01 / BEFORE THE BREACH
Get ahead of it.
Find out where you stand, test what attackers would try, and prepare your team — before an incident forces the question.

AT A GLANCE
What this covers
Who it serves
Organizations without a recent independent security review, teams facing an audit, insurance renewal or board ask, and anyone who suspects gaps but can’t prove them.
Typical trigger
A new policy requirement, insurer questionnaire, acquisition, leadership change, a near miss — or simply not knowing if you are already compromised.
The work
- Compromise assessment to look for existing attacker activity
- Penetration testing of external, internal, cloud or application scope
- Incident readiness: IR plan, playbooks, tabletop exercise
- Risk & compliance gap review against the framework you name
Deliverables
- Findings report with severity and plain-language business impact
- Prioritized remediation roadmap
- Executive summary suitable for leadership or insurer
- Tabletop after-action notes (if in scope)
Not included
- Remediation work itself unless added (see Hardening & remediation)
- Ongoing monitoring (see OnWatch SOC)
- Certification or audit opinions — IGH prepares you, auditors certify
KEEP GOING
Related
Talk it through
Tell us where you are. We’ll recommend a sensible first step.