TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one agreement Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Our Services

Security leadership, and everything it needs to work.

Some of what follows we do ourselves. Some of it we deliver through a partner network we select and manage. We'll tell you which is which on any engagement, and either way there is one contract, one team accountable, and one number to call when something goes wrong.

How we deliver

How the work gets done

The model is worth explaining, because it is the reason a college security office of two or a forty-person firm can get coverage that used to require a security department.

OUR TEAM

The judgment work

Security leadership, assessments, governance, policy, compliance, testing, and incident response. This is the part that depends on someone knowing your environment and your politics, so it stays with people you'll recognize by name.

OUR PARTNER NETWORK

The platform work

Round-the-clock monitoring, endpoint and identity detection, next-generation firewalls, filtering, email security. We select the technology, deploy it, tune it, and manage it. You get one invoice and one escalation path, not a stack of vendor relationships to maintain.

WHATEVER YOU ALREADY OWN

The tools you already own

We're deliberately technology-agnostic. If the tools you own work, we keep them and tune them.

Where most people start

Four flagship engagements.

Almost everyone begins with one of these, then adds from the catalogue below once we both understand the environment.

01

Cyber Risk Assessment

A working review with our CISO covering your technology, your policies, your procedures, and your people. We score you against a defined maturity framework and hand back a roadmap ordered by what would hurt most if it went wrong, with realistic timing and cost against each item.

This is the front door for almost everyone we work with. Scope and price are agreed up front, and the document is yours to keep whether or not you engage us further.

Executive risk reportMaturity index score90-day roadmapBoard-ready
02

Virtual CISO & Advisory CIO

A full-time chief information security officer costs well north of $250,000 a year, and the good ones are hard to keep in a district or a forty-person firm. Our vCISO service gives you that seniority on a retainer: strategy, risk decisions, vendor evaluation, board and cabinet reporting, and someone accountable when the question is serious.

The advisory CIO service covers the same ground for broader technology decisions. Both work well as interim coverage during a search, and both are common for organizations that will never justify the full-time role. For higher education, the vCISO also fills the Qualified Individual role that the FTC Safeguards Rule requires.

Monthly retainerBoard reportingInterim coverageQualified Individual
03

Incident Response Retainer

An incident is a bad time to be choosing a responder and negotiating terms. Retainer clients get a defined response time written into the agreement, a named contact who already knows the environment, and a response plan written and rehearsed in advance.

We coordinate with your insurer and your counsel, help with disclosure obligations, and stay through the rebuild. We do this work for organizations that aren't on retainer too, but the early hours go very differently when a plan exists.

Defined response timeNamed contactForensicsInsurance & legal coordination
04

24/7 Managed Detection & Response

Continuous monitoring across endpoints, identity, network, and cloud, with analysts reviewing what the tooling surfaces so an alert reaches you because it matters. Endpoint detection and response, identity threat detection, log management, and threat hunting run underneath it.

For school districts: MS-ISAC moved to paid membership in October 2025 when its federal funding ended, and many districts lost the round-the-clock monitoring they had relied on for years. This service replaces it.

MDREDR / XDRITDRSIEM & log managementThreat hunting
AI security

Governance for the AI tools your staff already use.

IBM's 2026 breach research found shadow AI involved in 43% of security incidents, more than double the year before, and that more than two thirds of organizations had no governance limiting unauthorized AI use. In the same study, 92% of organizations that suffered an attack on their AI systems had not implemented proper access controls.

FIND IT

Discover what's in use

Shadow AI discovery across browsers, extensions, SaaS, and endpoints. In most organizations the AI strategy is whatever staff signed up for themselves, and the inventory is usually a surprise.

GOVERN IT

Put a policy and an owner behind it

Acceptable use, approval workflow, vendor review, training, and a named person accountable. Mapped to NIST AI RMF and ISO/IEC 42001 where a certification would help you win business.

