CISSP & SSCP certified practitioner · Minneapolis, MN
Serving SaaS, AI, FinTech & healthcare nationwide

Get compliant fast.
Stay secure year-round.
Be ready for a breach.

Compliance built to last. Security built to hold.

We build practical security and compliance programs for fast-growing companies that need enterprise-grade credibility — not just audit prep, but an operating system for trust.

SOC 2 · ISO 27001 · ISO 42001

End-to-end from gap assessment to audit support. Implementation-first.

vCISO from $2,500/month

Senior security strategy and program ownership without the full-time hire.

HIPAA · GDPR · BAA support

Built for how SaaS actually handles ePHI and EU data — not hospital legal teams.

IR plans & tabletop exercises

Know your plan holds before you need it. Real scenarios, real injects, real findings.

Scroll
13+

Service lines,
four tiers each

90 days

Typical time
to SOC 2 readiness

7+

Compliance frameworks
under one program

$0

Hidden fees — full budget
disclosed at every scoping call

Which describes you?

The right program depends on where you are right now.

Three common situations. All solved with the same approach — practical implementation, not advisory theater.

An enterprise deal is on the line and security is blocking it.

A prospective customer just asked for a SOC 2 report. You have two weeks, no compliance program, and a CTO who is already stretched thin. The instinct is to hire a consultant who hands you policy templates and disappears. That does not work.

Your fastest path to compliant

SOC 2 Growth track or Starter compliance package. We own the work. You close the deal.

SOC 2 readiness
vCISO Starter
Policy development
GRC configuration

You know enough to know you are exposed.

HIPAA documentation is incomplete, vendor risk reviews are not happening, and the team has no IR plan. You need a partner who understands both the technical and regulatory side — and can speak to your board when needed.

Your recommended program

vCISO Growth + HIPAA support. Board-level reporting, quarterly tabletops, and year-round compliance ownership.

vCISO Growth
HIPAA & BAA
IR & tabletop
Audit readiness

You were told to "handle compliance" on top of everything else.

You have Drata or Vanta but have not configured half of it. Questionnaires come in faster than you can answer them. You need capacity and expertise — someone who takes the heavy work so you can focus on the technical side.

Relief, fast

GRC configuration sprint + customer security reviews retainer. We take the weight off within two weeks.

Vanta / Drata config
Customer security reviews
Audit readiness
Compliance maintenance

Measurable outcomes

What clients actually achieve

Not deliverables — real business results.

60–70%
Questionnaire volume drops after SOC 2

A completed SOC 2 report answers the majority of enterprise security questionnaires permanently — reclaiming your team’s time on every future deal.

90 days
Typical time to SOC 2 readiness

You do not need 18 months. You need the right guide, a realistic scope, and someone who does the implementation work — not just writes the plan.

40–60%
Questionnaire library absorption after 6 months

The response library built through customer security reviews handles 40 to 60% of all future questionnaire questions automatically — every subsequent one faster and cheaper.

What we do

All 13 service lines. Four tiers each.

Every service is built around implementation — not advisory-only engagements that leave you to execute the hard parts alone.

vCISO services

Gap assessment through audit completion. Hands-on control implementation, GRC configuration, full policy library, and auditor coordination.

$8,500 – $65,000+ one-time

SOC 2 / ISO 27001 / 42001 readiness

Gap assessment through audit completion. Hands-on control implementation, GRC configuration, full policy library, and auditor coordination.
$8,500 – $65,000+ one-time

Policy & procedure development

Practical, implementable policies — not boilerplate Word docs from 2019. Customized to your environment, framework-aligned, plain language.

$3,500 – $26,000 one-time

Security awareness training

Behavior change that holds under real pressure. Phishing simulations, role-based paths, department tracks, and framework-mapped records.

$900 – $7,500+ /month

Incident response & tabletop exercises

Build the plan. Run the exercise. Know it works before you need it. Ransomware, breach, insider threat, and board-level crisis scenarios.
$5,500 – $44,000 one-time

Penetration testing coordination

Scoped, managed, closed-loop. Pen test vendor managed by us. Results translated into business-risk language with remediation roadmap.

$2,000 – $20,000 /yr

Vanta & Drata configuration

Turn your GRC platform into a working compliance engine — not a dashboard full of red. Configuration, automation, ongoing health monitoring.

$2,800 – $24,000+

HIPAA & BAA support

Healthcare compliance built for SaaS — not hospital legal departments. Risk analysis, policies, BAA management, and OCR inquiry readiness.

$4,500 – $48,000+

Customer security reviews

If your enterprise customer sends 300 questions at 5 PM Friday, we already built your answers. Managed response, 24–48 hour SLA.

