Security Advisory
The Security Diagnosis
Cyber attacks are a weapon now. Nation-states use them. Criminal networks have industrialized them. Most founders don't know if they're exposed. They're guessing.
Security posture review · Fixed scope · Independent
Your security team is throwing acronyms at you. Some of what they are doing is right. Some of it is overkill. Some of it is missing entirely. You have no way to tell which is which.
This is a structured, independent assessment of your security posture. No vendor agenda. No frameworks handed to a junior analyst. Raphaël works directly with you, delivers a plain-language report your board can read, and gives you the questions to ask your security team. And what good answers look like. So you can own the answer.
If you're looking for a cybersecurity consultant to audit your systems and tell you where you stand: this is that. Independent. No vendor agenda. Fixed scope.
A cyber risk assessment built for the person who has to answer for it, not for a compliance team.
Asking costs nothing. The contact form is at the foot of this page.
Two people buy this
One is being assessed. One is doing the assessing.
You have been asked to prove something
A security questionnaire from an enterprise buyer, a diligence request from an investor, or an acquirer about to look properly. Somebody else set the deadline. You need to know where you stand before you answer.
You are the one asking
A deal team running diligence on a target before the money moves. We assess the company, and the read comes back to you rather than to them. Same scope, same fixed window, commissioned from the other side of the table.
The rest of this page is written to the company being assessed, because that is who answers the questions. If you are commissioning it on a target, the scope and the report are the same. Say so when you get in touch and we will address it to you.
When to Book This
Before a fundraise
Investors run security due diligence. If you cannot answer their questions, it creates doubt. Get the independent read before they ask.
Your board is asking about cyber risk
You should not be dependent on your vendor to speak for you in that room.
You have a security person or vendor but no way to evaluate them
Having someone in place is not the same as knowing if what they do is right for you.
After an incident, near-miss, or compliance request
Before you react and spend, understand what you actually need to fix.
Onboarding a new security hire or provider
Before you hand them the keys, know what the baseline is and what you expect from them.
Entering a regulated market or new geography
The compliance landscape just changed. Understand what that means before your legal team runs up a bill.
Scaling fast and security has not kept pace
What worked at 20 people does not work at 120. Stage transitions are where exposure quietly grows.
An enterprise customer sent you a security questionnaire
Before you answer, know where you actually stand.
Evaluating cyber insurance
Insurers will ask detailed questions about your security posture. Know your answers before they do.
How It Works
1 to 2 days. On-site or remote.
Initial interview
With you: the CEO or founder. Establishes context: your business, your stage, your risk profile. Also identifies who else needs to be in the room.
Follow-on interviews
With the relevant people: your security vendor, internal security lead, CTO, or whoever owns the decisions. Raphaël asks the questions you do not know to ask.
Ad-hoc follow-ups
In some cases, specific details are not immediately available during interviews. Raphaël requests what he needs directly, without creating noise for your team.
Written report
A full assessment covering every area in scope. Delivered within 5 business days.
Readout
Raphaël walks your leadership team through every finding, in plain language, with time for questions.
In Scope
- Company stage profiling: maturity, growth phase, regulatory exposure
- Threat landscape relevant to your company specifically
- Inventory of current security measures: what exists, who owns it
- Evaluation of current security vendors and internal security team
- What is missing, what is overkill, what is misaligned for your stage
- Independent verdict on products or services you are considering
- Prioritized recommendations in business language
Out of Scope
- Technical penetration testing
- Compliance certification (SOC 2, ISO 27001, etc.)
- Remediation or implementation
The design principle: comprehensive enough for what you are, not for what you are not. An unregulated startup does not need bank-grade security. A fintech with payment data does. Raphaël tells you what is appropriate for your stage, your industry, and your actual exposure. Nothing more. Nothing less.
What You Walk Away With
Your risk profile
Your company's stage, industry, and the threat landscape that is actually relevant to you. Not a generic framework. Not a template. Specific to what you are.
An honest audit
What you have in place: security measures, vendors, people. An independent verdict on whether it is right for your stage: what is right-sized, what is overkill, what is missing.
A compliance reality check
What you are required to do, what is optional, and what is irrelevant for your stage. In plain language.
Prioritized actions in business language
Options for each gap with pros, cons, and rough cost. No acronyms. No open questions. A plan you can act on.
A readout session
Raphaël walks your leadership team through every finding. Time for questions. Everyone in the room leaves with the same picture.
The questions to ask your security team
Not a translation that stays with Raphaël. The framework to evaluate your security yourself: what to ask your vendor, your analyst, your CTO. What a good answer looks like in each case.
What we do
Three to seven days, fixed scope. We read what you actually have: the posture, who owns it, what is being spent and what it is protecting against. Independent of whoever is currently doing the work.
What it produces
A plain-language read you can hand to an investor, an enterprise buyer or your own board. It says what is appropriate for your stage, what is missing, and what you are overpaying for.
What it isn't
Not a penetration test and not a vCISO retainer. It does not tell you what is breakable today. It tells you whether posture, ownership and priorities match the risk you are carrying.
What you are committing to
Typical shape, not a fixed package
How long
Typically three to seven days, depending on what is already documented.
Your time
A few hours, mostly access and a handful of conversations.
What you keep
A written read you can hand to an investor, a buyer or your board.
Fixed scope, which is what makes it answerable against somebody else's deadline. Three days where the policies exist and someone can find them. Seven where the answer to every question is a person rather than a document. You will know which you are within the first conversation, and so will we.
On the record
“… He doesn't jump to solutions. He gets to the crux of the problem first, builds solid hypotheses, and does the foundational research to back them up. The rigor was real. …”
Who is asking, and by when?
An investor, an enterprise buyer, or your own board. Tell us who is asking and the date you need an answer by.
The questions to ask your security team, and what good answers look like.
No obligation either way. We will come back with a tailored answer, or tell you it is not us.
Or write to us directly at contact@sha-rp.com.
Also for startups