MITG
SGE

Security Governance & Engineering

SGE connects security strategy and governance with the engineering that implements them. Where you have a security leader, MITG works as an extension of their organization and handles engineering and program execution under their direction. Where you do not, MITG’s CISO office provides that leadership.

What the program includes

01Security policy development and maintenance
02Compliance oversight against the frameworks that apply to you
03Attack surface reduction and hardening
04Security information and event management (SIEM) deployment and tuning
05Email security and access control
06Defenses and controls implemented proactively as new threats emerge
07A managed security awareness program with phishing simulation
08Disaster recovery readiness with tracked recovery testing
09Tabletop exercises and reporting for your leadership and board
10Incident response plan maintenance
11Security review of your vendors
12Cyber insurance renewal support
Common model
Adviser
Writes the policy
Handoff
Implementer
Hardens the environment
SGE
One teamStrategy · Policy · Hardening · Verification · Board reporting

Strategy, policy, and implementation stay with one accountable team.

Board report excerpt · illustrativeQuarterly, for leadership and the board
MeasurePrior quarterThis quarter
Open remediation items, high severity73
Multi-factor authentication coverage, user accounts96%100%
Phishing simulation click rate6.1%3.4%
Policies reviewed within the last 12 months10 of 1212 of 12
Disaster recovery testCompleted, 2 findingsCompleted, findings closed
Incidents requiring joint response10

Every value shown is illustrative. Reporting for your leadership and board is part of the program.

Strategy and execution from one team

The MITG team that sets your security strategy and writes your policies also implements the controls. There is no handoff from an adviser to a separate implementer, and the people accountable for the plan are the people doing the work.

Schedule an introduction