Cleveland, Ohio · Mon–Fri 8:30 AM – 6:00 PM ET
☎ (216) 832-6065  ·  security@graceandtaylor.com
Home / Services

What we actually do.

Three practices, tightly integrated. Sized to the questions your board is asking, not the ones consultants like to sell.

Practice One

Risk Advisory

Enterprise risk is not a spreadsheet. It is the disciplined act of asking, in plain terms, what could go wrong and what we would do about it. We build risk frameworks that operating executives actually use — because they had a hand in writing them.

  • Enterprise Risk Frameworks
    Custom risk registers, appetite statements, and quarterly review cadences.
  • M&A Due Diligence
    Pre-close operational, compliance, and security diligence for buyers and sellers.
  • Third-Party Risk Programs
    Vendor tiering, due diligence questionnaires, and contract clause libraries.
  • Board & Committee Advisory
    Quarterly briefings that keep directors informed without drowning them.
Vault mechanism representing security
Compliance advisory session
Practice Two

Regulatory Compliance

The regulator you'll meet next year is not the regulator you met last year. We design compliance programs that survive turnover, statutory drift, and the audit letter no one saw coming.

  • SOC 2 Type I & II Readiness
    Scope, controls, evidence collection, and auditor-facing preparation.
  • HIPAA & HITECH
    Risk analyses, business associate agreements, breach protocols.
  • State Privacy Compliance
    CCPA, CPRA, Colorado, Connecticut, Virginia and emerging state statutes.
  • Financial Services (GLBA, PCI DSS)
    Community bank and payment-adjacent program design and remediation.
Practice Three

Corporate Security

Corporate security is a discipline, not a product. It sits at the intersection of physical premises, information systems, and the people who move between them. We assess all three, then help you build the programs that hold up under pressure.

  • Security Program Assessments
    Full-spectrum review of physical, digital, and personnel security posture.
  • Insider Threat Programs
    Policy, training, and monitoring design consistent with employment law.
  • Incident Response Planning
    Tabletop exercises, runbook design, and crisis communications structure.
  • Executive Protection Posture
    Threat assessments and program design for principals and their families.
Cleveland skyline
Engagement Models

Three ways to work with us.

Every engagement is quoted in advance. Every fee is fixed. There are no hourly surprises.

A

Focused Assessment

A defined-scope engagement of two to eight weeks. A written report, a working session with leadership, and a prioritized action plan.

B

Program Build

Three to nine months of implementation partnership. We embed with your team, deliver the artifacts, and hand the keys over cleanly.

C

Advisory Retainer

Quarterly review sessions and on-call counsel for organizations who want a senior voice available without maintaining the seat in-house.

Not sure which fits? Neither are most of our clients on day one.

A thirty-minute conversation usually makes the answer obvious.

Start the Conversation →