$950 each – $7,500+ /month

GDPR & DPA support

Privacy compliance for companies with EU customers. ROPA, DSAR workflows, sub-processor management, and DPO-as-a-Service at Enterprise tier.

$4,500 – $42,000+

Audit readiness — SOC 2 / ISO 27001

Close the gaps before the auditor finds them. Evidence collection, control narratives, mock walkthroughs, and full auditor coordination.

$4,500 – $42,000 one-time

Vendor risk management

Know who has access to your data and whether to trust them. Vendor inventory, risk tiering, questionnaire management, fourth-party risk.

$2,200 project – $9,500+ /month

Compliance maintenance plan

Stay audit-ready between audits continuously — not just in the 8 weeks before renewal. GRC health, policy maintenance, annual pre-audit sprint.

$1,600 – $9,500+ /month

How we work

From kickoff to audit-ready in four steps

teps A disciplined process built around transparency and implementation — not plans you have to execute alone.
01
Day 1–3
Scoping call

Scope, timeline, total cost

We confirm your framework, urgency, and business driver. You get a clear scope, fee range, and total budget — platform licenses, audit firm fees, all third-party costs — disclosed before you commit.

02
Week 1–2
Readiness assessment

Gap report ranked by impact

We review your policies, controls, and processes. You get a gap report ranked by audit impact — not a generic checklist that sits in a folder and collects dust.

03
Week 2–12
Implementation

We do the actual work

We build what is missing — policies, GRC configuration, evidence workflows, training, vendor risk. We work alongside your team doing the implementation, not just advising on it.

04
Ongoing
Audit & maintenance

Year-round program ownership

We support auditor requests, manage questionnaires, and keep the program running year-round — audit-ready at every point, not just eight weeks before renewal.

Why InfoSecProsHub

Security compliance that works in the real world — built by practitioners, not just auditors.

01

We do the work, not just write the roadmap

We configure the platforms, write the policies, run the tabletops, and coordinate the auditors. Every deliverable is real and auditable — not a deck your team has to execute alone.

01

Built by someone who has sat on both sides

CISSP-certified with credit union security leadership. We know what enterprise procurement actually looks for because we have run those reviews. We build to that bar — not the minimum.

01

Fixed ranges, clear overage rates, no scope creep

Every engagement states hour ranges, overage rates, and discloses platform licenses, audit firm fees, and pen test costs before you sign. Total budget guidance at every scoping call.

04

Compliance does not stop a breach

SOC 2 gets you in the door with enterprise customers. A working IR plan and tested tabletop keep you there when things go wrong. We build both — because clients need to survive the incident.
05

Enterprise-grade requirements at startup speed

Most clients come to us because a deal is on the line. We know how to prioritize accordingly without cutting the corners that cost you in the next audit cycle.

06

The program does not collapse after the audit

Continuous evidence maintenance, GRC monitoring, quarterly reporting, and regulatory change alerts keep you audit-ready all year — not just in the eight weeks before your renewal date.

Who we work with

Four verticals where the stakes are highest

Built for companies under enterprise compliance pressure — where the cost of getting it wrong is greatest.

SaaS companies

Enterprise customers requiring SOC 2 before procurement closes. Sales-driven timelines. Lean or absent internal security teams.

SOC 2
ISO 27001
vCISO

AI & ML companies

Novel risk profiles. Investor due diligence on AI governance. First-mover ISO 42001 compliance for AI systems and models.

ISO 42001
SOC 2
AI governance

FinTech companies

Regulated data environments. SOC 2, GDPR, and PCI DSS combined. Board-level security governance and investor due diligence.

SOC 2
GDPR
PCI DSS

Healthcare SaaS

Health system procurement requires HIPAA plus SOC 2 combined. ePHI workflows, BAA chain management, and OCR readiness.

HIPAA
SOC 2
BAA

Client feedback

What practitioners say about working with us

Yves approaches cybersecurity with a practical mindset, emphasizing solutions that integrate into daily operations. His thoroughness ensured our strategies aligned with regulatory standards while remaining streamlined and accessible, avoiding unnecessary complexity.

CIO
Former CIO, SPIRE Credit Union
Also served as CISO, Blaze Credit Union

We went from a scattered policy library to a working compliance program in under twelve weeks. The audit went exactly as expected — no surprises, no last-minute scrambles. The ability to translate complex requirements into plain language our engineers could act on made all the difference.

