Jobs · Information Technology · New York

Data Exposure Review

DAISEQ · Paradox, NY · Yesterday
Information TechnologyFull-time

About the role

This engagement addresses the "Assurance Paradox" where organizations have invested in cyber security controls and passed audits but still lack confidence in their real-world data protection. It is particularly relevant for organizations that:

  • Have passed audits but remain uncertain about actual data exposure.
  • Have rolled out Copilot or sanctioned GenAI and need clarity on data exposure risks.
  • Are introducing AI capabilities and require a defensible understanding of sensitive data movement before facing stakeholder, regulatory, or board scrutiny.
  • Face questions from boards, audit committees, or regulators that cannot be confidently answered.
  • Seek an independent review before major control investments or program resets.

AI tools often inherit existing permissions, classifications, and access models, leading to accumulated oversharing, inconsistent data classification, and unreviewed access paths. This engagement identifies exposure risks and provides a defensible answer for accountable owners.

What the engagement produces

Four key outputs are delivered over the course of the engagement:

  • Exposure Assessment: An independent assessment of data, identity, collaboration, and AI environments within scope. It maps declared controls against actual exposure paths and identifies discrepancies.
  • Executive Prioritisation Roadmap: A prioritized remediation roadmap with immediate, tactical, and strategic actions, including owning functions and intended risk reduction per item. This supports internal planning but does not replace detailed effort estimation.
  • Board and Regulatory Defensibility Statement: A concise executive statement covering current exposure, key assumptions, confidence level, and priority actions. It is tailored for board, audit committee, and regulatory conversations and aligned with frameworks like DORA, GDPR, NIS2, and sector-specific oversight.
  • Executive Findings Workshop: A 90-minute workshop with the CISO, Head of Security Architecture, or nominated executives. It covers exposure findings, prioritization rationale, and recommended next steps, adjusted for business and political context.

Outcomes

  • Board-defensible exposure position.
  • Clear prioritization of exposure reduction activities.
  • Improved visibility of data and AI exposure.
  • Actionable remediation roadmap.
  • Better-informed regulatory and governance discussions.

How it is different

This is not a maturity assessment or compliance gap audit. It is an independent diagnostic with a fixed scope, fixed fee, and direct delivery. The output considers the broader environment rather than a single technology domain and provides a defensible position for boards and regulators. If your primary need is a vendor decision, the Security Decision Review may be a better fit. For ongoing advisory support, see the Cyber Security Advisor retainer.

Commercials

Typically £18,000 to £25,000 for a standard scope. Extended scope engagements (e.g., multi-tenant, multi-geo, or post-M&A environments) are priced on request. Elapsed duration is typically three to four weeks, subject to stakeholder availability and data access. Scope, assumptions, and deliverables are confirmed in the proposal following the initial conversation.

Similar jobs

Data Reporter

The Wall Street JournalNew York, NY· 2 wk ago
Marketing$120k–$140k/yrapply on wsj.jobs