Who owns cyber risk at your company?
You get the answer in writing, including which processes have never been tested.
Many expensive cyber failures
are not expertise failures
They are coordination failures. Specialists see their own domain clearly. Nobody owns the gaps or contradictions between them.
Legal assumes IT is handling it. IT assumes the security provider is handling it. The provider's contract says something narrower than anyone remembers agreeing to. None of these people are wrong. Each of them is describing part of an elephant, but none of them describes the elephant.
A controls assessment tells you whether 153 safeguards exist. It can't tell you how your team would act on any of them at 2am.
None of it surfaces until an incident, which is the most expensive moment to find it.
Nobody did anything wrong
- A vendor emails accounts payable with updated banking details.
- Accounts payable determines the email is from a legitimate source — the same vendor contact as usual. The internal protocols are followed and the necessary parties approve the change.
- Two more invoices are paid on the new details before the vendor calls to ask why it has not been paid in six weeks.
- Finance asks IT to review the email exchange. IT finds no compromise, because there was never one on your side. The vendor’s own email was compromised weeks earlier.
- Legal says the vendor contract includes breach notification requirements, but the alert routes to a former employee.
- You ask whether your cyber insurance covers this and discover it does not. The policy covers computer fraud, and this was an authorized transfer made by an employee.
What the gaps could cost you
on the day it matters
An unowned question is quiet until something forces the answer. Then it is answered under time pressure, by whoever is in the room, and at a price nobody planned for.
- Decisions made twice, or not at all, while people wait on authority nobody actually holds
- Forensic hours spent establishing facts someone in the building already knows
- Legal fees for questions that had answers, asked because nobody knew where to look
- Notification clocks running while administrative tasks are sorted out
- Employees asking questions you do not have answers to
- Vendors engaged outside your carrier’s panel, for work another provider is already paid to do
- Systems taken offline without knowing whether the evidence was preserved first
- Twelve people on a call that needed four, because nobody could say which four
None of this is the attack. It is the disorganization an attack finds when it arrives — and it is the only piece that is entirely knowable in advance. It is the part we can do something about.
The Cyber Risk Ownership Map
I interview every function that touches cyber risk โ leadership, finance, legal, operations, technology, HR โ and compare the answers against each other and against your documents.
My findings live in the comparison, not in any single answer. When four people each name a different risk owner, that disagreement is invisible from any assessment completed by a single one of them, no matter how many items it contains. An answer could also be technically correct and operationally meaningless at the same time.
The catch is that not every disagreement matters. Two people describing the same handoff differently may be harmless. Two people each assuming the other owns notification responsibility is probably not.
Agreement can also be misleading. When IT and Legal both say a device can be isolated, one means it is technically possible and the other means it is legally permissible — but neither is saying whether your cyber policy covers the operational downtime.
Telling these issues apart, and knowing which order to close them in, takes experience-based judgment. That is what you are hiring.
What it looks like on paper
The rest are working documents, not a report that gets filed. The next time someone asks โ a customer, a carrier, your board โ you know what is true, what is contested, and what you can defend.
Two ways to start
Executive Diagnostic
A structured interview and a short document request, ending in two of the Assessment's written deliverables โ built from a single perspective rather than compared across several. Includes an honest recommendation, which is sometimes that you do not need more.
- One 90-minute executive interview
- Executive Brief and Ranked Findings
- No interviews or deliverables beyond the above
Cyber Risk Ownership Assessment
The full engagement. Interviews across every related function, document review, an Ownership Map showing who owns what risk and what has never been tested, and a facilitated session where leadership closes the open decisions. Three weeks from kickoff, once interviews are scheduled.
- Eight domains, every related function interviewed — up to eight interviews
- Executive Brief, Ownership Map, Ranked Findings
- Compounding Analysis, Execution Roadmap, Executive Workbook
- Team Alignment Session
Both services are flat-rate engagements at a fixed tier. You get the total cost before any work begins, and it does not change — no hourly billing, no scope additions halfway through.
Ownership Review
For organizations that want the position reassessed rather than assumed. A status review against the original Ownership Map: what closed, what slipped, and what is newly exposed โ new vendors, new obligations, new people in the seats. Scoped after the first engagement, on a defined cadence, with board-ready reporting.
Who this is for
A good fit
- Big enough that every function has a specialist. Not big enough that anyone owns the space between them
- Cybersecurity is whatever your IT team or security provider does. Nothing sits above them
- You have made security promises in customer contracts, insurance applications, or federal awards, and nobody has verified you can keep them
- Nobody can say exactly what data you hold, where it lives, or who else has a copy
- You do not know what to ask your teams about cyber risk, and they do not know what to ask each other
Not a fit
- You need a SOC 2 audit, an ISO certification, penetration testing, or a technical controls review
- You need legal counsel, representation, or attorney work product
- You want a fractional or virtual CISO
- You want someone to implement or manage the fix, not to diagnose the problem
- You want a document to show a customer, not a change in how you operate
Nobody matches all of these. If two of them describe you, the conversation is worth having.
If you are in the second column, tell me what you are trying to solve and I will point you at who does it well.
What this is not
Not legal advice, legal analysis, or representation. No determination of whether any legal, regulatory, or contractual obligation is satisfied. Not a compliance or certification engagement โ no SOC 2, no audit, no attestation. No penetration testing, vulnerability scanning, or configuration review. No implementation, no remediation, no products, no procurement.
Passing an audit tells you the controls exist. It does not tell you who would act on them, and that is where my work begins.
Contractual, regulatory, and insurance commitments are examined for ownership and verification โ who is responsible for meeting them, and whether anyone has confirmed you can. Whether a given obligation is legally satisfied is a question for counsel.
The exclusions are the point of my work. I have nothing downstream to sell you, which is why the findings can be trusted. Where a legal, technical, or compliance question comes up, it gets referred โ never quietly absorbed.
I cannot tell you what the answer should be. I can tell you exactly what to ask, and who should be answering.
What you can hold me to
- Independence. No fee, commission, or revenue share from any firm, provider, broker, or carrier I refer you to. Ever.
- Confidentiality. Nothing here is privileged, and I say so plainly. Findings never leave the engagement in a form that identifies you, and whether you are ever named as a client at all is entirely your decision.
- No one is named in the findings. They are reported as counts and patterns. The question is where responsibility is undefined, not who failed to claim it.
- Ruthless prioritization. Not 150 findings of equal weight. One page tells you what matters and what to do first.
- A number before you commit. Flat-rate tiers, quoted in full before any work begins. What we agree at the start is what you pay at the end.
- An honest no. If an assessment would not help you, I will say so before you pay for one.
Jessica Jasper
I have advised companies through cyber incidents, led state regulatory investigations, applied compliance by design in software, handled legal operations in-house, and served at the FBI.
In every one of those roles I did the same thing โ translated between specialists who were each right about their own part and could not follow each other. My Assessment is that work, done before an incident instead of after.
Next steps
Tell me what prompted you to look for help. I will tell you honestly whether I can, or whether someone else should.
The work is the same whenever you do it. What changes is whether you are doing it on your own schedule or someone else's.

