ERMITS
ERMITS Advisory Supply Chain · Privacy · Threat

Engagements

Advisory scope & deliverables

Diagnostic outputs inform each proposal. Three paths—supply chain, privacy, and threat—with deliverables scaling by level (see table). An advisory review aligns owners and evidence before deeper work.

Three advisory paths

Supply chain, privacy, and threat—where the work emphasizes. Each path uses the same engagement ladder in the next section.

Vendor & supply chain risk

Outcome

Third-party and subcontractor risk: where dependency and concentration matter for operations.

Focus

  • Continuity and tier-1 concentration
  • Procurement, security, and the business on one view of risk

Privacy, breach & notification readiness

Outcome

Privacy and breach pressure: a coherent line for regulators and leadership.

Focus

  • Jurisdiction, transfers, retention
  • Legal, IT, security, comms on the same facts

Ransomware & threat resilience

Outcome

Threat and resilience: critical assets and scenarios first—so IR and spend match real impact.

Focus

  • Blast radius over exhaustive asset lists
  • Detection, backup, recovery under ransomware-style stress

What you receive at each level

Depth from the Cyber Brief through managed engagement—artifacts and evidence scale the same way across all three paths.

Engagement Primary value Typical artifacts Typical data / evidence
Brief / Baseline Fast board-ready exposure & readiness Brief HTML Full Report PDF L1 snapshot exports Minimal signals only: scope, geography, vendor reliance, governance baseline, and Brief questionnaire inputs mapped to Level 1 nodes.
Profile Refinement Sharper scope & priority logic L1 across all branches · Scoping brief Level 1 artifacts plus targeted follow-up to validate priority branches and narrow scope.
Structured Evidence Asset register, control context L2 artifacts · Benchmarking maps · Exposure heat maps Structured inventories and category-level evidence (assets, vendors, data classes, critical functions) per branch requirements.
Managed Engagement Cross-domain reporting & remediation Full L3 · Control mapping · Remediation workflow Full evidence layer: asset-to-control mapping, recovery measures, substitution planning, and ongoing validation.

How it works

Start with the free Cyber Exposure Brief

One sitting: Exposure Index, domain scores, and Level 1 snapshots—grounding the table above.

10–15 min · browser-only · runs locally · no signup
Need calendars and scope confirmed first? Use Talk to an advisor—not required to run the Brief.