Governance isthe keystone.
We help credit unions, school districts, local governments and growing businesses see their security gaps clearly, close them with confidence, and stay ready for the examiner, the auditor and whatever comes next.
- Personally ledOne advisor from the first conversation to the final report
- Evidence-basedEvery finding verified, every fix confirmed
- Fixed feeScoped and quoted before work begins
- HIPAA
- PCI DSS
- NIST CSF 2.0
- NCUA Part 748 & ACET
- FTC Safeguards Rule
- FERPA
- ISO 27001
- SOC 2
Most organizations know where some of their gaps are. The hard part is having the time and support to close them.
The people protecting credit unions, schools, townships and small businesses care deeply about the communities they serve. What they often lack isn't awareness; it's a clear path forward and someone in their corner to help them act on it.
That's why The Cyber Governance Group exists, and why we built our own tools: so every hour of an engagement goes toward making you more secure, not toward paperwork.
Our storyEverything a strong program needs.
From the first assessment to the board report a year later: one accountable advisor across risk, compliance, technical validation and ongoing oversight.
All servicesRisk & compliance assessments
Advisor-led assessments with hands-on technical validation. Findings are risk-rated, evidence-backed and written in your regulator's terms.
- Framework and risk assessments
- Vulnerability and configuration review
- Examiner-ready reporting
Fractional CISO
A seasoned security executive on a fractional basis: strategy, risk decisions, budget priorities and accountability for the program between audits.
- Security strategy and roadmap
- Board and committee reporting
- Examiner and insurer engagement
Remediation management
A managed path from finding to closure: owners and deadlines, implementation guidance, and verification of every fix.
- Prioritized remediation roadmap
- Progress tracking and escalation
- Verified closure, evidence on file
Security program development
Policies, standards, plans and records developed from assessed reality and mapped to the requirements they satisfy.
- Policy and standards framework
- System security plans and POA&Ms
- Risk and vendor registers
Incident readiness & response
Response plans mapped to every notification deadline you face, and clear decision support when an incident happens.
- Incident response planning
- Notification deadline mapping
- Breach notification governance
Third-party risk
Due diligence on the vendors that hold your data, and credible answers when your own customers send a security questionnaire.
- Vendor due diligence and tiering
- BAA, data-sharing and attestation tracking
- Customer questionnaire response
Four sectors. One standard of care.
Each answers to different regulators, examiners and stakeholders. The methodology is consistent; the obligations, language and priorities are specific to yours.
IndustriesCredit unions
Information security programs that stand up to NCUA examination, with board oversight that is informed and documented.
- NCUA Part 748
- ACET
- Board reporting
School districts
Protecting student and staff data across dozens of ed-tech platforms, with a program built on your terms ahead of rising expectations.
- FERPA
- Student data privacy
- Ed-tech vendors
Counties & municipalities
Resilience for dispatch, utilities and public records, and a budget-ready roadmap commissioners and councils can act on.
- NIST CSF 2.0
- Critical services
- Public records
Small & mid-sized businesses
Healthcare practices, retail and hospitality, financial services firms and vendors to regulated organizations.
- HIPAA
- PCI DSS
- FTC Safeguards
- Cyber insurance
Start where it makes sense. Build from there.
Every engagement is scoped and quoted as a fixed fee before work begins. Most organizations start with an assessment; many continue with ongoing fractional CISO support.
How engagements workSecurity Baseline Assessment
A focused assessment of your core controls and external exposure: a fast, defensible view of where you stand.
- Risk-rated findings across core control areas
- External exposure and Microsoft 365 review
- Prioritized 90-day action plan
- Executive briefing
Program Assessment & Development
A full, advisor-led assessment against the frameworks you answer to, and the program foundation that follows from it.
- Framework assessment with technical validation
- Risk register and plan of action
- Core policies, plans and standards
- Board-ready report and briefing
Fractional CISO
Ongoing executive leadership, with remediation managed to verified closure and the program kept current.
- A named security executive
- Remediation management and verification
- Board, examiner and insurer engagement
- Threat and regulatory monitoring
Targeted engagements
Defined projects for a specific deadline, requirement or stakeholder request.
- Incident response plan
- Vendor risk program
- Exam, audit or questionnaire readiness
- ITP-SEC023 independent assessment
Let's set the keystone.
A 30-minute conversation about your obligations, your environment and what's driving the timing. No cost and no obligation.