
Cybersecurity Governance, Artifacts, & NIST Controls Documentation
IT Policies, SOPs, Standards, Procedures, & Guidance Solutions

Delivering tailored Cybersecurity Policy, Artifacts, & NIST Controls Documentation for more than 15 years
Our Principal Kristen Ramos is a Cybersecurity Governance and IT Policy Subject Matter Expert. She serves as cybersecurity subject matter expert and consultant to government agencies, critical infrastructure, and private Fortune 500 clients and has successfully spearheaded IT policy and GRC projects around the globe for over fifteen years.
Kristen specializes in NIST SP 800-53, NIST CSF, MITRE TTPs, NERC-CIP, HIPAA, GDPR, ISO, NIS2, CMMC, and other global frameworks and authorities. She focuses her practice on developing cybersecurity artifacts including IT/OT policy, SOPs, assessments and implementation guidance across industry sectors for sensitive information systems, global supply chains, and system and application development lifecycle processes for clients including DoD, DHS, DoE, CISA, TSA, FAA, Idaho National Lab, Microsoft, and Pfizer. She recently orchestrated and authored CISA’s Ransomware Readiness Assessment from a straw man proposal to published, fully integrated assessment with reports, guidance, and resources for stopransomware.gov.
Capabilities
-
Embedded Cybersecurity Technical Writing
Effective documentation developed at your location of choice - in our well connected offices across New England, remotely, or hybrid on-site. We take great pride in embedding with your stakeholders and your team, regardless of where we sit.
-
Custom IT Policy, Standards, & Guidance
Tailored cybersecurity guidance delivered on time and on budget. We specialize in NIST SP 800-53, NIST CSF, MITRE TTPs, NERC-CIP, HIPAA, GDPR, ISO, NIS2, CMMC, and other global frameworks and authorities. We focus our practice on developing cybersecurity artifacts including IT/OT policy, SOPs, assessments and implementation guidance across industry sectors for sensitive information systems, global supply chains, and system and application development lifecycle processes for clients including DoD, DHS, DoE, CISA, TSA, FAA, Idaho National Lab, Microsoft, and Pfizer.
When it comes to small business and customer-facing cybersecurity guidance, we hit that mark too. Our principal cybersecurity SME, Kristen, recently orchestrated and authored CISA’s Ransomware Readiness Assessment from a straw man proposal to published, fully integrated assessment with customized reports, guidance, and carefully sourced references. It is the most universally-accessible ransomware assessment on the web.
-
Accessible Cybersecurity UX Content
Custom-built cybersecurity documentation that delivers an accessible, actionable experience across your organization - from the architects and engineers, to your clients, to the C-Suite.