Skip to main content

Three practice areas, one question.

What should this institution depend on, own, refuse, and prepare for as AI and security pressure reshape how it operates? Each practice answers a different part of that question.

Method

Ground truth first. Then strategy.

Strategy fails when it starts from a slide. We start from the operating environment and work upward to the decisions it can actually support.

01

Map

Locate the systems, vendors, data paths, owners, and unspoken dependencies that the official picture leaves out.

02

Stress

Test the picture against threat paths, failure modes, regulatory duties, and plausible futures until the weak assumptions show.

03

Decide

Frame the options with their exposure, cost, and reversibility so leaders can choose, and defend the choice later.

04

Transfer

Leave behind the artifacts, indicators, and operating rhythm that let your own people keep the analysis current.

How we engage

Three ways to work with the institute.

Defined Question

Commissioned Brief

A single strategic question, answered in writing with evidence, options, and a recommendation. Fixed scope, typically two to six weeks.

Ongoing

Standing Advisory

Ongoing access to senior judgment on AI, security, and risk. Monthly analysis, review of decisions before they are made, and a phone that answers during an incident.

Delivery

Embedded Program

We sit inside your organization for an extended period to build the governance, risk, or security program the analysis called for, and hand it over running.

Start here

Scope the question first.

Not every question needs a brief. Tell us what you are weighing and we will say plainly whether it does, and what it would take.

One conversation to scope the question. A written brief in two to six weeks.