Deliverables
Confidential written report with findings, prioritized recommendations, and resourcing implications
Governance-grade program review for corporate boards, audit committees, and general counsel — conducted at arm's length from operating management.
"The board has questions about the security function — and we cannot get the answer from the people running it."
An independent review of the enterprise security program at a level appropriate for board, audit committee, and general counsel deliberation. Scope spans governance, policy, reporting structure, vendor relationships, training discipline, incident handling, and the exposure carried relative to peer organizations. Conducted at arm's length from the CSO, CISO, and operating management.
The work is investigative in posture — not collaborative — by design. Findings are written for the audience that will act on them, not for the security team that will be reviewed by them.



Boards and audit committees with fiduciary questions about the enterprise security function. General counsel preparing for a regulatory inquiry or anticipating litigation. New CSO or CISO leadership inheriting a function and seeking independent baseline. CEOs whose security spend has grown faster than their confidence in what it is buying.
Engagements may be structured under attorney-client privilege through the client's counsel.
Confidential written report with findings, prioritized recommendations, and resourcing implications
Private board, committee, or executive briefing — in person or by secure video
Typically 4 – 8 weeks, scope-dependent
Fixed-scope, agreed in advance
Engagement may proceed under attorney-client privilege


Few private advisors carry the federal-investigative discipline this work actually requires. Mr. Deetz led the division that conducted internal misconduct, mission assurance, and insider-threat-type inquiries for the U.S. Secret Service — managing thirty supervisory agents and technical staff. That is the qualification.
Built on three decades of conducting the inquiries themselves.
Threat assessment teams trained on the early signals.
When existing documentation no longer matches operating reality.
