Sustainable Gaps

The Engagement

What Working With Us Looks Like

A structured, time-bound consulting engagement that measures the distance between where your security posture is today and where it must be. Our methodology has been applied across 11 countries for federal law enforcement and intelligence programs. No ambiguity. No open-ended retainers. Measurable outcomes.

Five Phases · Signal to Hardening Plan

01

Signal & Discovery

2–4 weeks

We monitor 17 federal and public data sources to identify utilities and infrastructure operators facing regulatory pressure, security mandates, or compliance gaps. When a qualifying signal is detected, we initiate discovery — profiling the organization, stakeholders, regulatory calendar, and stated pain points.

Deliverable

Discovery Summary — site profile, key stakeholders, regulatory exposure, recommended engagement scope.

Your Role

One introductory call. We do the research.

02

Fit Scoring

1 week

We apply a quantitative scoring model to determine alignment between your organization's risk profile and our assessment methodology. This isn't a sales exercise — it's a mutual qualification. If the fit score doesn't reach threshold, we tell you. No engagement is better than the wrong engagement.

Deliverable

Fit Score Report — quantified alignment across regulatory exposure, physical posture, operational readiness, and strategic timing.

Your Role

Provide access to relevant compliance documentation.

03

On-Site Assessment

1–2 weeks

Our team walks your facilities. We assess physical perimeters, access controls, detection systems, surveillance coverage, lighting, barrier integrity, and procedural compliance against applicable standards (NERC CIP-014, TSA Security Directives, OSHA PSM, CFATS, AWIA). Every observation is documented with photos, measurements, and regulatory citations.

Deliverable

Site Assessment Workbook — facility-by-facility observations, measurements, and compliance status against applicable standards.

Your Role

Facility access, point of contact for site logistics, relevant drawings or as-builts.

04

Gap Analysis Report

2 weeks

We quantify the distance between where your security posture is today and where it must be to meet regulatory, operational, and risk thresholds. Every gap is categorized by severity, remediation cost estimate, and timeline. No gap is theoretical — each one traces back to a specific observation from the on-site assessment.

Deliverable

Gap Analysis Report — prioritized findings, severity ratings, cost estimates, and regulatory cross-references.

Your Role

Review and feedback on draft findings.

05

90-Day Hardening Plan

Ongoing support

We deliver a phased remediation plan with specific actions, responsible parties, budget estimates, and completion criteria for each gap. The plan is designed to show measurable progress within 90 days — enough to demonstrate compliance momentum to regulators and board members. We remain available for implementation support and progress reviews.

Deliverable

90-Day Hardening Plan — sequenced remediation actions, vendor recommendations, budget framework, and progress milestones.

Your Role

Assign internal owners. Execute. We support.

Engagement Options

Every engagement is scoped to your specific regulatory framework, facility profile, and risk posture. These are starting points — not packages.

Security Diagnostic

Remote signal analysis + risk profile for a single utility or facility

Starting at $5,000
1–2 weeks · 10-page diagnostic report with signal provenance and risk indicators

Single-Facility Assessment

On-site assessment of one substation, plant, or facility

Starting at $25,000
4–6 weeks · Gap analysis report + 90-day hardening plan

Enterprise Assessment

Multiple facilities across a service territory or operating region

Starting at $75,000
8–12 weeks · Comprehensive gap analysis + prioritized hardening roadmap

Intelligence Retainer

Ongoing signal monitoring + monthly briefings + quarterly reviews

$3,000–$5,000/month
Ongoing · Monthly intelligence brief, signal alerts, and quarterly strategy review

Start With a Diagnostic

Not sure where you stand? A Security Diagnostic gives you a signal-informed risk profile in two weeks — no on-site visit required. If the findings warrant a full assessment, the diagnostic fee applies toward the engagement.

Request a Security Diagnostic →