Risk & Cyber Program Package
Get your business into a ready-state
The Risk & Cyber Program Package is an eight part engagement that starts with everything in our Risk Consultation Package, a full risk assessment and a hands-on tune up session, then expands into building out the policies, plans, and program documentation your business needs to operate from a place of assurance, not guesswork.
How It Works
This engagement is built around one outcome: a clear, documented program your business can stand behind and keep building on.
- Kickoff and Information Gathering - We start by learning about your business, your systems, and your current practices.
- Core Systems Security Review - We review the security settings in your most critical systems to identify gaps.
- Working Session - One on one time with a consultant to dig into open items and start closing the low hanging fruit, the fixes that make an immediate impact.
- Risk Report Review and Remediation Plan - We walk through your completed risk assessment together, a report that scores your risks based on Likelihood and Impact, along with a clear remediation plan for what to do next.
- Policy and Procedure Kickoff - We introduce the next phase of the engagement and start working through the policies and procedures your business needs, built around your actual risk profile.
- Policy, Procedure, and Incident Response Planning - We continue refining your policies and procedures while reviewing and shaping your incident response plan alongside you.
- Working Session - A final working meeting to resolve outstanding questions and finish refining your policies, procedures, and incident response plan.
- Plan of Action and Milestones Review - We present your finalized Plan of Action and Milestones alongside your risk register, giving you a clear, prioritized list of next steps and a living document to guide your business going forward.
What You Get
- Risk Assessment
- Risk Remediation Plan
- Policies and Procedures
- Plan of Action and Milestones (POAM)
- Incident Response Plan tune-up
If you need more help after this engagement, you can add additional consulting time or move into one of our other services to take your cybersecurity and compliance further.
Don't want to pay in full? Use the Klarna option on the next page to choose from affordable payment options by breaking it into payments!
Not sure if it's right for you?
Book a free Cyber Readiness Assessment and we'll help point you in the right direction or tailor a package to fit your needs
Terms
Consulting and services fall under our standard Terms of Service currently located HERE and the Service Order below. You must agree to these terms and conditions to proceed with your purchase.
SERVICE ORDER
This Service Order (“SO”) is entered into as of the date purchased (the “Effective Date”), by and between RLS Consulting, LLC dba ReadyState Cybersecurity, a Colorado limited liability company residing at 1480 Abilene Dr, Broomfield, CO 80020 (“READYSTATE”) and the customer submitting this order (“Customer”).
1. SERVICES. READYSTATE agrees to provide the following services (the “Services”) to Customer, as more fully described on Schedule A. Additional work beyond this scope may require a new SO.
2. PRICING AND PAYMENT. Customer agrees to pay for all services provided by READYSTATE using either a credit card or Automated Clearing House (ACH) transfers via our online payment system. No other forms of payment will be accepted unless explicitly agreed upon in writing by both parties.
3. TERM. Except as otherwise set forth in the Services Descriptions in Schedule A, below, the initial term of the Services shall be 12 months (the “Initial Term”). Unless at least thirty (30) days written notice prior to the end of the Initial Term or any Renewal Term is provided by either party, the term will continue (the “Renewal Term”) at the pricing and original term. The Initial Term and any Renewal Terms shall collectively be referred to as the “Term.” All subscriptions require a full 12 month commitment, regardless of payment plan type.
4. ADDITIONAL TERMS AND CONDITIONS. Unless otherwise agreed, this SO, and the Services provided, are governed by the standard READYSTATE Terms of Service currently located HERE (the “READYSTATE Terms”). All capitalized terms in this SO shall have the meaning ascribed to them in the Terms of Service, unless otherwise defined in this SO. Customer represents and warrants that the Customer agrees to the Terms of Service and all terms referenced in and incorporated into the Terms of Service.
