One way in.
Three ways to stay.
Every relationship starts by finding out where you actually stand. From there, you decide how much of the work comes off your desk, and pricing follows the scope, shared on request.
First, find out where
you actually stand.
A fixed-scope, four-to-six-week Baseline that turns "we're probably fine" into a number, a priority list, and a plan. Most clients keep going from here, but nothing about it obligates you to.
You walk away with
- Your financial exposure, quantified in dollars
- A 90-day roadmap, priorities ranked by the risk each removes
- The gaps where reported maturity and real exposure diverge
- A first board-ready read on where you stand
Then decide how much
to hand over.
Three retained programs, each a superset of the one before it. Know quantifies and governs. Own runs the program. Prove puts a named leader in front of your board.
| What's included | KnowQuarterly cadence | Most engagedOwnMonthly leadership | ProveFull ownership |
|---|---|---|---|
| Quarterly Cyber Risk Briefing | |||
| Financial Exposure Model | Snapshot | Tolerance tracking | Full trend analysis |
| Risk tolerance & appetite framework | |||
| Monthly Executive Intelligence Brief | — | ||
| Executive reporting cadence | Quarterly | Monthly | Monthly |
| Board briefing | Quarterly | With exec prep | Core3 presents |
| Compliance program management | Advisory | Active | Active |
| Vendor relationship governance | Quarterly | Active | Active |
| Annual tabletop exercise | — | ||
| Named CISO on documentation | — | ||
| Incident response coordination | — | — | |
| AI governance program track | — | — | |
| M&A due diligence support | — | — | Scoped separately |
| Managed security functions | Add-on | Add-on | Add-on |
Pricing is shared on request. Managed security functions are scoped as an add-on at any tier.
What Core3 runs,
end to end.
"Own the program" is not a slogan. Under a retained engagement, this is the work that comes off your desk, directed where teams and vendors already exist, built and run where they don't.
- Cybersecurity strategy & 12-month roadmap
- Program assessment & gap remediation
- Priorities ranked by financial exposure
- Security vendor direction & governance
- Compliance program management
- Policy & governance development
- Audit & customer-review preparation
- Incident response coordination
- Tabletop exercise design
- Third-party risk management
- Executive & board reporting
- Commitment tracking, quarter over quarter
- Insurance & financial-exposure modeling
- Threat & regulatory intelligence
Six months in, the
conversation has changed.
Not a promise, but the operating state Core3 engagements are built to reach by the half-year mark.
- Cyber risk is discussed in business language, not technical language.
- Exposure is quantified in dollars, so leadership sees risk, not heat maps.
- Reporting is decision-ready; whoever holds oversight can actually exercise it.
- The program has a named accountability structure, tracked against outcomes.
- Security spend is mapped to risk reduction: "what did this remove?", not "is it enough?"
- Governance runs on cadence: monthly briefs, quarterly board reviews, an annual plan.
What actually lands
on your desk.
Recurring, and written for executives: the artifacts a board, a CFO, or an investor can read without translation.
- 01
Quarterly Cyber Risk Briefing
All programsFinancial exposure measured against the agreed risk-tolerance threshold, this quarter's priority decision and its reasoning, accountability for last quarter's commitments, and what's being watched but not yet funded. AI risk is modeled natively.
- 02
Monthly Executive Intelligence Brief
Own & ProveWhat changed in the threat and regulatory environment, what it means for this organization specifically, and whether any prior decisions need revisiting, curated and translated for an executive reader.
- 03
Financial Exposure Model
All programsAn actuarially-grounded picture of what a cyber event would actually cost this organization, broken down by loss category and modeled against insurance coverage. The foundation every other deliverable is built on.
- 04
Annual Program Review
All programsOnce a year, a longer-form review of how exposure has moved since the engagement began, which commitments were kept, what the program accomplished, and the following year's priorities.
When cyber lands on
the agenda unexpectedly.
Discrete, time-boxed engagements for a specific moment: a deal, a raise, a review. Often how an organization meets Core3 for the first time.
AI Governance Assessment
Formal review of AI systems, governance gaps, regulatory mapping, and board briefing.
M&A Cyber Due Diligence
Rapid risk assessment, financial exposure model, and integration risk brief.
Managed Security Functions
Discrete security operations run under Core3 direction, added to a program or scoped on their own.
Executive Advisory
On-call executive counsel for an enterprise deal, an LP or board review, or a customer security review.
The Baseline is the
low-commitment way in.
Fixed scope, four to six weeks, one clear deliverable. If a program follows, it follows because you decided it should.