TMCP

What We Deliver

Services

TMCP delivers hands-on execution across the full spectrum of cybersecurity and governance, risk, and compliance programs. Every engagement is led by a CISSP/CISM-certified principal and supported by a vetted network of specialists.

vCISO / Fractional CISO

Who It’s For

Growing organizations that need a Chief Information Security Officer but are not ready for a full-time hire. Ideal for startups scaling into enterprise, mid-market companies facing compliance pressure, and organizations preparing for their first audit or certification.

What’s Included

  • Ongoing security strategy and program roadmap development
  • Executive and board-level advisory and reporting
  • Security program maturity assessment and improvement
  • Vendor and security tool evaluation and oversight
  • Policy governance and compliance program ownership
  • Incident coordination, escalation leadership, and tabletop facilitation
  • Representation in client, investor, and regulatory conversations

Expected Outcomes

A fully functioning, maturing security program led by a CISSP/CISM-certified executive at a fraction of full-time cost.

Engagement Model

Monthly retainer

Investment Range

$3,500 – $8,000 / month

ISO 27001 Implementation

Who It’s For

Organizations seeking ISO 27001 certification for competitive advantage, enterprise client requirements, or regulatory alignment. Common in technology, SaaS, financial services, and healthcare-adjacent industries.

What’s Included

  • ISMS design and implementation
  • Risk assessment and risk treatment plan development
  • Security policy and control documentation
  • Control implementation guidance and evidence collection
  • Internal audit preparation and readiness assessment
  • External auditor coordination through Stage 1 and Stage 2
  • Post-certification maintenance planning

Expected Outcomes

Full ISO 27001 certification. TMCP has personally led and completed this process for multiple organizations including an AI-specific ISMS for a next-generation AI company.

Engagement Model

Project-based

Investment Range

$15,000 – $35,000

SOC 2 Readiness

Who It’s For

Technology companies, SaaS providers, and service organizations that need to demonstrate security controls to enterprise customers, investors, or partners.

What’s Included

  • SOC 2 Trust Services Criteria gap assessment
  • Control design and implementation guidance
  • Evidence collection program setup and management
  • Auditor-ready documentation package
  • Coordination with your chosen audit firm
  • SOC 2 Type I and Type II readiness support

Expected Outcomes

Audit-ready posture for SOC 2 Type I or Type II. TMCP has completed SOC 2 Type I and led active Type II readiness programs.

Engagement Model

Project-based

Investment Range

$12,000 – $28,000

Incident Response Planning

Who It’s For

Any organization that wants to be prepared — not reactive — when a security incident occurs. Especially valuable for organizations handling sensitive data or operating in regulated industries.

What’s Included

  • Incident Response Plan development tailored to your environment
  • Playbook creation: ransomware, data breach, account compromise, insider threat
  • Roles and responsibilities matrix
  • Communication templates and escalation procedures
  • Tabletop exercise design and facilitation
  • Post-incident review and lessons learned framework

Expected Outcomes

A tested, documented IR capability that reduces response time and limits business impact.

Engagement Model

Project-based

Investment Range

$5,000 – $12,000

HIPAA / HITRUST Compliance

Who It’s For

Healthcare organizations, health technology companies, and business associates subject to HIPAA or client-mandated HITRUST assessments.

What’s Included

  • HIPAA Security Rule gap assessment
  • Remediation planning and control implementation
  • HIPAA policy and procedure development
  • HITRUST CSF assessment scoping and preparation
  • Evidence collection and remediation management
  • HITRUST Validated Assessment coordination
  • Ongoing compliance monitoring guidance

Expected Outcomes

Documented HIPAA compliance posture and successful HITRUST Validated Assessment. TMCP has directed the full HITRUST process and built the accompanying security program from scratch for a regulated healthcare organization.

Engagement Model

Project-based

Investment Range

$15,000 – $40,000

Vendor Risk Management

Who It’s For

Organizations with third-party vendors, SaaS providers, or supply chain dependencies that carry security or compliance risk.

What’s Included

  • Third-party risk management program design
  • Vendor tiering and risk classification framework
  • Vendor security assessment questionnaire development
  • Risk scoring methodology and remediation tracking
  • Ongoing vendor monitoring process design
  • Contract and SLA security review guidance

Expected Outcomes

A structured, repeatable vendor risk program that protects your organization and satisfies auditor requirements.

Engagement Model

Project or retainer

Investment Range

$4,000 – $10,000

Security Policy Development

Who It’s For

Organizations without formal security documentation or those preparing for their first audit or certification.

What’s Included

  • Written Information Security Program (WISP)
  • Complete core policy suite: Acceptable Use, Data Classification, Access Control, Data Retention, Incident Response, Remote Work, Password Management, BYOD, Vendor Management, and more
  • Standards and procedures aligned to ISO 27001, NIST CSF, SOC 2, or HITRUST
  • Policy review and approval workflow design
  • Employee acknowledgment process

Expected Outcomes

A complete, audit-ready policy library tailored to your organization — not boilerplate.

Engagement Model

Project-based

Investment Range

$5,000 – $15,000

Security Awareness Training

Who It’s For

Organizations that want to reduce human risk through an educated, security-aware workforce.

What’s Included

  • Security awareness program design and annual content calendar
  • New-hire security onboarding training
  • Role-based training for high-risk roles
  • Phishing simulation campaign planning and execution
  • Security culture assessment and baseline metrics
  • Reporting and participation tracking

Expected Outcomes

Measurable reduction in human-risk indicators. TMCP has designed and delivered awareness programs for organizations ranging from 200 to 22,000 employees.

Engagement Model

Annual program

Investment Range

$4,000 – $10,000 / year

Ready to get started?

Schedule a complimentary discovery call to discuss your needs.

Schedule a Discovery Call →