What We Deliver
Services
TMCP delivers hands-on execution across the full spectrum of cybersecurity and governance, risk, and compliance programs. Every engagement is led by a CISSP/CISM-certified principal and supported by a vetted network of specialists.
vCISO / Fractional CISO
Who It’s For
Growing organizations that need a Chief Information Security Officer but are not ready for a full-time hire. Ideal for startups scaling into enterprise, mid-market companies facing compliance pressure, and organizations preparing for their first audit or certification.
What’s Included
- —Ongoing security strategy and program roadmap development
- —Executive and board-level advisory and reporting
- —Security program maturity assessment and improvement
- —Vendor and security tool evaluation and oversight
- —Policy governance and compliance program ownership
- —Incident coordination, escalation leadership, and tabletop facilitation
- —Representation in client, investor, and regulatory conversations
Expected Outcomes
A fully functioning, maturing security program led by a CISSP/CISM-certified executive at a fraction of full-time cost.
Engagement Model
Monthly retainer
Investment Range
$3,500 – $8,000 / month
ISO 27001 Implementation
Who It’s For
Organizations seeking ISO 27001 certification for competitive advantage, enterprise client requirements, or regulatory alignment. Common in technology, SaaS, financial services, and healthcare-adjacent industries.
What’s Included
- —ISMS design and implementation
- —Risk assessment and risk treatment plan development
- —Security policy and control documentation
- —Control implementation guidance and evidence collection
- —Internal audit preparation and readiness assessment
- —External auditor coordination through Stage 1 and Stage 2
- —Post-certification maintenance planning
Expected Outcomes
Full ISO 27001 certification. TMCP has personally led and completed this process for multiple organizations including an AI-specific ISMS for a next-generation AI company.
Engagement Model
Project-based
Investment Range
$15,000 – $35,000
SOC 2 Readiness
Who It’s For
Technology companies, SaaS providers, and service organizations that need to demonstrate security controls to enterprise customers, investors, or partners.
What’s Included
- —SOC 2 Trust Services Criteria gap assessment
- —Control design and implementation guidance
- —Evidence collection program setup and management
- —Auditor-ready documentation package
- —Coordination with your chosen audit firm
- —SOC 2 Type I and Type II readiness support
Expected Outcomes
Audit-ready posture for SOC 2 Type I or Type II. TMCP has completed SOC 2 Type I and led active Type II readiness programs.
Engagement Model
Project-based
Investment Range
$12,000 – $28,000
Incident Response Planning
Who It’s For
Any organization that wants to be prepared — not reactive — when a security incident occurs. Especially valuable for organizations handling sensitive data or operating in regulated industries.
What’s Included
- —Incident Response Plan development tailored to your environment
- —Playbook creation: ransomware, data breach, account compromise, insider threat
- —Roles and responsibilities matrix
- —Communication templates and escalation procedures
- —Tabletop exercise design and facilitation
- —Post-incident review and lessons learned framework
Expected Outcomes
A tested, documented IR capability that reduces response time and limits business impact.
Engagement Model
Project-based
Investment Range
$5,000 – $12,000
HIPAA / HITRUST Compliance
Who It’s For
Healthcare organizations, health technology companies, and business associates subject to HIPAA or client-mandated HITRUST assessments.
What’s Included
- —HIPAA Security Rule gap assessment
- —Remediation planning and control implementation
- —HIPAA policy and procedure development
- —HITRUST CSF assessment scoping and preparation
- —Evidence collection and remediation management
- —HITRUST Validated Assessment coordination
- —Ongoing compliance monitoring guidance
Expected Outcomes
Documented HIPAA compliance posture and successful HITRUST Validated Assessment. TMCP has directed the full HITRUST process and built the accompanying security program from scratch for a regulated healthcare organization.
Engagement Model
Project-based
Investment Range
$15,000 – $40,000
Vendor Risk Management
Who It’s For
Organizations with third-party vendors, SaaS providers, or supply chain dependencies that carry security or compliance risk.
What’s Included
- —Third-party risk management program design
- —Vendor tiering and risk classification framework
- —Vendor security assessment questionnaire development
- —Risk scoring methodology and remediation tracking
- —Ongoing vendor monitoring process design
- —Contract and SLA security review guidance
Expected Outcomes
A structured, repeatable vendor risk program that protects your organization and satisfies auditor requirements.
Engagement Model
Project or retainer
Investment Range
$4,000 – $10,000
Security Policy Development
Who It’s For
Organizations without formal security documentation or those preparing for their first audit or certification.
What’s Included
- —Written Information Security Program (WISP)
- —Complete core policy suite: Acceptable Use, Data Classification, Access Control, Data Retention, Incident Response, Remote Work, Password Management, BYOD, Vendor Management, and more
- —Standards and procedures aligned to ISO 27001, NIST CSF, SOC 2, or HITRUST
- —Policy review and approval workflow design
- —Employee acknowledgment process
Expected Outcomes
A complete, audit-ready policy library tailored to your organization — not boilerplate.
Engagement Model
Project-based
Investment Range
$5,000 – $15,000
Security Awareness Training
Who It’s For
Organizations that want to reduce human risk through an educated, security-aware workforce.
What’s Included
- —Security awareness program design and annual content calendar
- —New-hire security onboarding training
- —Role-based training for high-risk roles
- —Phishing simulation campaign planning and execution
- —Security culture assessment and baseline metrics
- —Reporting and participation tracking
Expected Outcomes
Measurable reduction in human-risk indicators. TMCP has designed and delivered awareness programs for organizations ranging from 200 to 22,000 employees.
Engagement Model
Annual program
Investment Range
$4,000 – $10,000 / year
Ready to get started?
Schedule a complimentary discovery call to discuss your needs.
Schedule a Discovery Call →