We stay close to a small number of verticals so we can be useful, not generic.
Banking, payments, wealth-tech, insurance carriers. About 42% of our engagements. We understand SOC 1, SOC 2, PCI DSS 4.0, NYDFS Part 500, and the OCC's expectations for third-party risk. Our senior consultants have worked inside financial regulators or the CISO office of tier-1 banks.
Provider networks, digital-health SaaS, medical-device firmware, claims platforms. Roughly 20% of our work. HIPAA §164.308, HITRUST, FDA premarket cybersecurity guidance. We hold BAAs with all major healthcare clients.
B2B SaaS moving upmarket. About 25% of our work. Common ask: prepare the security story for enterprise procurement, close the gaps a Fortune 500 CISO will actually check on the questionnaire.
Selective engagements only, US-cleared personnel available. FedRAMP High, CMMC Level 2/3, DFARS 7012. Roughly 8% of our work. Not our main focus, but where we go we go deep.
Every report is cross-referenced to the controls your auditor will ask about.
| Framework | Controls we address | Common use |
|---|---|---|
| SOC 2 (Trust Services) | CC7.1, CC7.2, CC7.3, CC7.4, CC8.1 | Annual pentest, vuln management |
| PCI DSS 4.0 | 11.3, 11.4, 6.2, 6.3 | Annual & post-change pentesting for CDE |
| ISO/IEC 27001:2022 | A.5.7, A.8.8, A.8.29 | ISMS security testing evidence |
| HIPAA Security Rule | §164.308(a)(1)(ii)(A), §164.308(a)(8) | Risk analysis, evaluation |
| NIST CSF 2.0 | ID.RA, PR.IP-12, DE.CM, RS | Cybersecurity risk-management program |
| NYDFS 23 NYCRR 500 | §500.5, §500.16 | Annual penetration testing |
| FedRAMP | CA-8, RA-5 | Annual authorization testing |
| CMMC 2.0 Level 2 | CA.L2-3.12.1, RM.L2-3.11.2 | Assessment support |
Not on the list? Ask us — we've likely cross-mapped to it before.