TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one partner Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Our Services

If it's part of protecting your organization, it's in scope.

Some of what follows we do ourselves. Some of it we deliver through a partner network we've spent years assembling and vetting. You don't need to know or care which is which, because either way there's one contract, one team accountable, and one number to call when something goes wrong.

How we deliver

Three ways work gets done, and we're upfront about all of them.

Plenty of firms quietly subcontract and hope nobody asks. We'd rather explain it, because the model is the reason a forty-person firm can get coverage that used to require a security department.

OUR TEAM

The judgment work

Security leadership, assessments, governance, policy, compliance, testing, and incident response. This is the part that depends on someone knowing your environment and your politics, so it stays with people you'll recognize by name.

OUR PARTNER NETWORK

The platform work

Round-the-clock monitoring, endpoint and identity detection, next-generation firewalls, filtering, email security. We select the technology, deploy it, tune it, and manage it. You get one invoice and one escalation path, not a stack of vendor relationships to maintain.

WHATEVER YOU ALREADY OWN

The stuff you've already bought

We're deliberately technology-agnostic. If you've already paid for tools, our first move is making them actually perform rather than selling you replacements. Ripping out working technology to fit our preferences would be a good deal for us and a bad one for you.

Where most people start

Four flagship engagements.

Almost everyone begins with one of these, then adds from the catalogue below once we both understand the environment.

01

Cyber Risk Assessment

A working review with our CISO covering your technology, your policies, your procedures, and your people. We score you against a defined maturity framework and hand back a roadmap ordered by what would hurt most if it went wrong, with realistic timing and cost against each item.

This is the front door for almost everyone we work with. Scope and price are agreed up front, and the document is yours to keep whether or not you engage us further.

Executive risk reportMaturity index score90-day roadmapBoard-ready
02

Virtual CISO & Advisory CIO

A full-time chief information security officer costs well north of $250,000 a year, and the good ones are hard to keep in a district or a forty-person firm. Our vCISO service gives you that seniority on a retainer: strategy, risk decisions, vendor evaluation, board and cabinet reporting, and someone accountable when the question is serious.

The advisory CIO service covers the same ground for broader technology decisions. Both work well as interim coverage during a search, and both are common for organizations that will never justify the full-time role. For higher education, the vCISO also fills the Qualified Individual role that the FTC Safeguards Rule requires.

Monthly retainerBoard reportingInterim coverageQualified Individual
03

24/7 Managed Detection & Response

Continuous monitoring across endpoints, identity, network, and cloud, with analysts reviewing what the tooling surfaces so an alert reaches you because it matters. Endpoint detection and response, identity threat detection, log management, and threat hunting run underneath it.

This is worth saying plainly to school districts: MS-ISAC moved to paid membership in October 2025 when its federal funding ended, and a lot of districts quietly lost round-the-clock monitoring they'd relied on for years without replacing it. If that's you, this is the gap.

MDREDR / XDRITDRSIEM & log managementThreat hunting
04

Incident Response Retainer

The worst time to work out who you're calling is while your systems are encrypting. Retainer clients get a guaranteed response time, a named contact who already knows the environment, and a response plan written and rehearsed in advance.

We coordinate with your insurer and your counsel, help with disclosure obligations, and stay through the rebuild. We do this work for organizations that aren't on retainer too, but the difference in how the first six hours go is significant.

Guaranteed SLANamed contactForensicsInsurance & legal coordination
AI security

Your people are already using AI. The question is whether anyone is governing it.

IBM's 2026 breach research found shadow AI involved in 43% of security incidents, more than double the year before, and that more than two thirds of organizations had no governance limiting unauthorized AI use. In the same study, 92% of organizations that suffered an attack on their AI systems had not implemented proper access controls.

FIND IT

Discover what's actually in use

Shadow AI discovery across browsers, extensions, SaaS, and endpoints. In most organizations the AI strategy is whatever staff signed up for themselves, and the first honest inventory is uncomfortable reading.