DEFEND IT

Controls at the point of use

AI runtime defense at the gateway, guardrails against prompt injection and data leakage, least-privilege access to AI systems, and identity for agents that currently share credentials with nobody watching.

Permissions before Copilot

Turning on Microsoft 365 Copilot or Google Gemini doesn't create new permissions. It surfaces the ones you already had, including years of accumulated sharing mistakes, which is why Microsoft's own guidance says to clean up permissions before the rollout. We do that review first, and it is usually the cheapest fix on the list.

Agents change the risk entirely

An AI that answers questions creates a data-handling problem; an AI that takes actions creates an access problem. Agents routinely share credentials, have no individual identity, and can't be audited one at a time. NSA published guidance on Model Context Protocol security in 2026, and CISA with its Five Eyes partners issued joint guidance on adopting agentic AI carefully. We build to both.

We work to the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, MITRE ATLAS, the CSA AI Controls Matrix, NIST AI RMF and the emerging NIST control overlays for AI systems, and ISO/IEC 42001.

The full catalogue

Twelve domains, one agreement.

This is the full map of what we cover, directly or through partners we manage. The judgment work stays with our team; the platform work runs through partners we select and hold the contract for. If something you need isn't here, ask.

Security Leadership & Program

Senior leadership, on retainer.

Virtual CISOAdvisory CIOSecurity program development Multi-year roadmap & budget planningBoard & cabinet reporting Interim coverage during a vacancySecurity tool rationalization M&A and investment cyber diligencePost-close portfolio remediation Security staffing advisory

Governance, Risk & Compliance

Policy, audits, and the frameworks that apply to you.

Cyber risk assessmentRisk quantificationFramework gap assessment Policy & standards developmentAudit preparation & evidence Third-party risk managementSupply chain risk Cyber insurance readinessBusiness impact analysis Continuity & disaster recovery planningRecords retention & data minimization Regulatory reporting readiness

Detection & Response

Monitoring, and a rehearsed response.

24/7 SOC monitoringManaged detection & response (MDR) Endpoint detection & response (EDR / XDR)Identity threat detection (ITDR) SIEM & log managementThreat huntingThreat intelligence Incident response retainerDigital forensics Ransomware containment & recoveryBreach notification support Post-incident review

Endpoint & Device

Laptops, phones, and Chromebooks.

Endpoint protection deploymentMobile device management Patch & vulnerability managementHardening baselines 1:1 device fleet managementSecure enterprise browser Removable media controlSecure disposal & data sanitization

Identity & Access

Accounts, access, and MFA.

Single sign-on & federationMulti-factor authentication rollout Conditional access designPrivileged access management Identity governance & administrationIdentity security posture management Machine & non-human identityJoiner / mover / leaver automation Dark web credential monitoringSecrets management

Network & Infrastructure

Firewalls, segmentation, and the wireless estate.

Next-generation & AI-assisted firewallsFirewall management & tuning Network segmentation & microsegmentationZero trust architecture Secure access service edge (SASE / SSE)DNS & web content filtering Network access controlIntrusion detection & prevention Wired & wireless infrastructure auditRemote access & VPN OT, IoT & building systemsCamera & access control security

Cloud, SaaS & Application

Microsoft 365, Google Workspace, and cloud.

Microsoft 365 hardeningGoogle Workspace hardening Cloud security posture managementCloud-native application protection SaaS security posture managementShadow IT discovery Application security posture managementSecure configuration baselines API security reviewContainer & Kubernetes security Cloud entitlement management

Data Protection & Resilience

Backups, recovery, and data loss prevention.

Backup design & immutabilityRestore testing Disaster recovery engineeringData loss prevention Data security posture managementData discovery & classification Encryption at rest & in transitEmail security & anti-phishing Secure file transferPost-quantum readiness assessment

Offensive Security & Exposure

Penetration testing and red team.

