Understand the business and the risks in front of leadership, and act on anything genuinely urgent.
Key activities
- Executive interviews and a stakeholder / decision map
- Inventory of assets, data, and the institution's "crown jewels"
- Review of prior assessments, audit findings, and exam history
- Rapid triage of urgent exposure — privileged access, internet-facing services, backup integrity
Deliverables
Establish an objective baseline against NIST CSF 2.0 and separate real risk from noise.
Key activities
- Maturity assessment across the six CSF functions
- Third-party and critical-service mapping — concentration and Nth-party exposure
- Control and evidence review against the target profile
- Tabletop exercise — ransomware or wire-fraud scenario
- Business-impact view of the top risks
Deliverables
Translate findings into a sequenced, costed plan and a governance cadence that sticks.
Key activities
- 90-day / 12-month / 24-month remediation sequencing
- Investment estimates and resourcing options
- Key risk indicators and risk-appetite statements
- Reporting cadence, decision rights, and committee rhythm
- Prepare and deliver the first risk-committee package
Deliverables
Execute & govern
Work the roadmap, run the reporting cadence, close priority gaps, and evidence progress for examiners, auditors, and insurers.
Mature & optimize
Raise maturity toward target tier, fold in AI and third-party governance, and shift from remediation to sustained, measured oversight.
Illustrative composite. This sample reflects how NorthBridge structures an initial engagement. Activities and deliverables are tailored to each institution; it contains no client data.