Is this for you?
- You have between five and two hundred people, and nobody whose full-time job is security.
- You are preparing for a certification program, a funding round, a large customer's supplier questionnaire, or EASA Part-IS or ISO/IEC 27001 compliance, and need to know the gap before someone else measures it.
- You have had a scare, a phishing incident, a lost laptop, a supplier breach, and want to know what it means for the rest of the business.
- You want a plan you can execute with the people you have, not a 300-page report.
What you get
- Gap analysis. Your current state against the framework we agree on: NIST CSF 2.0, ISO/IEC 27001, CIS Controls or EASA Part-IS, with the aviation-specific obligations (airworthiness security, EFB, flight data, supplier contracts) called out.
- Prioritized risk register. What could actually hurt you, ranked by likelihood and effect on flight safety, certification, revenue and reputation, in a form you can keep maintaining.
- 90-day roadmap. The ten to fifteen actions that close most of the gap, with an owner, an effort estimate and a sequence, chosen so that your own team can run them.
- One-page summary. For the board, the investor or the authority: where you are, what you are doing about it, and by when.
- Optional: retainer. After the 90 days, I can act as your part-time security lead: a fixed number of hours a month to keep the roadmap moving and answer questions as they come.
How it runs
- Week 0Readiness call45 minutes on what you build or operate, who is asking, and which framework fits. Fixed quote follows.
- Week 1Documents and interviewsI read what you have (policies, diagrams, contracts, certification plans) and hold six to ten 45-minute interviews across engineering, operations, maintenance and administration.
- Week 2Technical reviewA read-only look at the systems that matter: cloud and identity, endpoints, design and test data, EFB or fleet systems, backups. Screenshots and walkthroughs are enough; I do not need administrator access.
- Week 3Report and roadmapGap analysis, risk register, roadmap and summary, then a working session with you to adjust priorities to what is realistic.
What I need from you
One internal contact who can open doors, the documents you already have (there is no minimum), six to ten interviewees for 45 minutes each, and a walkthrough of your key systems. Most of the engagement is remote; I come on site in Canada and the United States where it helps.
Questions I get asked
Is this an audit or a certification?
No. It is a readiness assessment: it tells you where you stand and what to do, and it prepares you for a formal ISO/IEC 27001 audit or a Part-IS review by someone else. I do not certify.
Which framework should we use?
If nobody is telling you which one, NIST CSF 2.0 is the practical default for a small company and maps to the others. If you sell to or operate under EASA, Part-IS sets the obligations. If a customer requires ISO/IEC 27001, we use that. We decide on the readiness call.
How small is too small?
Five people is fine. Below that, the readiness call itself usually answers the question and I will tell you so.
Will this disrupt the team?
About an hour per interviewee and a few hours for your internal contact over three weeks. Nothing is installed and nothing is scanned without your say-so.
Start with a 45-minute readiness call
Tell me what you build or operate. You leave the call with your three most important next steps, whether or not we work together; if this engagement fits, a fixed-scope proposal and quote follow within a few days.
Ask about a readiness assessment