MITG
SGE

Security Governance & Engineering

SGE connects security strategy and governance with architecture and hands-on engineering. Where you have security leadership in place, MITG provides advisory support, architecture, engineering, and program execution under their direction. Where you do not, MITG’s CISO office provides that leadership.

Turning findings into decisions

Board report excerpt · illustrativeQuarterly, for leadership and the board

A decision for leadership · illustrative

Material risk
A critical business application relies on infrastructure approaching end of support, increasing security exposure and the risk of disruption.
MITG recommendation
Prioritize migration to supported infrastructure and tighten access controls while the migration is completed.
Decision required
Approve the migration budget and agree on an implementation window with the business owner and IT.
MeasurePrior quarterThis quarter
Open remediation items, high severity73
Multi-factor authentication coverage, user accounts96%100%
Phishing simulation click rate6.1%3.4%
Policies reviewed within the last 12 months10 of 1212 of 12
Client IT disaster recovery testCompleted, 2 findingsCompleted, findings closed
Incidents requiring joint response10

All metrics and the decision example are illustrative. Reporting for your leadership and board is part of the program.

What the program includes

Leadership and governance

  • Security policy development and maintenance
  • Compliance oversight against the frameworks that apply to you
  • Security review of your vendors
  • Cyber insurance renewal support

Architecture and engineering

  • Security architecture and control design
  • Attack surface reduction and hardening
  • Security information and event management (SIEM) deployment and tuning
  • Email security and access control
  • Defenses and controls implemented proactively as new threats emerge

Readiness and assurance

  • A managed security awareness program with phishing simulation
  • Disaster recovery test oversight: client IT performs testing; MITG verifies results and tracks follow-up actions
  • Tabletop exercises and reporting for your leadership and board
  • Incident response plan maintenance
Separate advisory and implementation teams
Adviser
Writes the policy
Handoff
Implementer
Hardens the environment
SGE
One teamStrategy · Policy · Architecture · Hardening · Verification · Board reporting

Strategy, policy, architecture, and implementation stay with one accountable team.

Strategy and execution from one team

The team responsible for your security strategy and policies also designs, implements, and verifies the controls, keeping planning and execution connected.

Request an introductory meeting