Talsoft TS
Executive team reviewing cybersecurity evidence

12-month program · Assess · Implement · Operate

Turn isolated efforts into an operable, defensible cybersecurity program.

A yearly structure to understand posture, execute a roadmap and sustain controls, owners and evidence for customers, auditors and insurers.

  • Roadmap prioritized by risk and capacity.
  • Owners and reusable evidence.
  • Senior consulting throughout the cycle.

Duration

12 months

Stages

Assess · Implement · Operate

Entry point

GAP, PenTest, readiness or concrete pressure

The core offer

One program, three connected stages.

The sequence adapts to context and team capacity while keeping one objective: every assessment should lead to execution and every control should leave evidence.

  1. 01 · Month 1Assess

    Initial GAP + Roadmap

    Understand context, assets, risks, controls, owners and available evidence.

    Outputs: GAP report, risk register, control matrix, evidence map and roadmap.

  2. 02 · Months 2–6Implement

    Roadmap execution

    Formalize processes, close priority gaps and integrate governance with operations.

    Outputs: Policies, procedures, RACI, runbooks, evidence, metrics and an updated backlog.

  3. 03 · Months 7–12Operate

    Continuous management

    Verify controls, review risk, sustain evidence and prepare the next cycle.

    Outputs: Executive reviews, health checks, metrics, Fractional CISO support and next annual plan.

Visible outcomes

What should change throughout the year.

30 days

Posture and priorities

Initial risks, gaps and decisions become visible and organized.

90 days

Owners and quick wins

The first improvements have owners, evidence and follow-up.

6 months

Implemented controls

The roadmap has produced processes, documentation and verifiable closure.

12 months

Operable cadence

The company can review posture, demonstrate progress and prepare the next cycle.

Fit

It makes sense when the organization needs transformation, not an isolated deliverable.

Evaluate the program when

  • Controls exist, but there is no shared system for risks, owners and evidence.
  • Customer, audit or insurer pressure will be recurring.
  • Leadership needs a roadmap and follow-up capacity throughout the year.

A point engagement may be better when

  • The requirement is a PenTest with a closed scope.
  • A specific audit or questionnaire has a near deadline.
  • Clarity is still low and the Mini Assessment or Initial GAP is the right starting point.

Outputs

A baseline leadership and teams can use.

Decision

Risk map, priorities, accepted risks and investment criteria.

Execution

Roadmap, backlog, owners, milestones and coordination with teams and vendors.

Evidence

Control matrix, documentation and reusable third-party evidence.

Follow-up

Executive dashboard, metrics, reviews and next-cycle plan.

How the offers relate

The Annual Program organizes the full transformation.

Annual Program

Connected assessment, implementation and operations over 12 months.

This page

Fractional CISO

Recurring senior direction when executive security leadership is missing.

View Fractional CISO

Public case

Rivkin Securities: from an existing structure to a more governed, documented program.

Talsoft provided six months of support to formalize an ISO 27001-aligned management system, live risk register, incident response, centralized monitoring and external PenTest.

  • Consistent governance and documentation.
  • Risks and controls with follow-up.
  • Coordination between leadership and technical execution.
View case studies
“Leandro and the team did a great job enhancing and formalising our existing security structure. The engagement was well-organised, consistently documented, and delivered to a high standard.”
CTO, Rivkin Securities

Maturity framework

Six levels to explain progress without reducing it to a certification.

LEVEL 1

Reactive

LEVEL 2

Organized

LEVEL 3

Managed

LEVEL 4

Measured

LEVEL 5

Integrated

LEVEL 6

Evolving

Talsoft does not replace the internal owner or guarantee certification, audit approval or absolute security. Scope, priorities and pace are agreed according to context and execution capacity.

Frequently asked questions

What company size does the program serve?

Startups, SMBs and growing teams that need to organize risk, evidence and execution.

What do we get after the Initial GAP?

Risk map, prioritized 30-60-90 roadmap, main gaps and required evidence to move forward.

Does the program guarantee certification or compliance?

No. It helps prepare posture, controls and evidence, but does not guarantee certifications or audit outcomes.

Do we always need to start with the full program?

No. Many relationships start with PenTest, readiness, a security questionnaire, Mini Assessment or a specific risk. The program works as the framework for continuity when it makes sense.

What happens after the GAP?

When structural evolution is appropriate, ISMS Implementation is followed by Continuous Security Management. A PenTest or specific readiness engagement may also be next depending on risk.

Is there an initial call?

Yes. The initial call helps understand context, external pressure and whether the GAP makes sense for your company.

Let us confirm whether the Annual Program is the right next step.

We review external pressure, current posture, team and execution capacity before proposing scope, sequence and terms.