What we do

The record, kept current. What the Program does, in the order it happens.

Three stages, one thread

How we work

Attack Surface Analysis

A quiet, outside-in map of the Client's exposure. No cost, no obligation, the Client's to keep.

The Protection Guide

Five hour-long calls with a named advisor that turn the analysis into a prioritized plan of what to address and when.

The Program

Policies written, controls in place, watch kept, and a named advisor on the record.

See the outside view first

The Program, in six steps

  1. 01

    Consultation

    A short, plain conversation about the outside view. No pressure and no script.

  2. 02

    Skeleton

    A free Attack Surface Analysis and, for firms that qualify, a Protection Guide. The Client's to keep.

  3. 03

    Engagement

    For firms that want to go further, we scope and begin the Program together with the named advisor.

  4. 04

    Client System Analysis

    A study of the Client's firm, its exposure, and the systems behind it.

  5. 05

    Full Research

    A policy and document suite written for the firm, implemented by us, and a compliance crosswalk to the frameworks the Client is asked about.

  6. 06

    The Program

    A dedicated security team that keeps records, updates systems, and protects the business. The advisor of record.

Ongoing services

Continuous monitoring and alerts

The Client finds out before anyone else does.

Weekly briefs and quarterly board reviews

The Client walks into the board room prepared.

Insurance questionnaires, with evidence

Pass the renewal and hold premiums down.

Customer questionnaires, answered by us

Security closes deals instead of stalling them.

Compliance mapping and policy upkeep

Any framework the Client is asked about, shown on the day it is asked.

Incident response coordination

A plan and a person, already in place.

Questions from the Client's team

NDAs, who does the work, internal circulation, and scope verification: the questions a committee usually asks before an engagement begins.

  • Will Bridgham sign the Client's NDA?

    Yes. A mutual NDA is executed before any engagement that involves reviewing the Client's systems, policies, or data.

  • Who does the work?

    A named advisor leads the engagement, supported by the firm's research and technical staff. A person reviews every deliverable before it is delivered.

  • Can the report be circulated to the board or the carrier?

    Yes. Every report is written to be forwarded to the board, the auditors, or the insurer with no further explanation needed.

  • How is scope verified before anything is paid?

    The Protection Guide produces a written, ranked plan before any paid engagement begins. The Client reads the full plan, and can check its scope, before deciding.

  • What if the analysis finds nothing serious?

    A clean report is the correct result, and it is still the Client's to keep. Where a setup leaves no meaningful gaps, we say so plainly.

  • Can a firm with no security lead still work with Bridgham?

    Yes. The named advisor walks the Client's team through the plan in as much or as little technical depth as the committee asks for.

  • How are findings kept separate from the sale?

    Every finding is checked against a named source before it is delivered, so the Client's team can verify the work independently.

  • Can this help with a cyber-insurance renewal?

    Yes. We prepare the evidence carriers ask for during underwriting and renewal, which supports both qualification and premium.

  • How is AI used in this work?

    Software does the gathering, because it reads public exposure faster and more completely than a person sampling by hand. A named advisor decides what it means and reviews every deliverable. Client data never trains a public model, and anything we could not verify is labelled not yet assessed.

  • What happens when an engagement ends?

    Reports can be exported at any time during the engagement. When it ends, platform and advisor access ends with it, and we delete identifiable data on request. Only de-identified insights are retained, and they trace back to nobody. The AI transparency page sets this out in full.

Start the conversation

Everything above is done for the Client and presented by a named advisor. It begins with a short, plain conversation about the outside view.