The four phases

Align

One strategy across domains, governed

Integrate protective objectives across physical security, cybersecurity, and executive protection into a coherent strategy. Reconcile competing resource constraints, operational friction, and security posture. Establish governance that connects protective decisions to organizational objectives and regulatory requirements. Create the alignment between threat intelligence, capability, and commitment that enables consistent protective posture.

LEARNALIGNPERFORMREVIEWPrincipledPerformancePRAESTANTIA PRINCIPIATA

What this phase produces

  • Objectives integrated across domains
  • Constraints reconciled
  • Governance connected to objectives and regulation
  • Intelligence, capability, and commitment aligned

Writing

14 articles on Align

All articles

When the Lights Go Out: What ISO 22301 Actually Does for Your Business

ISO 22301 is the international standard for business continuity management. This article explains what it actually requires, why it belongs in the boardroom rather than the risk register, and how to start applying its thinking before you pursue certification.

9 min read

A GRC Blueprint for Directing 24/7 Security Operations at Scale

A large, multi-site security operation running around the clock is a live risk management system. Every shift, every post assignment, and every client contract carries obligations that can slip in small ways. This article applies the OCEG Principled Performance framework to a 24/7 security operations context, with a four-step implementation timeline.

9 min read

· part 1

Beyond IT: GRC as an Enterprise Discipline

Many people first encounter GRC through cybersecurity, audit, privacy, or IT control work. But GRC is not an IT function. It is an enterprise discipline that helps organizations govern decisions, manage uncertainty, meet obligations, and act with integrity wherever decisions create consequences.

9 min read

· part 2

GRC in Physical Security: Governing Protection, Duty of Care, and Resilience

In physical security, risk is not abstract. It has weight, movement, timing, location, and consequence. A guard standing post is not the same thing as a controlled security operation. A protective detail is not the same thing as an executive protection program. The difference is GRC.

12 min read

· part 3

GRC in Mission-Driven Organizations: Turning Ethical Purpose into Accountable Action

A good mission does not eliminate the need for governance, risk management, and compliance. It increases it. This article applies GRC to a fictional nonprofit to show how mission-driven organizations convert ethical purpose into accountable action through board oversight, donor stewardship, campaign governance, and credible impact reporting.

14 min read

The Executive Protection Standard: What It Changes, and What It Requires

For decades, executive protection operated without a recognized national standard. The new ANSI-recognized standard changes that. This article examines what it changes, what it requires, and what the industry must do now to meet the floor it establishes.

8 min read

· part 1

From Guard Gates to Grid Resilience: Why Physical Security Is Now Critical Infrastructure Risk Management

Power-company security has always been about gates, badges, cameras, patrols, and response. But the threat landscape has evolved so fundamentally that physical security must now be understood as critical infrastructure risk management. This article argues that security teams in the electric sector must think in terms of function, consequence, and resilience rather than perimeter alone.

10 min read

From Stewardship to Enterprise: Why the Modern Family Office Requires Institutional-Grade Risk Management

The global wealth landscape is witnessing the rapid institutionalization of private capital. Family offices are evolving from discreet wealth preservation vehicles into sophisticated investment platforms, yet their security and risk management frameworks have not matured concurrently. This article examines the expanding threat landscape and the imperative to adopt enterprise-grade risk management.

8 min read

The Architecture of Trust: Risk Management in the New Era of Branded and Wellness-Centric Living

The global pipeline for branded residences is projected to exceed 1,000 schemes by 2030. As the value proposition shifts toward wellness, community, and curated lifestyle, the security and risk management implications are significant and largely unaddressed.

7 min read

· part 9

Bridging the Silos: Protective Intelligence as the Core of Insider Threat Programs

Organizations with a formal, cross-functional insider risk management program avoid an average of seven major insider incidents per year, resulting in approximately $8.2 million in avoided breach costs. Yet only 63% of organizations currently operate such a program. The structural failure is not a lack of data. It is a failure to connect the data that already exists across organizational silos.

8 min read

Applying ISO 31000 Under Pressure

What a risk management standard actually looks like when the country is on fire. Drawing from seven years of experience in Haiti, this article demonstrates how ISO 31000's framework for managing uncertainty translates into life-or-death operational decisions in one of the world's most complex security environments.

