The four phases

Review

Measure, test, audit, feed back

Assess protective effectiveness and gaps. Test controls and detection capabilities. Measure detection time, response time, and mitigation effectiveness. Audit compliance with protective standards and protocols. Feed findings into threat intelligence and capability planning. Refine threat models and protective measures based on what the environment teaches you.

LEARNALIGNPERFORMREVIEWPrincipledPerformancePRAESTANTIA PRINCIPIATA

What this phase produces

  • Detection time
  • Response time
  • Mitigation effectiveness
  • Compliance with protective standards
  • Findings fed back into Learn

Writing

8 articles on Review

All articles

Post Coverage Is a Protective Audit, Not a Finance Task

An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.

5 min read

The After-Action Review Is Where Review Happens

Exercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.

5 min read

Three Numbers a Protective Program Must Report

Activity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.

5 min read

The Internal Audit Is a Protective Control

Operations cannot see its own gaps from inside. An internal audit against a standard and the organization's own documented practice finds what daily work hides, and the closing meeting is where leadership decides what to do about it. Six ISO/IEC 27001 Clause 9.2 audits delivered for client organizations show how the method works, and why protective programs, which are almost never audited this way, need it most.

5 min read

How Humans Break Terraform Deployments: A Cautionary Tale

Infrastructure as Code has changed how organizations provision cloud resources. Terraform enables repeatable, auditable deployments. But human operators break it in predictable ways. This article maps ten common failure patterns to GRC control gaps, providing both practitioners and governance professionals a shared framework for closing them.

10 min read

· part 3

Building a Security Knowledge Base for the Energy Sector: From Lessons Learned to Better Decisions

Critical infrastructure security teams in the energy sector need more than scattered documents and compliance files. They need a structured Book of Knowledge that consolidates operational experience, regulatory requirements, threat intelligence, and lessons learned into a reasoning-capable resource that supports action under pressure.

9 min read

Should Security Investigators Play a Larger Role in Risk Management Audits in Global MedTech?

A mature security function should not be judged only by how well it prevents theft, violence, or data loss. In a global medical device company, the stronger test is whether it facilitates the mission. This article makes the case for the Office of Security Risk Management as an enterprise capability that strengthens ISO 14971 compliance and audit follow-through.

9 min read

· part 8

Proving the Value: Metrics, KPIs, and Board-Level Reporting for Security Programs

Executive protection and Protective Intelligence programs are among the most closely scrutinized areas of any corporate security budget. When these programs operate at their best, nothing happens. That quiet success creates a persistent perception problem. Programs that cannot articulate their value in the language of the business are the first to face reduction.

10 min read

Services that deliver Review

How the Trusted Advisor delivers this phase

The Trusted Advisor delivers Review through audits and measurement: ISO/IEC 27001 internal audits, security program audits, and the metrics and board reporting that show what detection, response, and mitigation actually achieved.

Talk to the Trusted Advisor

Risk posture

Security audits, assessments, and surveys

Structured reviews of facilities, events, teams, and programs to identify practical gaps and strengthen protective posture.

Portfolio evidence

Applied work in Review

Full portfolio
Maturity Assessment · NIST CSF · 15 pagesNIST CSF Maturity Assessment and Three-Year Remediation RoadmapA full 98-subcategory NIST Cybersecurity Framework maturity assessment for Oscorp, a fictional organization, based on structured stakeholder interviews across IT, cybersecurity, risk, and procurement. Oscorp passed 26 of 98 controls (27% overall). The Respond function scored 0% — the most urgent finding in the assessment. The report closes with a sequenced three-year remediation roadmap: foundational governance and access control in Year 1, detection and response capability plus TPRM in Year 2, and quantified risk management in Year 3.IaC Governance · 9 pagesHow Humans Break Terraform Deployments: A Cautionary TaleA practitioner-focused analysis of the ten most common human failure patterns in Terraform-managed AWS environments, written as a control-gap analysis for GRC professionals and an operational checklist for engineers. Each failure — state file deletion, drift from manual console changes, hardcoded secrets, variable mistakes, accidental destruction, permission failures, backend misconfiguration, circular dependencies, concurrent modification, and version drift — is examined through three lenses: cause, effect, and fix. The document bridges the gap between IaC tooling and governance, mapping each failure to a specific control category: data integrity, change management, access control, segregation of duties, business continuity, least privilege, configuration management, and release management.