Who owns cyber risk at your company?

You get the answer in writing, including which processes have never been tested.

The problem

Many expensive cyber failures
are not expertise failures

They are coordination failures. Specialists see their own domain clearly. Nobody owns the gaps or contradictions between them.

Legal assumes IT is handling it. IT assumes the security provider is handling it. The provider's contract says something narrower than anyone remembers agreeing to. None of these people are wrong. Each of them is describing part of an elephant, but none of them describes the elephant.

A controls assessment tells you whether 153 safeguards exist. It can't tell you how your team would act on any of them at 2am.

None of it surfaces until an incident, which is the most expensive moment to find it.

Nobody did anything wrong

An illustration — not a real engagement.
  • A vendor emails accounts payable with updated banking details.
  • Accounts payable determines the email is from a legitimate source — the same vendor contact as usual. The internal protocols are followed and the necessary parties approve the change.
  • Two more invoices are paid on the new details before the vendor calls to ask why it has not been paid in six weeks.
  • Finance asks IT to review the email exchange. IT finds no compromise, because there was never one on your side. The vendor’s own email was compromised weeks earlier.
  • Legal says the vendor contract includes breach notification requirements, but the alert routes to a former employee.
  • You ask whether your cyber insurance covers this and discover it does not. The policy covers computer fraud, and this was an authorized transfer made by an employee.
Every person in this chain followed a process that existed, and every decision was defensible on its own. The failure lived in the handoffs nobody owned — Finance verifying a banking change against a number Operations already had, Legal comparing the insurance policy against how Finance actually pays people, Operations and IT reconciling the notification contacts against who still works here. These are the questions I ask.
How it compounds

What the gaps could cost you
on the day it matters

An unowned question is quiet until something forces the answer. Then it is answered under time pressure, by whoever is in the room, and at a price nobody planned for.

  • Decisions made twice, or not at all, while people wait on authority nobody actually holds
  • Forensic hours spent establishing facts someone in the building already knows
  • Legal fees for questions that had answers, asked because nobody knew where to look
  • Notification clocks running while administrative tasks are sorted out
  • Employees asking questions you do not have answers to
  • Vendors engaged outside your carrier’s panel, for work another provider is already paid to do
  • Systems taken offline without knowing whether the evidence was preserved first
  • Twelve people on a call that needed four, because nobody could say which four

None of this is the attack. It is the disorganization an attack finds when it arrives — and it is the only piece that is entirely knowable in advance. It is the part we can do something about.

The method

The Cyber Risk Ownership Map

I interview every function that touches cyber risk โ€” leadership, finance, legal, operations, technology, HR โ€” and compare the answers against each other and against your documents.

My findings live in the comparison, not in any single answer. When four people each name a different risk owner, that disagreement is invisible from any assessment completed by a single one of them, no matter how many items it contains. An answer could also be technically correct and operationally meaningless at the same time.

The catch is that not every disagreement matters. Two people describing the same handoff differently may be harmless. Two people each assuming the other owns notification responsibility is probably not.

Agreement can also be misleading. When IT and Legal both say a device can be isolated, one means it is technically possible and the other means it is legally permissible — but neither is saying whether your cyber policy covers the operational downtime.

Telling these issues apart, and knowing which order to close them in, takes experience-based judgment. That is what you are hiring.

01Governance & Ownership
02Incident Readiness
03Security Oversight
04Data & Privacy Ownership
05Vendors & Commitments
06Insurance & Financial Recovery
07Regulatory Awareness
08Personnel & Access
ContestedNamed as someone’s responsibility by one or more people. Accepted by none. The most dangerous state, because it looks like coverage from every direction.
UnownedNo owner identified by anyone. A known gap rather than a false comfort.
Owned, untestedSomeone is responsible. Nothing has ever been exercised or verified.
CurrentOwned, tested within a reasonable interval, and evidenced.
The deliverables

What it looks like on paper

For the boardExecutive BriefOne page. Where you stand, and the three findings to address first.
For your team leadsOwnership MapEvery domain marked contested, unowned, untested, or current.
For the CEO and counselRanked FindingsEvery finding, ranked by its potential impact during a real incident, and who should respond to it.
For the skeptic in the roomCompounding AnalysisThe narrative that connects the findings โ€” why they matter together rather than one at a time.
For the person holding the budgetExecution RoadmapWhat to do first, which items depend on others, how long each should take, and how you know when it is done.
For the risk managerExecutive WorkbookEvery inquiry recorded and every finding given a target condition, so progress can be tracked and evidenced without going back to the report.
For everyone, in one room Team Alignment Session A facilitated working session, not a presentation. The findings are on the table and the open questions get settled while everyone is present: who will own each one going forward, by when, and what does done look like. Decisions are recorded as they are made, and become the first entries in the Execution Roadmap. No finding is attributed to any individual โ€” the session assigns responsibility, it does not assign fault.