5. COMPLETE AGREEMENT, AMENDMENTS. The SO, the SOW (if any) and the Terms of Service (collectively the “Agreement”) constitute the complete and exclusive statement of agreement among the parties with respect to the subject matter of the Agreement and replace and supersede all prior and contemporaneous written and oral agreements, negotiations, discussions or statements by and among the parties. The Agreement may be amended only by a subsequent writing that specifically refers to the Agreement and that is signed by both parties. No other act, document, usage, or custom, including any printed terms and conditions contained in any purchase order, shall be deemed to amend the Agreement.
The individuals who execute this SO represent and warrant that they have full legal authority to execute this SO and thereby bind the parties to full performance.
SCHEDULE A
1. SERVICE DESCRIPTIONS.
-
Risk Consultation
-
READYSTATE will work with Customer to complete a cybersecurity risk assessment designed to assess the likelihood and impact related to cyber risks to the Customer's environment.
-
Deliverables:
-
Cybersecurity Risk Assessment: An assessment of Customer's risks related to Likelihood and Impact factors.
-
Risk Report: Summary of findings and recommendations based on the Risk Assessment.
- Remediation Plan: A plan with prioritized steps to address the most critical risks in the Customer's environment based on the findings in the Risk Assessment.
- Policies and Procedures: Using CIS as a recognized framework, READYSTATE will help Customer adopt documentation for their best practices.
- Plan of Action and Milestones (POAM): A working document and checklist that helps identify plans to reduce risk and implement best practices, as well as demonstrate progress and due diligence.
- Incident Response Plan: Using a template from Customer's insurance provider or other versions, ReadyState will help Customer adapt one for their specific needs.
-
-
- Consulting Engagements
-
The Risk Consultation and Cyber Program Development will be conducted through 8 online consulting engagements (60 min each). Meeting topics may vary but, in general, will include:
-
Initial introduction to the assessment and discussions around current practices and risk inventory
- Working session to answer questions and continue progress on the risk assessment
-
Review of security settings in core systems
-
Review of Risk Assessment and Report, as well as gaps and priorities to focus on when following your Remediation Plan
- Introduction to our Policy and Procedure templates and initial work in reviewing and adopting practices based on CIS
- Review of your Incident Response Plan to make sure it includes elements necessary for effective response and legal requirements
- Second, general Working Session to resolve outstanding questions and finish refining your policies, procedures, and incident response plan
- Final session to review Plan of Action and Milestones risk register, Cyber Program documentation and overview of what to prioritize for the future
-
-
2. ASSUMPTIONS. In addition to any other assumptions identified in this SO, READYSTATE’s delivery of service under this SO, the estimated timeline, and the fees, are subject to the following assumptions:
-
READYSTATE will be provided access to Customer resources, employees, and documentation as needed to perform the Services listed in Section 1.
-
READYSTATE does not make any form of representation, warranty, or guarantee that improvements to cyber risk or training can make anyone 100% secure from an attack.
-
Unless described otherwise, no travel is expected or included.
-
All work will be performed during normal business hours.
3. CUSTOMER RESPONSIBILITIES. In addition to any other responsibilities identified in this SO, READYSTATE’s delivery of service under this SO, the estimated timeline, and the fees, are subject to Customer complying with the following obligations:
-
Project Manager. Customer shall designate one of its employees to serve as its primary contact with respect to this Agreement and to act as its authorized representative with respect to matters pertaining to this Agreement and who will have the authority to act on behalf of Customer in connection with matters pertaining to this Agreement, with such designation to remain in force unless and until a successor is appointed.
-
Response. Customer shall require that the Project Manager respond promptly to any reasonable requests from READYSTATE for instructions, information, or approvals required by READYSTATE to provide the Services.
-
Cooperation. Customer shall cooperate with READYSTATE in its performance of the Services and provide access to premises, employees, and equipment as required to enable READYSTATE to provide the Services.
-
Consents. Customer shall take all steps necessary, including obtaining any required licenses or consents, to prevent Customer-caused delays in READYSTATE's provision of the Services.