Services / Part-time security lead

A senior security owner on a monthly retainer: decisions, policies, client questionnaires and incident guidance, without a full-time hire.

Growing companies reach a point where customers ask for security answers, auditors ask for evidence and engineers need decisions, long before a full-time security leader makes sense.

We act as your part-time security lead: an agreed number of days each month to own the security roadmap, answer customers and auditors, review changes, and be there when something goes wrong.

security-review — september.md
## Done this month✓ Acme Bank questionnaire answered (212 q)✓ SSO enforced on the admin console✓ Leaver access review: 4 accounts removed ## Open risks✕ Backups never restore-tested→ Next: patch policy, restore test, VAPT scope
When you need this
  • Enterprise customers send security questionnaires you struggle to answer
  • You are preparing for an audit, a certification or a client due-diligence review
  • Nobody on the team clearly owns security decisions
  • You have had an incident and want a steady hand for what comes next
Coverage

What's included

The exact scope is agreed in writing before we start. This is what a typical engagement covers.

01

Ownership & roadmap

  • A risk register kept current
  • A quarterly security roadmap
  • A monthly review with leadership
02

Customers & auditors

  • Answering security questionnaires
  • Evidence for audits and due diligence
  • Joining client security calls
03

Policies & practice

  • Security policies that match how you actually work
  • Access reviews and joiner / leaver checks
  • Reviews of the vendors that handle your data
04

Engineering

  • Security review of designs and major changes
  • Secure development practices for the team
  • Planning and triaging security testing
05

Incidents

  • An incident response plan
  • Guidance during an incident
  • A review afterwards, with fixes tracked
Deliverables

What you receive.

  • A risk register and security roadmap, kept current
  • A monthly security report for leadership
  • Answered questionnaires and audit evidence
  • Security policies written for how you actually work
  • A named person to call when something goes wrong
Standards we work to
  • ISO/IEC 27001:2022
  • SOC 2
  • NIST CSF 2.0
  • CIS Controls v8
  • DPDP Act 2023
Before we start

What we need from you

  • A leadership sponsor and a monthly review slot
  • Access to the systems and documents needed to assess risk, read-only where possible
  • An agreed number of days per month

Never send passwords or keys by email. We set up a secure channel once the scope is agreed.

Often combined with

Related services.

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope