Client Journey

A systematic approach to enduring protection

Client Journey

Engagements run in the same five stages, in the same order, whether the work is one assessment or a standing arrangement. The order matters: each stage produces something the next one uses, and each leaves a record of what was decided and why.

Why a Structured Journey Matters

Work done improvisationally creates visibility you did not ask for: unexplained outages, contractors nobody recognizes, questions from people who should not have been told. A set sequence avoids that and produces a record of what was done. It has three practical advantages:

First, work in a set order means the biggest exposures are dealt with first rather than whichever one surfaced most recently. We cannot prevent every incident, and say so plainly elsewhere on this site; what a sequence does is shrink the number of ways in and make the rest survivable.

Second, a non-disclosure agreement is in place before you tell us anything substantive, and access to what you share is limited to the people doing the work and recorded when it happens.

Third, a position that was accurate on the day it was assessed drifts as people, systems and suppliers change. Reviews at agreed intervals are what keep the picture current rather than historic.

Our Five-Phase Engagement Model

The five stages below are sequential, and you can stop at any of them. Many clients take the first two and no more.

Step 1: Confidential Consultation

A first conversation, under a non-disclosure agreement, to establish what is prompting the question, what has already happened, and what would make the most difference. It is a scoping discussion rather than a sales call.

What You Receive

  • Secure Discussion Environment
    A protected forum for discussing sensitive risk exposures, operational concerns, and strategic objectives without fear of disclosure or competitive intelligence loss.
  • Fiduciary Risk Identification
    Focused exploration of governance obligations, regulatory compliance requirements, and fiduciary responsibilities that shape security priorities for executives and trustees.
  • Preliminary Risk Mapping
    Initial assessment of exposure areas and vulnerability concentrations, providing immediate insight into your current security posture without operational disruption.

The consultation is covered by a non-disclosure agreement before you tell us anything substantive, and what you share reaches only the people working on your engagement.

Step 2: Tailored Assessment

Next comes the assessment itself, scoped to your circumstances and governance. It combines measurement with judgment: what the tooling finds, and what someone who has worked with offices like yours makes of it.

What You Receive

  • A picture of where you stand
    Technical weaknesses, operational exposures and governance gaps in one view, with each finding tied to the asset or process it affects.
  • Prioritized Remediation Roadmap
    Risk-ranked recommendations that direct resources toward highest-impact interventions, ensuring that initial investments address the most significant vulnerabilities first.
  • Quantified Impact Analysis
    Where you want figures, estimates of breach cost avoided and continuity improved, built on your own numbers and published breach data. These are models for comparing options, not predictions.

Assessment deliverables are designed for executive audiences, presenting complex technical findings in business terms that support strategic decision-making.

Step 3: Program Configuration

The findings decide what follows. The programs are modular: one on its own, or several in sequence, from a single piece of remedial work to a full modernization.

Available Programs

  • Insight — confidential assessment of IT and cyber risk, with a prioritized roadmap
  • Revive — secure modernization: legacy replacement, cloud migration, private AI
  • Fortify — ongoing security operations: monitoring, tested recovery, compliance evidence
  • Guardian — senior IT advisory and support under an agreed service level
  • Sovereign — personal and household protection for principals and families
  • Ark — an offline, private AI archive for institutional memory

What You Receive

  • Customized Program Selection
    Tailored combination of programs precisely aligned with your strategic objectives, risk appetite, and resource constraints.
  • Scalable Architecture
    Modular design that grows with your organization, accommodating expansion without requiring fundamental redesign or creating technical debt.
  • Detailed Implementation Plan
    Who does what, by when, and what you receive at each stage — written down before work starts.

What you end up with is a costed plan in an agreed order, rather than a report.

Step 4: Implementation

Implementation proceeds with minimal operational disruption and maximum confidentiality. Security enhancements are integrated into existing workflows rather than imposed as parallel systems, preserving operational efficiency while strengthening protection.

What You Receive

  • Built into how you already work
    Controls added to the systems and routines you have, so that people do not need retraining to keep working, and nobody routes around the security because it is in the way.
  • Minimal Business Interruption
    Carefully sequenced deployment that avoids downtime and maintains productivity, with implementation scheduled around your operational priorities rather than technical convenience.
  • Continuous Monitoring and Adjustment
    Real-time oversight during implementation enabling rapid response to unexpected issues and tactical adjustments as circumstances evolve.

Changes are scheduled around how you actually work, announced to the people who need to know and no one else, and reversible for as long as practical. Most of what we do should be invisible to everyone except the person who approved it.

Step 5: Ongoing Support

Security is not a project with a completion date. Ongoing cover comes from two programs, taken separately or together: Fortify runs the monitoring and incident response, and Guardian provides the senior advice, vendor oversight and day-to-day support. Which you need depends on whether you already have an internal team.

What You Receive

  • Monitoring and response (Fortify)
    Systems are watched 24/7. Alerts come to us rather than to you, we triage them, and incidents are handled to playbooks agreed before anything happens.
  • Advice and support (Guardian)
    A named senior contact for decisions, oversight of your suppliers, and help for your people, under a response time agreed in writing — office hours through to around the clock.
  • Regular reviews
    Your position is reassessed periodically as technology, threats and your circumstances change, and the roadmap is updated with you.

Each period you receive a written record of what was closed, what remains open, and what changed — in a form a trustee or board can read.

Expected Outcomes

The sequence exists so that each stage produces something the next one uses: the assessment sets the order of work, the design fixes the scope, implementation leaves a record, and ongoing cover keeps it current. What you end up with is a position you can explain to a board, a trustee or a regulator.

The point of running it this way is that the answer to "what do we have in place, and how do we know it works" stops being a conversation and becomes a document.