Wyvern assesses security programs against HIPAA, SOC 2, NIST CSF, Essential Eight, ISO 27001 and other frameworks, then builds a remediation plan your team can execute. For companies that need security leadership without a full-time hire, we also work in a fractional CISO capacity.
Most engagements start with an assessment: where your security program stands against the framework you're targeting, and what it will take to close the distance. Many clients keep us on after that for advisory or vCISO work.
We review your administrative, technical and operational controls against HIPAA, NIST CSF, SOC 2, Essential Eight, ISO 27001 or the framework your customers and regulators expect. You get risk-rated findings mapped to the framework's criteria, not a scan report.
After the assessment we build the remediation plan together with your team. Each finding gets an owner, an effort estimate, a timeline and measurable success criteria. Working through it together is a large part of why these plans get followed.
If you need a CISO but can't justify the full-time hire, we step in. We join your leadership team on a fractional basis and own the security function: strategy, risk management, compliance oversight and board reporting.
The threats and compliance expectations vary by industry. Here's where we spend most of our time.
Patient data, HIPAA and HITRUST in the US, the Privacy Act in Australia. Healthcare and biotech companies deal with some of the strictest regulatory scrutiny around. We help build security programs that hold up to it.
Your customers are asking about SOC 2. Your enterprise prospects want to see ISO 27001. We help you get there and make sure your engineering team is building securely along the way.
Fintechs and financial platforms answer to regulators like APRA, banking partners and enterprise customers at the same time. We help you work out which requirements apply and build a program sized to the company.
You need a security program but hiring a CISO doesn't make sense yet. We help you put the foundations in place and get through customer due diligence without derailing your roadmap.
We talk to your leadership and your technical people. We review what you have, compare it to what the frameworks expect, and tell you what to fix first and why.
Remote pre-work and data requests, then an onsite kick-off of up to two days. We meet your team, learn how the business operates and map where sensitive data lives.
Interviews with technical and business stakeholders, documentation review and controls evaluation, all mapped against your target framework. This phase runs mostly remote.
We consolidate findings into a prioritized gap analysis and remediation roadmap. Each item gets an owner, an effort estimate and a definition of done, worked out collaboratively with your team.
An onsite debrief with your leadership and technical teams: a working session to walk through findings, refine priorities and confirm who owns what.
Every assessment produces a defined set of deliverables. These are the standard ones; exact scope depends on the engagement.
A high-level view of findings, risk posture and key recommendations, written for executive and board audiences.
Risk-rated findings across every in-scope domain, with evidence and remediation recommendations mapped to your framework's criteria.
Current controls mapped to HIPAA Security Rule, SOC 2, NIST CSF, Essential Eight or APRA CPS 234 requirements, with identified gaps and recommended actions. NIST CSF engagements include maturity ratings across all five functions.
Phased priorities with assigned owners, effort estimates, timelines and measurable success criteria.
Proposed KPIs and tracking mechanisms for demonstrating security posture improvement to leadership, partners and regulators.
A presentation-ready summary of findings and recommendations, delivered onsite as a working session with your leadership and technical teams.
This kind of work comes down to who's doing it. Here's what you get with us.
Decades in infosec, much of that leading security teams as CISO and VP at companies from early-stage startups to large enterprises.
We've been the first security hire and we've run large security orgs. Either way, you're working with someone who has done this before.
Our reports are written in plain language with clear priorities, so your team can read them and act on them.
HIPAA, HITRUST, SOC 2, ISO 27001, NIST CSF, FedRAMP, Essential Eight, IRAP, ISM, APRA CPS 234. We know what auditors and regulators are looking for, because as practitioners we've sat in the auditee's seat and passed, not just reviewed the findings.
There are no account managers or junior analysts between you and the work. You deal directly with the person doing it.
Most of our clients stick around after the initial assessment. The longer we work together, the better we know your environment.