The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
Where to invest first to take most of the risk off the table.
The name comes from a pattern that repeats in almost every environment: a small fraction of the actions accounts for most of the risk reduction. This engagement exists to find that fraction in your case. We assess where your security stands today, score each discipline, and deliver the plan in the order worth executing, with what to do first separated from what can wait.
We start with what the company already has: documents, configurations, and records, instead of a blank questionnaire. In the full format, we also interview the people who operate and the people who decide, because the document says what should happen and the conversation says what actually happens. Each discipline's score comes from comparing practice against what is expected of it, with the criteria open for you to verify.
On your side, we need access to the evidence, time on the right people's calendars, and a willingness to show the environment as it really is. In the end, the Health Check delivers a quick read organized by the NIST CSF, with the immediate priorities; the full oitenta20 delivers the score per discipline, comparable in the next round, the prioritized plan, and the board presentation. The second one is what sustains the budget conversation.
The stages and deliverables below describe the Full oitenta20® modality. The other modalities appear when you request the proposal.
Evidence gathering
We collect what already exists: documents, configurations and logs. We start from what the company has, rather than from a blank form.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Maturity analysis
We compare the practice with what each discipline calls for and assign the score, with the criteria in the open.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.