ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
AlvorAdvisory
Advisory/All engagements

The catalogue

Every engagement, in one place.

Twenty-nine named engagements across the four delivery tracks. Each carries a typical duration, and every one is scoped in writing before any work begins. Start with one, or ask us where to start.

29 engagements · 4 tracks

Book a consultation
01

AssessThe diagnostic

Know exactly where you stand, and what to fix first.

Explore the track
Full page

Security Program Assessment

Typically 3–4 weeks

Know exactly where you stand, and what to fix first.

Best for a first, complete read of where the program stands.

Full page

Compliance Readiness Assessment

Typically 2–3 weeks

See the exact distance to certification before you commit to the audit.

Best for teams heading into a first certification or surveillance audit.

Full page

Domain Maturity Assessment

Typically 2–3 weeks

Score a single security function against the model built for it.

Best for a deep read of one capability, not the whole program.

Full page

AI Security and Governance Assessment

Typically 2–4 weeks

See where AI is already in your business, and what it exposes.

Best for organisations whose AI adoption is running ahead of governance.

Full page

Incident Response and Resilience Readiness

Typically 2–3 weeks

Know the plan holds before you ever need it.

Best for teams whose IR plan has never been rehearsed.

Full page

Cloud Security Posture Review

Typically 2–4 weeks, sized to the estate

Find what your cloud is actually exposing.

Best for cloud-first teams unsure what their accounts expose.

Full page

Third-Party Risk Assessment

Typically 2–4 weeks

Understand the risk you inherit from the vendors you depend on.

Best for organisations with a growing or unmapped vendor estate.

Full page

Penetration Test and Control Validation

Typically 1–3 weeks per scope

Confirm the controls you rely on actually hold.

Best for teams needing technical proof, not just a paper review.

Full page

Identity and Access Management Assessment

Typically 2–4 weeks

Map who and what can reach your systems, and where that access goes wrong.

Best for teams where identity has sprawled faster than anyone has governed it.

Full page

Essential Eight Maturity Assessment

Typically 2–3 weeks

Know your Essential Eight maturity level, and what it takes to reach the next one.

Best for Australian teams holding themselves to the ACSC baseline.

Full page

APRA CPS 234 Information Security Readiness

Typically 3–4 weeks

Meet the prudential standard your board attests to, with the evidence to prove it.

Best for APRA-regulated entities and the providers who serve them.

Full page

APRA CPS 230 Operational Resilience Readiness

Typically 3–5 weeks

Show you can keep critical operations running through disruption, and that your providers can too.

Best for APRA-regulated entities preparing for CPS 230.

Full page

SOCI Risk Management Program Readiness

Typically 3–5 weeks

Stand up the risk-management program the SOCI Act requires, across all four hazard domains.

Best for responsible entities for assets covered by the SOCI Act.

02

ArchitectThe keystone

Decide what good looks like before a single control is built.

Explore the track
Full page

Target-State Security Architecture

Typically 4–8 weeks

Decide what good looks like before a single control is built.

Best for organisations building or rebuilding the program deliberately.

Full page

Unified Control Framework

Typically 3–6 weeks

Design the control set once and evidence every standard at once.

Best for teams answering to more than one standard.

Full page

Security Strategy and Roadmap

Typically 3–5 weeks

A sequenced path from where you are to the target state.

Best for leaders who need a defensible plan.

Full page

Operating Model and Policy Framework

Typically 3–5 weeks

Decide who owns what, and write it down.

Best for programs that live in one person's head today.

Full page

Identity and Zero Trust Architecture

Typically 4–6 weeks

A focused design for identity, access, and Zero Trust.

Best for teams modernising identity as the new perimeter.

Full page

AI Governance and Control Architecture

Typically 3–6 weeks

An AI control plane, designed before adoption hardens into habit.

Best for organisations putting AI into products or workflows.

03

BuildThe implementation

Stand the controls up, integrate them, and prove they work.

Explore the track
Full page

Remediation Delivery

Sized to the gap register

Close the gap register against the blueprint, control by control.

Best for teams with a blueprint and gaps to close.

Full page

Tooling Selection and Deployment

Typically 6–12 weeks

The right tools chosen against your architecture, not a vendor's roadmap.

Best for teams buying or consolidating security tooling.

Full page

Security Engineering and Automation

Typically 4–10 weeks

Controls that hold without anyone remembering to apply them.

Best for engineering-led teams scaling controls.

Full page

Audit Preparation

Typically 4–8 weeks

Walk into the assessment ready.

Best for teams with an audit date on the calendar.

Full page

Security PMO and Enablement

Runs with the build

The program run to a plan, and your team brought up to speed.

Best for organisations standing up a security program at pace.

04

OperateThe managed service

Stay audit-ready all year, without rebuilding the capability yourself.

Explore the track
Full page

Managed Compliance

Standing, reviewed on your terms

Stay audit-ready all year, without rebuilding the capability yourself.

Best for certified teams who must stay certified.

Full page

Virtual CISO and Fractional Leadership

Standing, sized to you

The leadership of an in-house team, without the hire.

Best for teams not ready for a full-time CISO.

Full page

Continuous Control Monitoring

Standing, reviewed quarterly

Posture tracked, not assumed.

Best for leaders who want posture they can prove.

Full page

Managed Third-Party Risk

Standing, sized to the estate

Vendor risk run for you, as a standing service.

Best for teams with a large or fast-moving vendor estate.

Full page

Security Program Management

Standing, reviewed on your terms

The wider program run for you, end to end.

Best for organisations outsourcing the run, not just the build.

Not sure where to start? That is a fine place to start.

Book a consultation
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security, Simplified.

Platform

  • Overview
  • AI Assistant
  • Security Architecture
  • Assets
  • Components
  • Dependency Mapping
  • Data Governance
  • Secure by Design
  • Security Design Review
  • Threat Modeling
  • Risk
  • Compliance
  • Policy
  • Program
  • Business Continuity
  • TPRM

Solutions

  • Startups
  • Mid-Market
  • Enterprise

Company

  • About
  • Advisory
  • Compliance
  • Blog
  • Security
  • Pricing
  • Compare

Legal

  • Privacy
  • Cookie Policy
  • Terms
  • Disclosure

© 2026 Alvor, Inc. All rights reserved.

LinkedIn