CTO
CTO, Series A healthcare SaaS
60 employees · Minneapolis area

We had Vanta purchased and sitting mostly idle. Within three weeks, every integration was live, evidence was collecting automatically, and our control pass rate went from 40% to over 85%. The difference between having the platform and actually using it well is enormous.

SM
Security manager, Series B FinTech
120 employees

Why not alternatives?

How we compare to your other options

Most companies evaluate four paths. Here is an honest comparison.

Estimates. Actual costs vary by scope and company size. ISPH fees include hour estimates and overage rates disclosed upfront.

Standalone products & add-ons

Six high-value engagements that stand on their own

$8,500 – $15,000

ISO 42001 AI governance assessment

Standalone AI security risk assessment for AI and ML startups. Gap analysis, risk register, remediation roadmap. Almost no boutique competition in this space today.

First-mover advantage
$8,000 – $14,000

Investor / pre-fundraise security package

Security posture assessment, gap report, and evidence package for Series A/B investor due diligence. Urgency-driven buyer with a motivated timeline.

Series A / B ready
$3,500 – $6,000

Annual security program review

Formal annual assessment of program maturity, progress, and gaps. Natural January or February renewal product for all vCISO and maintenance clients.

Annual renewal anchor
$3,000 – $6,000

Cyber insurance alignment review

Security controls documentation structured for cyber insurance underwriters. Findings mapped to common coverage requirements. Pairs with any compliance or IR engagement.

Insurance-ready
$1,500 – $3,000

Trust center setup

Post-SOC 2 customer-facing trust page on Vanta or Drata. Natural upsell after every compliance engagement. Eliminates dozens of questionnaire questions permanently.

Post-audit upsell
Custom · bulk discount

VC portfolio security program

Structured program for VC firms placing consistent compliance requirements on portfolio companies. One VC relationship becomes three to five client engagements.

3+ portfolio companies

Common questions

Pre-sales questions we hear most often

Straight answers before you book the call.

Most compliance consultants deliver a binder of policy templates and a gap report, then invoice. We build the program with you — configuring the GRC platform, writing customized policies that reflect how your company actually operates, coordinating the auditor, and managing evidence collection. The deliverable is a working compliance program, not a set of documents requiring your team to execute everything.

Most companies that buy a GRC platform discover getting integrations working, evidence collecting automatically, and controls showing green requires significant configuration work no one on the team has time for. The Vanta and Drata Configuration service (starting at $2,800) is designed exactly for this situation — getting your existing platform from idle to audit-ready.

Total cost depends on scope, but here is a realistic range for a typical Series A SaaS company: ISPH fee $18K–$28K (Growth tier), plus GRC platform license $10K–$25K/year (Vanta or Drata), plus audit firm fee $15K–$40K. Total budget typically falls in the $50K–$100K range for a first SOC 2. We disclose all three numbers at every scoping call — no surprises.

For a single-product SaaS company with a clean cloud environment: SOC 2 Type I in 10–14 weeks. Type II requires an additional observation period of three to six months after Type I. The biggest variables are evidence access speed, cloud complexity, and whether policies need to be built from scratch. We give you a realistic timeline at the scoping call based on your actual situation.

No. InfoSecProsHub provides compliance program management and security implementation — not legal advice or legal representation. For HIPAA and GDPR engagements, OCR inquiries, breach notification letters, DPA negotiations, and supervisory authority interactions should involve legal counsel arranged and paid by the client.

Most compliance programs collapse after the SOC 2 report drops. Evidence stops collecting, policies go unreviewed, and by the next audit cycle you are starting over. The Compliance Maintenance Plan (starting at $1,600/month) prevents that cliff — keeping evidence current, controls active, and the GRC platform healthy year-round so your next audit is a continuation rather than a restart.

Yes — and we recommend it. Enterprise health system procurement increasingly requires both. There is significant control overlap between HIPAA and SOC 2, meaning the combined cost of doing both together is substantially lower than two separate engagements. The multi-framework approach is available at Professional and Enterprise tiers.

The scoping call is a free 30-minute conversation. We confirm your framework, timeline, business urgency, and current state. After the call, you receive a written scope and fee range within 48 hours — including platform license estimates, audit firm fee estimates, and total budget guidance. No sales pressure, no obligation. If we are not the right fit, we will tell you.

Ready to start?

Let's talk about what's blocking your next deal.

A 30-minute scoping call costs nothing and gives you a clear picture of what it takes to get compliant, stay secure, and be ready for what is next.

No pitch. No pressure. A practical conversation about what you need and whether we are the right fit.

Total cost transparency. Every scoping call includes the complete budget — ISPH fee, platform license estimate, and audit firm fee estimate. No surprises at any stage.