14 min read

From Protective Detail to Enterprise Risk Program: Applying GRC to Executive Protection

Executive Protection should be governed as an enterprise risk function, not treated as a standalone protective service. When Governance, Risk, and Compliance is applied to an integrated EP program, it gives leaders a disciplined way to define authority, align protective decisions with enterprise risk appetite, meet duty-of-care and compliance obligations, and create accountable, auditable protection outcomes.

12 min read

· part 2

The Intelligence-Led Executive Protection Detail

The era of the visible deterrent is over. The modern executive protection detail must evolve from a logistics-heavy guarding function into a dynamic, intelligence-driven operation. It is no longer about how close you stand to the principal. It is about how far ahead you can see.

8 min read

· part 7

Navigating the Gray Areas: Ethics, Privacy, and Legal Compliance in Intelligence

The difference between effective intelligence gathering and an unlawful invasion of privacy often hinges on how data is collected and subsequently used, not merely what data is collected. A Protective Intelligence program that operates without strict ethical and legal guardrails is not a security asset; it is a liability.

8 min read

Services that deliver Align

How the Trusted Advisor delivers this phase

The Trusted Advisor delivers Align through management consulting and cybersecurity GRC: governance that connects protective decisions to the organization's objectives, risk registers that quantify exposure across domains, and controls that hold under pressure.

Talk to the Trusted Advisor

GRC & Operations

Management Consulting

Mission-focused operations advisory and GRC implementation support for organizations building or maturing security governance frameworks. Translates strategic intent into executable programs — policies, controls, risk registers, and accountability structures that hold under operational pressure.

Cyber Risk & Compliance

Cybersecurity GRC

Governance, risk, and compliance advisory for organizations aligning cybersecurity programs to regulatory requirements and enterprise risk frameworks. Covers control design, policy development, risk register management, IT GRC implementation, and compliance readiness across NIST CSF, ISO 27001, and sector-specific standards.

Portfolio evidence

Applied work in Align

Full portfolio
ISMS · ISO 27001 · 17 pagesISO/IEC 27001:2022 Risk Assessment and Statement of ApplicabilityA complete, audit-ready ISO/IEC 27001:2022 risk assessment and Statement of Applicability for Stark Industries Inc., a fictional SaaS marketing platform hosted on AWS. Covers Clauses 6.1.2 and 6.1.3 in full: five-asset inventory with CIA ratings, five risk scenarios scored on a 5×5 likelihood-impact scale, a risk treatment plan with selected Annex A controls, and a full 93-control SoA with applicability justifications and exclusion rationale. Residual risk is scored post-treatment and presented for management sign-off.AI Governance · GRC · 8 pagesAI Governance Program BlueprintA complete AI governance blueprint for a composite energy-sector enterprise. Covers governance structure and RACI accountability, a standards crosswalk across NIST AI RMF, ISO/IEC 42001, and the EU AI Act, a ten-entry scored risk register, and a four-quarter phased implementation roadmap. Demonstrates how named frameworks translate into an operating committee, a control set, and a risk register a real organization could adopt.Third-Party Risk · TPRM · 13 pagesTPRM Program Design and Tiered Supplier Risk AssessmentA complete third-party risk management (TPRM) program design for Stark Industries Inc., applied to its most critical supplier, Amazon Web Services. The program follows a four-step process: supplier inventory, three-tier risk classification, tiered questionnaire assessment with evidence review, and signed management report. The worked AWS assessment is built from AWS's own publicly published compliance documentation — Shared Responsibility Model, ISO/IEC 27001 certificates, and SOC 2 Type II attestations — and identifies two residual actions that belong to Stark Industries rather than AWS.ISMS Build · Google Workspace Security · 18 pagesISMS Build for a Physical Security Firm: Rockops Protection AgencyA complete, end-to-end ISMS build for Rockops Protection Agency, a fictional 125-person physical security and executive protection firm. Part A establishes the governance layer — ISMS scope, information security policy, RACI accountability matrix, a ten-entry risk register scored on a 5×5 likelihood-impact scale, and a full 93-control Statement of Applicability — with a documented judgment call on Google Workspace edition selection. Part B translates every Technological control named in Part A's SoA into a specific, sequenced configuration of the Google Admin console: OU structure, BYOD endpoint management for field agents, Gmail hardening (SPF/DKIM/DMARC), Drive sharing controls, audit alerts, Vault retention, and a one-hour offboarding runbook. Together the two documents demonstrate the full governance-to-implementation chain ISO/IEC 27001 requires.