbrains.com


SERVICES THAT TURN
CYBERSECURITY NOISE


INTO PRACTICAL
DECISIONS.

Our services are built to create clarity, not just more findings.

NIST-BASED. AI-ENHANCED. HUMAN-CONTROLLED

TWO CORE SERVICES. ONE GOAL:CLARITY.

CYBERSECURITY
CONTROLS ASSESSMENT

Two frameworks. One service.

A facilitated, NIST CSF and CIS informed assessment delivered through human-led workshops, connecting cybersecurity maturity, operational reality, practical control effectiveness, and business priorities.

Establish a realistic current-state view

Guided workshops to determine maturity of important controls and their governance

Identify what matters most

Create a practical improvement roadmap

Where are we now?
WHAT NEEDS ADDRESSING?

Best for organizations that need a clear view of where they stand and what should happen next

Marty, Founder and Product Strategy/Security Officer


EXPLORE CONTROLS ASSESSMENT

AI GOVERNANCE
WORKSHOP

Practical guardrails. Responsible adoption.

Understand how AI is being used across the organization, identify governance, accountability, and risk gaps, and establish practical guardrails for acceptable use, data handling, oversight, and responsible adoption.

Clarify accountability and acceptable use

Address shadow AI and data-handling concerns

Identify governance gaps and priority actions

Create a practical governance pathway

WHAT AI GOVERNANCE GAPS EXIST?
HOW DO WE ADDRESS THEM?

Best for organizations adopting AI faster than their governance can keep up.

Marty, Founder and Product Strategy/Security Officer


EXPLORE AI GOVERNANCE

NOT SURE WHICH SERVICE FITS?

Need a broad view of maturity, risk, and priorities?

Start with the
Cybersecurity Controls Assessment

You receive

A facilitated, evidence-informed view of your current maturity

Clear findings on what is working, what is inconsistent, and where risk remains

Prioritized recommendations and a practical improvement roadmap

Point 3

Need to bring order to fast-moving AI adoption and understand the risk it creates?

Start with the AI Governance workshop


You receive

A clear picture of how AI is being used across the organization

Identified gaps in ownership, acceptable use, data handling, and oversight

Practical guardrails and a prioritized governance pathway

You can do one or the other
But they're really good together!

We completed both engagements, and the overlap was really valuable. The AI Governance workshop reinforced some of the third-party and supplier risk concerns identified during the Controls Assessment, which helped us see the issues in a much more connected way.


IT Manager
Oil & Gas Services

additional ways we help.

Microsoft architecture
& vCISO services

Senior Microsoft architecture expertise and vCISO leadership to strengthen resilience, security, and business continuity.

Microsoft infrastructure & cloud architecture

Identity, authentication and platform design

Business continuity & minimal viable company design & roadmap

vCISO leadership & strategic guidance

Architecture review & advisory

Getting the cloud architecture right is critical to building a strong security foundation. Identity, authentication, resilient backup, and recovery all need to work together as part of a coherent design. Our architecture and extended security team brings more than 100 years of combined industry experience.


Marty, Founder and Product Strategy/Security Officer


DISCUSS ARCHITECTURE & vCISO SERVICES WITH THE TEAM

WORKSHOPS &
TABLETOP EXERCISES

Facilitated sessions that align teams, challenge assumptions, and test how your plans perform under pressure.

Zero Trust Readiness Workshop

OT Governance Workshop

Cybersecurity Tabletop exercises

Custom leadership & technical workshops

Best for organizations that need alignment, practical discussion, or a safe way to test readiness


Ian, Founder and Sales & Marketing Strategy


DISCUSS WORKSHOPS & TABLETOPS WITH THE TEAM →

 

RISK ANALYSIS & RISK REGISTER DEVELOPMENT

Facilitated risk workshops, scenario analysis, and risk register development in business language — so leaders can prioritize what matters most.

WHY CLIENTS COME TO SECBRAINS.

nodding heads

We explain things in plain English

respectful CURIOSITY

We challenge bias and assumptions

practical FOCUS

We highlight what's important

rubber hits the road

We produce outputs people can actually use

NOT ANOTHER SELF ASSESSMENT
GUIDED DISCUSSIONS. MEANINGFUL OUTCOMES.

IF YOU WANT ANOTHER GENERIC CYBER PAGE,
THIS PROBABLY ISN’T IT.

WE DON’T SELL TOOLS.

We bring experience, ask the right questions,
and help you make better decisions.

We provide clearer priorities, better conversations, and practical guidance.

LET'S HAVE A BETTER CONVERSATION.

CLARITY. PRIORITIES. PROGRESS.

NIST BASED. AI ENHANCED. HUMAN CONTROLLED

How would you like to connect?

Send us a note or choose a time that works for you.

Send us a message

Tell us what you’re working through and we’ll get back to you.

By submitting this form, you agree that SecBrains may use the information you provide to respond to your inquiry. Please see our Privacy Policy for more information.

Book a conversation

Choose a time that works for you.

What would you like to see?

Explore how we work, or take a look at a sample deliverable.

CYBERSECURITY CONTROLS ASSESSMENT

Know where you stand — and what should happen next

A practical, management-focused assessment that turns cybersecurity controls, maturity, and operational reality into clearer priorities for leadership.