GOVERN IT

Put a policy and an owner behind it

Acceptable use, approval workflow, vendor review, training, and a named person accountable. Mapped to NIST AI RMF and ISO/IEC 42001 where a certification would help you win business.

DEFEND IT

Controls at the point of use

AI runtime defense at the gateway, guardrails against prompt injection and data leakage, least-privilege access to AI systems, and identity for agents that currently share credentials with nobody watching.

The one most people miss

Turning on Microsoft 365 Copilot or Google Gemini doesn't create new permissions. It surfaces the ones you already had, including two decades of accumulated sharing mistakes. Microsoft publishes guidance on this because it is the single most common way a copilot rollout goes wrong. Fixing permission sprawl before you switch it on is cheap. Explaining afterward why the assistant summarized the salary file is not.

Agents change the risk entirely

An AI that answers questions is a data problem. An AI that takes actions is an access problem. Agents routinely share credentials, have no individual identity, and can't be audited per agent. NSA published guidance on Model Context Protocol security in 2026, and CISA with its Five Eyes partners issued joint guidance on adopting agentic AI carefully. We build to both.

We work to the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, MITRE ATLAS, the CSA AI Controls Matrix, NIST AI RMF and the emerging NIST control overlays for AI systems, and ISO/IEC 42001.

The full catalogue

Twelve domains. Nothing you'd have to go elsewhere for.

This is the complete list, including the specialist work most providers our size send you away for. If something you need isn't here, ask anyway. The answer is usually yes.

Security Leadership & Program

Someone senior who owns the outcome.

Virtual CISOAdvisory CIOSecurity program development Multi-year roadmap & budget planningBoard & cabinet reporting Interim coverage during a vacancySecurity tool rationalization M&A and investment cyber diligencePost-close portfolio remediation Security staffing advisory

Governance, Risk & Compliance

Written down, current, followed, and defensible.

Cyber risk assessmentRisk quantificationFramework gap assessment Policy & standards developmentAudit preparation & evidence Third-party risk managementSupply chain risk Cyber insurance readinessBusiness impact analysis Continuity & disaster recovery planningRecords retention & data minimization Regulatory reporting readiness

Detection & Response

Somebody watching while you sleep, and a plan for the bad day.

24/7 SOC monitoringManaged detection & response (MDR) Endpoint detection & response (EDR / XDR)Identity threat detection (ITDR) SIEM & log managementThreat huntingThreat intelligence Incident response retainerDigital forensics Ransomware containment & recoveryBreach notification support Post-incident review

Endpoint & Device

Every laptop, phone, and Chromebook you're responsible for.

Endpoint protection deploymentMobile device management Patch & vulnerability managementHardening baselines 1:1 device fleet managementSecure enterprise browser Removable media controlSecure disposal & data sanitization

Identity & Access

Who can reach what, and how you'd know if that changed.

Single sign-on & federationMulti-factor authentication rollout Conditional access designPrivileged access management Identity governance & administrationIdentity security posture management Machine & non-human identityJoiner / mover / leaver automation Dark web credential monitoringSecrets management

Network & Infrastructure

The plumbing, including the parts nobody has looked at in five years.

Next-generation & AI-assisted firewallsFirewall management & tuning Network segmentation & microsegmentationZero trust architecture Secure access service edge (SASE / SSE)DNS & web content filtering Network access controlIntrusion detection & prevention Wired & wireless infrastructure auditRemote access & VPN OT, IoT & building systemsCamera & access control security

Cloud, SaaS & Application

Where the work actually happens now.

Microsoft 365 hardeningGoogle Workspace hardening Cloud security posture managementCloud-native application protection SaaS security posture managementShadow IT discovery Application security posture managementSecure configuration baselines API security reviewContainer & Kubernetes security Cloud entitlement management

Data Protection & Resilience

Getting back on your feet, and keeping data where it belongs.

Backup design & immutabilityRestore testing Disaster recovery engineeringData loss prevention Data security posture managementData discovery & classification Encryption at rest & in transitEmail security & anti-phishing Secure file transferPost-quantum readiness assessment

Offensive Security & Exposure

Finding your gaps before somebody less friendly does.

