One way in.
Three ways to stay.

Every relationship starts by finding out where you actually stand. From there, you decide how much of the work comes off your desk, and pricing follows the scope, shared on request.

First, find out where
you actually stand.

A fixed-scope, four-to-six-week Baseline that turns "we're probably fine" into a number, a priority list, and a plan. Most clients keep going from here, but nothing about it obligates you to.

Cyber Risk Baseline · 4–6 weeks · one time

You walk away with

  • Your financial exposure, quantified in dollars
  • A 90-day roadmap, priorities ranked by the risk each removes
  • The gaps where reported maturity and real exposure diverge
  • A first board-ready read on where you stand

Then decide how much
to hand over.

Three retained programs, each a superset of the one before it. Know quantifies and governs. Own runs the program. Prove puts a named leader in front of your board.

What's included KnowQuarterly cadence Most engagedOwnMonthly leadership ProveFull ownership
Quarterly Cyber Risk Briefing
Financial Exposure ModelSnapshotTolerance trackingFull trend analysis
Risk tolerance & appetite framework
Monthly Executive Intelligence Brief
Executive reporting cadenceQuarterlyMonthlyMonthly
Board briefingQuarterlyWith exec prepCore3 presents
Compliance program managementAdvisoryActiveActive
Vendor relationship governanceQuarterlyActiveActive
Annual tabletop exercise
Named CISO on documentation
Incident response coordination
AI governance program track
M&A due diligence supportScoped separately
Managed security functionsAdd-onAdd-onAdd-on

Pricing is shared on request. Managed security functions are scoped as an add-on at any tier.

What Core3 runs,
end to end.

"Own the program" is not a slogan. Under a retained engagement, this is the work that comes off your desk, directed where teams and vendors already exist, built and run where they don't.

  • Cybersecurity strategy & 12-month roadmap
  • Program assessment & gap remediation
  • Priorities ranked by financial exposure
  • Security vendor direction & governance
  • Compliance program management
  • Policy & governance development
  • Audit & customer-review preparation
  • Incident response coordination
  • Tabletop exercise design
  • Third-party risk management
  • Executive & board reporting
  • Commitment tracking, quarter over quarter
  • Insurance & financial-exposure modeling
  • Threat & regulatory intelligence

Six months in, the
conversation has changed.

Not a promise, but the operating state Core3 engagements are built to reach by the half-year mark.

  • Cyber risk is discussed in business language, not technical language.
  • Exposure is quantified in dollars, so leadership sees risk, not heat maps.
  • Reporting is decision-ready; whoever holds oversight can actually exercise it.
  • The program has a named accountability structure, tracked against outcomes.
  • Security spend is mapped to risk reduction: "what did this remove?", not "is it enough?"
  • Governance runs on cadence: monthly briefs, quarterly board reviews, an annual plan.

What actually lands
on your desk.

Recurring, and written for executives: the artifacts a board, a CFO, or an investor can read without translation.

  1. 01

    Quarterly Cyber Risk Briefing

    All programs

    Financial exposure measured against the agreed risk-tolerance threshold, this quarter's priority decision and its reasoning, accountability for last quarter's commitments, and what's being watched but not yet funded. AI risk is modeled natively.

  2. 02

    Monthly Executive Intelligence Brief

    Own & Prove

    What changed in the threat and regulatory environment, what it means for this organization specifically, and whether any prior decisions need revisiting, curated and translated for an executive reader.

  3. 03

    Financial Exposure Model

    All programs

    An actuarially-grounded picture of what a cyber event would actually cost this organization, broken down by loss category and modeled against insurance coverage. The foundation every other deliverable is built on.

  4. 04

    Annual Program Review

    All programs

    Once a year, a longer-form review of how exposure has moved since the engagement began, which commitments were kept, what the program accomplished, and the following year's priorities.

When cyber lands on
the agenda unexpectedly.

Discrete, time-boxed engagements for a specific moment: a deal, a raise, a review. Often how an organization meets Core3 for the first time.

AI Governance Assessment

Formal review of AI systems, governance gaps, regulatory mapping, and board briefing.

M&A Cyber Due Diligence

Rapid risk assessment, financial exposure model, and integration risk brief.

Managed Security Functions

Discrete security operations run under Core3 direction, added to a program or scoped on their own.

Executive Advisory

On-call executive counsel for an enterprise deal, an LP or board review, or a customer security review.

The Baseline is the
low-commitment way in.

Fixed scope, four to six weeks, one clear deliverable. If a program follows, it follows because you decided it should.