Cleveland, Ohio · Mon–Fri 8:30 AM – 6:00 PM ET
☎ (216) 832-6065  ·  security@graceandtaylor.com
Boutique Advisory · Est. 2011 · Cleveland

Quiet counsel for
consequential decisions.

Grace & Taylor Advisory partners with mid-market leaders across the Great Lakes to navigate risk, regulatory compliance, and corporate security — with the discretion of a private banker and the rigor of an audit team.

Risk ManagementRegulatory ComplianceCorporate Security
Scroll
Enterprise RiskSOC 2 ReadinessVendor Due DiligenceBoard AdvisoryIncident ResponseInsider Threat ProgramsRegulatory Strategy Enterprise RiskSOC 2 ReadinessVendor Due DiligenceBoard AdvisoryIncident ResponseInsider Threat ProgramsRegulatory Strategy
Who We Are

Fourteen years of judgment. One partner from beginning to end.

Founded in 2011 by Wilburn Griffin, Grace & Taylor Advisory grew from a single-desk practice on Euclid Avenue into a trusted counsel for family offices, manufacturers, healthcare networks, and community banks across Ohio, Pennsylvania, and Michigan.

We are deliberately small. Every engagement is led personally by a senior advisor — never handed off to a rotating cast of associates. Our clients return year after year because the person who first understood their business is still the person answering the phone.

0
Years in Practice
0
Engagements
0
Client Firms
0
Retention Rate
Grace & Taylor Advisory consultants reviewing a risk assessment
Our Practice

Three disciplines. One integrated engagement.

Risk, compliance, and security rarely live in separate rooms — and neither do we. Every engagement draws from all three practices, sized to the questions your board is actually asking.

R

Risk Advisory

Enterprise risk assessments, scenario modeling, and board-ready dashboards that translate uncertainty into a decision your leadership can act on.

  • Enterprise Risk Frameworks
  • Operational & Financial Risk
  • M&A Due Diligence
  • Third-Party Risk Programs
C

Compliance

Programs designed for the regulator you'll meet next quarter — SOC 2, HIPAA, GLBA, PCI DSS, state privacy statutes — grounded in what your team can actually sustain.

  • SOC 2 Type I & II Readiness
  • HIPAA & HITECH
  • State Privacy Compliance
  • Policy & Control Design
S

Corporate Security

The physical, digital, and human layers of protecting a business — from access control to insider threat programs to executive protection posture reviews.

  • Security Program Assessments
  • Insider Threat Programs
  • Incident Response Planning
  • Vendor Security Reviews
Our Approach

Deliberately unhurried. Written down. Delivered in person.

01

Listen

A candid conversation, usually over coffee, to understand what's actually keeping the leadership team up at night.

02

Map

We diagram the business as it truly runs — not the org chart — and identify where risk, regulation, and security intersect.

03

Advise

A written recommendation set, ranked by impact and effort, briefed to the board or executive team in plain English.

04

Stay

Quarterly check-ins for as long as the relationship is useful. No auto-renewing retainers. No surprise invoices.

In Their Words

Clients we've kept for a decade.

Wilburn spent three days walking our plant floor before writing a single word of his risk assessment. That's why we're still working together eight years later.

Managing Director · Regional Manufacturer

Grace & Taylor got our SOC 2 across the line without turning our engineering team into paperwork clerks. The auditor said it was the cleanest readiness package she'd seen that year.

CFO · Financial Services Firm

They don't oversell. They tell you what you actually need, and they tell you when you don't need them anymore. That's rare.

General Counsel · Healthcare Network
Frequently Asked

Questions we hear before every first meeting.

Do you work with companies outside of Ohio?

Yes. Roughly a third of our engagements are within Cleveland, another third across the Great Lakes region (Columbus, Pittsburgh, Detroit, Buffalo), and the remainder throughout the United States. We travel when it helps and we work remotely when it doesn't.

What is a typical engagement size?

Our engagements range from a two-week focused assessment for a Series-B company preparing for its first enterprise sale, to multi-year advisory relationships with mid-market firms navigating regulatory change. We are candid about fit before we quote a scope.

Are you a law firm or an accounting firm?

Neither. We are an advisory practice. We work alongside your outside counsel and audit team, translating what they say into what your operating leaders can execute.

Do you work with private equity portfolio companies?

Regularly. We provide operational due diligence support pre-close and post-close program design across a portfolio, most often in industrial, healthcare, and financial services verticals.

Who is my point of contact once I sign on?

The same senior advisor who scoped your engagement. We do not hand engagements off to junior staff after the sales conversation. It is the reason we stay small.

Begin

An unhurried conversation is a good place to start.

Send a note or call the office. We reply within one business day, and initial consultations are always without cost or obligation.

Reach Wilburn Directly →