External & internal penetration testingWeb & mobile application testing Wireless penetration testingSocial engineering assessment Physical security assessmentRed team & purple team exercises Vulnerability assessment & scanningExternal attack surface management Continuous threat exposure managementAdversarial exposure validation

AI Security & Governance

Shadow AI, governance, and runtime defense.

AI runtime defense (AI gateway + guardrails)Prompt injection & jailbreak mitigation AI acceptable use policyAI governance program build NIST AI RMF & ISO/IEC 42001 alignmentShadow AI discovery AI security posture managementAI data loss prevention Copilot & Gemini tenant oversharing remediationAI access control & least privilege Agentic AI governanceAI agent identity & credentials MCP server security reviewAI browser & extension risk AI red teaming & adversarial testingModel scanning & provenance AI-BOM / ML-BOMAI supply chain security Deepfake & voice-clone process defensesAI vendor & feature risk review AI incident response & tabletopsAI literacy & staff training AI-assisted detection & triageAssessment redesign for academic integrity

Human Risk & Awareness

Training, phishing simulation, and deepfake awareness.

Security awareness trainingPhishing simulation Role-based training for finance, HR & executivesAI & deepfake awareness Tabletop exercisesExecutive & board briefings Onboarding & offboarding securityHuman risk management program

Education-Specific

The requirements that only exist in education.

Student data privacy agreements & DPA registryEd-tech app vetting workflow COPPA compliance programCIPA filtering & certification records Student safety & self-harm alert monitoringFERPA program review HECVAT 4 completion & inbound triageGLBA & Safeguards for financial aid Research data security & CUI enclavesE-Rate & FCC Pilot support MS-ISAC transition advisoryBoard reporting written for public record
Compliance

The frameworks we work in, and keep current on.

We track the versions so you don't have to. A few that moved recently and catch people out: ISO 27001:2013 certificates expired in October 2025, PCI DSS 4.0.1 lost its grace period in March 2025, COPPA's amended rule reached full compliance in April 2026, and the Department of Defense suspended the CMMC Phase 2 transition in July 2026 while Phase 1 self-assessment stays in force.

NIST CSF 2.0NIST SP 800-171NIST SP 800-53 CIS Controls v8.1ISO/IEC 27001:2022SOC 2 PCI DSS 4.0.1CMMCHIPAA Security Rule FTC Safeguards RuleGLBAFERPACOPPA CIPAHECVAT 4SEC Regulation S-P SEC cyber disclosureState privacy laws State student data privacyGDPRNIS2 flow-down NIST AI RMFISO/IEC 42001
A fair question

"How can a company your size do all of that?"

Because the model is built for it, and because we'd rather answer this directly than let you wonder.

Security leadership, assessments, governance and compliance work, policy, audit support, penetration testing, training, tabletop exercises, incident response, and the education-specific work. That's the judgment-dependent half of the list and it stays in-house. Ask us on any engagement who is doing what and we'll tell you, in writing if you want it.
Monitoring, endpoint and identity detection, firewalls, filtering, email security, and backup platforms come through partners we've selected and worked with over years. We handle selection, deployment, tuning, and day-to-day management, and we hold the relationship. You sign one agreement with us. When something breaks overnight you call us, and a person answers.
A reseller sells you a product and moves on. We're accountable for whether your organization is defensible, which is a different job and a much harder one to walk away from. The technology is a means to that. It's also why we're comfortable telling a client that the tool they already own is fine and they should spend the money elsewhere.
Most of our clients do, and it works well. Managed service providers keep systems running; we're accountable for whether they're defensible. We're happy to work alongside whoever is already there rather than displacing them, and in higher education we normally operate alongside a full central IT organization.
Yes. Nothing on this page requires you to take anything else. Plenty of clients engage us for a single penetration test or one compliance project and never buy anything further, and that's a perfectly good outcome for both of us.

Not sure which of these you need?

The first conversation is free and takes about half an hour. You leave knowing which two or three of these would move your risk the most.