SGE
Security Governance & Engineering
SGE connects security strategy and governance with architecture and hands-on engineering. Where you have security leadership in place, MITG provides advisory support, architecture, engineering, and program execution under their direction. Where you do not, MITG’s CISO office provides that leadership.
Turning findings into decisions
Board report excerpt · illustrativeQuarterly, for leadership and the board
A decision for leadership · illustrative
- Material risk
- A critical business application relies on infrastructure approaching end of support, increasing security exposure and the risk of disruption.
- MITG recommendation
- Prioritize migration to supported infrastructure and tighten access controls while the migration is completed.
- Decision required
- Approve the migration budget and agree on an implementation window with the business owner and IT.
| Measure | Prior quarter | This quarter |
|---|---|---|
| Open remediation items, high severity | 7 | 3 |
| Multi-factor authentication coverage, user accounts | 96% | 100% |
| Phishing simulation click rate | 6.1% | 3.4% |
| Policies reviewed within the last 12 months | 10 of 12 | 12 of 12 |
| Client IT disaster recovery test | Completed, 2 findings | Completed, findings closed |
| Incidents requiring joint response | 1 | 0 |
All metrics and the decision example are illustrative. Reporting for your leadership and board is part of the program.
What the program includes
Leadership and governance
- Security policy development and maintenance
- Compliance oversight against the frameworks that apply to you
- Security review of your vendors
- Cyber insurance renewal support
Architecture and engineering
- Security architecture and control design
- Attack surface reduction and hardening
- Security information and event management (SIEM) deployment and tuning
- Email security and access control
- Defenses and controls implemented proactively as new threats emerge
Readiness and assurance
- A managed security awareness program with phishing simulation
- Disaster recovery test oversight: client IT performs testing; MITG verifies results and tracks follow-up actions
- Tabletop exercises and reporting for your leadership and board
- Incident response plan maintenance
Separate advisory and implementation teams
Adviser
Writes the policy
Handoff
Implementer
Hardens the environment
SGE
Strategy, policy, architecture, and implementation stay with one accountable team.
Strategy and execution from one team
The team responsible for your security strategy and policies also designs, implements, and verifies the controls, keeping planning and execution connected.
Request an introductory meeting