The rest are working documents, not a report that gets filed. The next time someone asks โ€” a customer, a carrier, your board โ€” you know what is true, what is contested, and what you can defend.

How to work together

Two ways to start

Executive Diagnostic

One week · Cost may be credited toward the Assessment

A structured interview and a short document request, ending in two of the Assessment's written deliverables โ€” built from a single perspective rather than compared across several. Includes an honest recommendation, which is sometimes that you do not need more.

  • One 90-minute executive interview
  • Executive Brief and Ranked Findings
  • No interviews or deliverables beyond the above

Cyber Risk Ownership Assessment

Three weeks ยท up to 8 interviews

The full engagement. Interviews across every related function, document review, an Ownership Map showing who owns what risk and what has never been tested, and a facilitated session where leadership closes the open decisions. Three weeks from kickoff, once interviews are scheduled.

  • Eight domains, every related function interviewed — up to eight interviews
  • Executive Brief, Ownership Map, Ranked Findings
  • Compounding Analysis, Execution Roadmap, Executive Workbook
  • Team Alignment Session

Both services are flat-rate engagements at a fixed tier. You get the total cost before any work begins, and it does not change — no hourly billing, no scope additions halfway through.

After an assessment

Ownership Review

For organizations that want the position reassessed rather than assumed. A status review against the original Ownership Map: what closed, what slipped, and what is newly exposed โ€” new vendors, new obligations, new people in the seats. Scoped after the first engagement, on a defined cadence, with board-ready reporting.

Fit

Who this is for

A good fit

  • Big enough that every function has a specialist. Not big enough that anyone owns the space between them
  • Cybersecurity is whatever your IT team or security provider does. Nothing sits above them
  • You have made security promises in customer contracts, insurance applications, or federal awards, and nobody has verified you can keep them
  • Nobody can say exactly what data you hold, where it lives, or who else has a copy
  • You do not know what to ask your teams about cyber risk, and they do not know what to ask each other

Not a fit

  • You need a SOC 2 audit, an ISO certification, penetration testing, or a technical controls review
  • You need legal counsel, representation, or attorney work product
  • You want a fractional or virtual CISO
  • You want someone to implement or manage the fix, not to diagnose the problem
  • You want a document to show a customer, not a change in how you operate

Nobody matches all of these. If two of them describe you, the conversation is worth having.

If you are in the second column, tell me what you are trying to solve and I will point you at who does it well.

Scope

What this is not

Not legal advice, legal analysis, or representation. No determination of whether any legal, regulatory, or contractual obligation is satisfied. Not a compliance or certification engagement โ€” no SOC 2, no audit, no attestation. No penetration testing, vulnerability scanning, or configuration review. No implementation, no remediation, no products, no procurement.

Passing an audit tells you the controls exist. It does not tell you who would act on them, and that is where my work begins.

Contractual, regulatory, and insurance commitments are examined for ownership and verification โ€” who is responsible for meeting them, and whether anyone has confirmed you can. Whether a given obligation is legally satisfied is a question for counsel.

The exclusions are the point of my work. I have nothing downstream to sell you, which is why the findings can be trusted. Where a legal, technical, or compliance question comes up, it gets referred โ€” never quietly absorbed.

I cannot tell you what the answer should be. I can tell you exactly what to ask, and who should be answering.

Commitments

What you can hold me to

  • Independence. No fee, commission, or revenue share from any firm, provider, broker, or carrier I refer you to. Ever.
  • Confidentiality. Nothing here is privileged, and I say so plainly. Findings never leave the engagement in a form that identifies you, and whether you are ever named as a client at all is entirely your decision.
  • No one is named in the findings. They are reported as counts and patterns. The question is where responsibility is undefined, not who failed to claim it.
  • Ruthless prioritization. Not 150 findings of equal weight. One page tells you what matters and what to do first.
  • A number before you commit. Flat-rate tiers, quoted in full before any work begins. What we agree at the start is what you pay at the end.
  • An honest no. If an assessment would not help you, I will say so before you pay for one.
Who you would be working with

Jessica Jasper

I have advised companies through cyber incidents, led state regulatory investigations, applied compliance by design in software, handled legal operations in-house, and served at the FBI.

In every one of those roles I did the same thing โ€” translated between specialists who were each right about their own part and could not follow each other. My Assessment is that work, done before an incident instead of after.

Next steps

Tell me what prompted you to look for help. I will tell you honestly whether I can, or whether someone else should.

The work is the same whenever you do it. What changes is whether you are doing it on your own schedule or someone else's.