Most organizations already have security controls, technologies, policies, suppliers, and improvement initiatives in place. The harder question is whether those controls are consistently implemented, appropriately governed, and addressing the risks that matter most to the business.

SecBrains brings experienced facilitators together with your IT, security, and business stakeholders to work through that question. Our approach uses the NIST Cybersecurity Framework and CIS Controls as complementary lenses, supported by curated validation questions and operational discussion.

This is not a technical audit and it is not another generic checklist. The objective is to understand the organization’s current control maturity, challenge important assumptions, identify meaningful gaps, and turn the findings into practical management action.

What we look at

  • Cybersecurity control maturity and implementation
  • Governance, ownership, and accountability
  • Operational assurance and important control assumptions
  • Credible cybersecurity risk scenarios
  • Where improvement effort will have the greatest value

What you receive

  • An executive view of cybersecurity maturity
  • Prioritized risk and control observations
  • Top improvement priorities
  • A practical improvement roadmap
  • Detailed NIST CSF and control-domain analysis
  • Clearer linkage between cybersecurity activity and business risk
Two frameworks. One service. NIST-based. CIS-informed. AI-enhanced. Human-controlled.
Discuss a Controls Assessment →
AI GOVERNANCE WORKSHOP

Put practical guardrails around AI — without stopping adoption

Understand how AI is actually being used, where the important governance gaps exist, and what practical controls should come next.

AI adoption rarely waits for a complete governance program. Employees experiment with new tools, business teams find useful applications, vendors introduce AI capabilities, and sensitive information can begin moving through services that were never formally reviewed.

The challenge is not simply whether AI should be used. It is establishing enough visibility, ownership, and practical guidance that the organization can use AI confidently without creating unnecessary risk.

SecBrains facilitates a structured discussion across technology, security, privacy, governance, and business stakeholders. We help uncover where AI is already being used, identify areas of uncertainty, and establish realistic guardrails that support responsible adoption rather than simply producing another policy document.

What we look at

  • Current and emerging AI use across the organization
  • Ownership, accountability, and decision authority
  • Acceptable use and employee guidance
  • Shadow AI and unapproved tools
  • Data handling, privacy, and information exposure
  • Third-party and embedded AI capabilities
  • Oversight, review, and ongoing governance

What you receive

  • A clear view of current AI governance posture
  • Priority governance and risk gaps
  • Practical recommendations for responsible adoption
  • Defined areas of ownership and accountability
  • Guidance for acceptable use and data handling
  • A practical roadmap for strengthening AI governance
Practical guardrails. Responsible adoption. Governance that helps the business use AI — not governance that simply tells people not to.
Discuss AI Governance →
HIGHER EDUCATION

Strong security controls. Less clarity about what should come next.

This higher-education organization had invested in solid cybersecurity capabilities. The challenge was understanding how those controls came together, where meaningful gaps remained, and which issues deserved leadership attention first.

The situation

The institution operated in a heavily cloud- and SaaS-dependent environment supporting learning, administrative, financial, and student-facing services.

Operational security was stronger than the overall maturity score might initially suggest. Multi-factor authentication was enforced across the user population, endpoint detection and response coverage exceeded 95%, 24×7 managed detection and response was in place, and backups were immutable and logically separated.

What was less mature was the governance wrapped around those capabilities. Executive accountability, enterprise risk integration, access governance, third-party oversight, and coordinated recovery planning were not yet consistently institutionalized.

What SecBrains did

SecBrains facilitated three structured workshops using the NIST Cybersecurity Framework 2.0 together with an operational control lens. Governance and cybersecurity maturity were examined alongside the way controls actually operated day to day.

Rather than producing another undifferentiated list of findings, the assessment connected maturity, operational reality, institutional dependencies, and business consequences.

What became clear

  • Overall cybersecurity maturity was assessed at 2.4 out of 5, with a Defined maturity level of 3 identified as the next practical target.
  • Operational safeguards were comparatively strong, while governance and incident-response maturity lagged behind.
  • Identity represented a critical security boundary because of the institution's extensive reliance on SaaS and federated access.
  • Third-party and SaaS dependencies required stronger lifecycle governance and recovery assurance.
  • Technical recovery capabilities existed, but coordinated business recovery expectations, sequencing, and decision authority needed greater structure.

The priorities

The assessment distilled the findings into five leadership priorities:

  1. Establish executive cybersecurity accountability and oversight.
  2. Build a formal workforce security awareness and readiness program.
  3. Implement role-based access and privilege governance.
  4. Integrate cybersecurity risk into enterprise risk management.
  5. Establish third-party risk governance and ongoing monitoring.

From findings to action

Those priorities were translated into a sequenced roadmap beginning with governance and decision authority, then reducing identity, SaaS, and supplier exposure, and finally strengthening monitoring, response, and recovery assurance.

The value wasn't another security score. It was a clearer view of what mattered, why it mattered, and what the organization should do next.
SecBrains helped us cut through the noise, align our leadership team, and focus on the issues that actually move the needle. IT Manager, Higher Education Sector
DISCUSS A CONTROLS ASSESSMENT →