Sample engagement

Municipal
cybersecurity assessment.

A verified view of exposure, a risk-ranked action register, and a roadmap local government can budget and execute.

The assignment

Find what matters. Show the evidence. Sequence the work.

The assessment covers governance, identity, endpoints, networks, backups, incident readiness, vendor access, and operational dependencies. The scope is adjusted after authorized discovery.

01Authorize

Assessment charter

Confirm systems, stakeholders, safety constraints, evidence sources, testing permissions, escalation routes, and acceptance criteria before technical work begins.

DELIVERABLEApproved scope and rules of engagement
02Discover

Environment record

Reconcile interviews, inventories, diagrams, configurations, and approved observation into an asset record and high-level view of trust boundaries and dependencies.

DELIVERABLEAsset record, architecture view, and evidence exceptions
03Assess

Risk and control analysis

Evaluate how credible threats meet actual exposure and existing safeguards. Findings distinguish verified facts, reported conditions, and unresolved evidence gaps.

DELIVERABLERisk register with evidence, consequence, owner, and priority
04Validate

Authorized technical testing

Use approved methods proportionate to the environment. Production operational technology defaults to passive, evidence-based, or low-impact review.

BOUNDARYNo destructive testing or uncontrolled production changes
05Prioritize

Implementation roadmap

Organize actions into immediate, 90-day, annual, and capital-planning horizons with dependencies, responsible roles, completion evidence, and cost bands where supportable.

DELIVERABLEProduct-neutral remediation roadmap
06Transfer

Briefing and readiness exercise

Walk leadership and technical staff through material risk, decisions, and next actions. An optional tabletop tests escalation, continuity, communications, and recovery.

DELIVERABLEExecutive briefing, technical handoff, and after-action record

Why BowTiedCyber

Direct experience, carefully applied.

BowTiedCyber LLC was formed in Delaware in February 2022 and is authorized to transact business in Florida. Its organizational assessment capability is led by Evan Lutz and grounded in his prior professional experience completing dozens of risk assessments, supporting security operations and incident response, working in an ICS-related broadcasting environment, and developing a successful SOC 2 Type II program from a zero baseline.

METHODEvidence and operational consequence drive priority
DELIVERYOne accountable principal from discovery through handoff
PRODUCTSPurchases recommended only after requirements are known
OUTPUTEditable registers, reports, roadmaps, and decision material

Request a scope

Start with the environment you have.

Send the requirement or describe the systems and decision you need to make.

admin@bowtiedcyber.com