
Nothing on this page is a rate card. It is the shape of an engagement, so you know what you are asking for.
A family practice built on more than 50 years of combined experience in government finance, cybersecurity, and regulatory compliance. The partners who scope the work do the work.
Four engagement types
1. Assessment
A fixed-scope review that produces a written finding, not a slide deck of options.
Financial health review — nonprofits and faith-based organizations. Typically two to three weeks, fixed fee. Grant-compliance posture under 2 CFR 200, internal controls, reporting quality (including readiness for Form 990 and, where federal awards require it, the SEFA and single audit), and tax-exemption standing with the IRS and, where relevant, Hacienda.
Regulatory readiness assessment — commercial and financial-services organizations. Fixed scope against the regime you actually answer to: often 23 NYCRR 500, sometimes a NIST CSF or NIST 800-53/171 mapping, sometimes a narrower question (vendor risk, incident-response evidence, annual certification file). Deliverable: gap analysis, prioritized remediation, and realistic effort estimates.
You can stop at the assessment. Some organizations take the report and fix things themselves. That is a complete engagement.
2. Program build
When the assessment is not enough — or when you already know the gap — we build the thing the rule requires: a cost-allocation plan and indirect-cost-rate proposal; a 23 NYCRR 500 policy set, CISO reporting cadence, and certification file; a vendor-risk tiering and contract standard; a control matrix with the test evidence that goes with it.
Program-build work is a defined-scope project. The scope says what “done” means before we start. It does not expand because a meeting produced a new wish list. If the work needs to grow, we rewrite the scope.
3. Ongoing advisory
A retainer for organizations that need a standing place to take questions: a new grant condition, a vendor that failed a review, a draft policy, a notice from Hacienda or a regulator, a board packet that has to be right on Thursday.
Retainer advisory is not an open-ended staff augmentation. It has a defined cadence (for example, a monthly close review, a quarterly control test, a named point of contact for incident triage) and a defined way to escalate into a project when the question is actually a build.
4. Incident support
When something has already happened — a suspected intrusion, a ransomware event, a lost device, a vendor breach, a regulator inquiry — the job is to preserve evidence, meet the notice clock, and keep the organization able to operate.
Incident support is scoped as soon as we know enough to scope it. We will tell you on the first call whether we are the right firm for the technical forensics, the regulatory notice, the board briefing, or some combination — and what we are not.
Electronic-evidence handling is part of this practice. That comes from prosecutorial work, not from a playbook we bought.
How fees are structured
We do not publish rates on this site. We do name the structure, because “call us for pricing” is how engagements stall.
- Fixed-fee assessments. A stated fee for a stated scope and a stated deliverable. The financial health review and the regulatory readiness assessment are built this way.
- Defined-scope projects. A statement of work, a fee or a fee range tied to that scope, and a change process. Program builds live here.
- Retainer advisory. A monthly or quarterly fee for a defined cadence and a defined volume of questions. Work outside that cadence is a project.
If a matter cannot be scoped, we will say so and we will not invent a fixed fee to make the conversation easier.
Who does the work
The people who scope your engagement are the people who do it. We are a small firm. That is a constraint and a design choice. You will not be handed to an anonymous delivery team.
When something falls outside our range — an attest audit we are not engaged to perform, a tool implementation we do not run, a matter that needs a firm with a different license — we say so.
Confidentiality
Inquiries are treated as confidential. We do not use the fact of a conversation as a credential. This site names no clients and no engagements; that is a rule, not a marketing posture.
A professional relationship, and the duties that go with it, begin only under a written engagement. Until then, do not send us material you are not prepared to share with a firm you have not retained. If you need a secure channel for documents, ask before you attach them to a form.
Language
We work in English and Spanish. Say which you prefer.
What happens first
A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm, and — if we are not — who is more likely to be.
· +1 917 410 3335 · [email protected]