External & internal penetration testingWeb & mobile application testing Wireless penetration testingSocial engineering assessment Physical security assessmentRed team & purple team exercises Vulnerability assessment & scanningExternal attack surface management Continuous threat exposure managementAdversarial exposure validation

AI Security & Governance

The fastest-moving risk on this page, and the one most organizations haven't touched.

AI runtime defense (AI gateway + guardrails)Prompt injection & jailbreak mitigation AI acceptable use policyAI governance program build NIST AI RMF & ISO/IEC 42001 alignmentShadow AI discovery AI security posture managementAI data loss prevention Copilot & Gemini tenant oversharing remediationAI access control & least privilege Agentic AI governanceAI agent identity & credentials MCP server security reviewAI browser & extension risk AI red teaming & adversarial testingModel scanning & provenance AI-BOM / ML-BOMAI supply chain security Deepfake & voice-clone process defensesAI vendor & feature risk review AI incident response & tabletopsAI literacy & staff training AI-assisted detection & triageAssessment redesign for academic integrity

Human Risk & Awareness

Your people will be the target long before your firewall is.

Security awareness trainingPhishing simulation Role-based training for finance, HR & executivesAI & deepfake awareness Tabletop exercisesExecutive & board briefings Onboarding & offboarding securityHuman risk management program

Education-Specific

The work general providers don't do, because it only exists in schools.

Student data privacy agreements & DPA registryEd-tech app vetting workflow COPPA compliance programCIPA filtering & certification records Student safety & self-harm alert monitoringFERPA program review HECVAT 4 completion & inbound triageGLBA & Safeguards for financial aid Research data security & CUI enclavesE-Rate & FCC Pilot support MS-ISAC transition advisoryBoard reporting written for public record
Compliance

The frameworks we work in, and keep current on.

We track the versions so you don't have to. A few that moved recently and catch people out: ISO 27001:2013 certificates expired in October 2025, PCI DSS 4.0.1 lost its grace period in March 2025, COPPA's amended rule reached full compliance in April 2026, and the Department of Defense suspended the CMMC Phase 2 transition in July 2026 while Phase 1 self-assessment stays in force.

NIST CSF 2.0NIST SP 800-171NIST SP 800-53 CIS Controls v8.1ISO/IEC 27001:2022SOC 2 PCI DSS 4.0.1CMMCHIPAA Security Rule FTC Safeguards RuleGLBAFERPACOPPA CIPAHECVAT 4SEC Regulation S-P SEC cyber disclosureState privacy laws State student data privacyGDPRNIS2 flow-down NIST AI RMFISO/IEC 42001
A fair question

"How can a company your size do all of that?"

Because the model is built for it, and because we'd rather answer this directly than let you wonder.

Security leadership, assessments, governance and compliance work, policy, audit support, penetration testing, training, tabletop exercises, incident response, and the education-specific work. That's the judgment-dependent half of the list and it stays in-house. Ask us on any engagement who is doing what and we'll tell you plainly, in writing if you want it.
Monitoring, endpoint and identity detection, firewalls, filtering, email security, and backup platforms come through partners we've selected and worked with over years. We handle selection, deployment, tuning, and day-to-day management, and we hold the relationship. You sign one agreement with us. When something breaks at 2am you call us, not a vendor support queue.
A reseller sells you a product and moves on. We're accountable for whether your organization is defensible, which is a different job and a much harder one to walk away from. The technology is a means to that. It's also why we're comfortable telling a client that the tool they already own is fine and they should spend the money elsewhere.
Most of our clients do, and it works well. Managed service providers keep systems running; we're accountable for whether they're defensible. We're happy to work alongside whoever is already there rather than displacing them, and in higher education we routinely operate alongside a full central IT organization.
Yes. Nothing on this page requires you to take anything else. Plenty of clients engage us for a single penetration test or one compliance project and never buy anything further, and that's a perfectly good outcome for both of us.

Not sure which of these you need?

That's what the consultation is for. Thirty minutes, no cost and no commitment, and you leave knowing which two or three of these would move your risk the most.