The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
Before buying tooling, decide the order.
The security master plan answers three questions in the right order: where your security stands today, where it needs to go, and which sequence of investments connects one to the other. We measure maturity against a recognized framework and deliver the initiatives prioritized by risk and by cost, with what to do this quarter separated from what can wait.
The reading comes from two sources that rarely tell the same story: interviews with the people who operate and conversations with the people who decide. The target is validated with leadership, because how far to invest is a business decision, not a technical choice. The final text is written for whoever signs the budget, with no translation needed from someone in the field.
The difference between tiers is what happens after delivery. In the format with follow-through, we hold execution accountable, remeasure maturity with the same method, and bring the number back to the board, which is what separates having a plan from being able to show it moved.
We will need time with operations and leadership, access to the evidence, and candor about budget and constraints, because a plan that ignores the real constraint never leaves the paper. You receive a score comparable in the next round, the prioritized plan, and the evolution roadmap for the following period.
The stages and deliverables below describe the Plan with execution follow up modality. The other modalities appear when you request the proposal.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Opening assessment
A snapshot of the starting point: what exists, what is written down and what actually works. Progress will be measured against it at the end of the period, so we record it with method, not from memory.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Validation with the board
We take the result to the people who decide. Recovery time is a business decision rather than a technical choice.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
Executive follow-up
A weekly meeting with the leadership, a monthly report and an alert when something changes. The rhythm is what moves security forward between one meeting and the next.
Proof of progress
A fresh assessment, a side by side comparison and a presentation of what changed in the period, with evidence.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.