How We Work

Four services. One engagement model. Never committed beyond one interval.

A viewer of capability lists learns what a firm knows. This page is about something more useful: what it is like to hire us, what we commit to, and how we are held to it.

The four services

The first three are how clients typically meet the firm. The fourth is where relationships go.

01

Assessment

A structured, evidence-based read of where you stand, in one domain or across all three, ranked by business impact and delivered in language a board can act on.

02

Strategy

The plan that closes the distance between where the assessment found you and where the consequence you carry says you need to be: sequenced, costed, and owned.

03

Governance design

Operating structures that keep risk governed after we leave the room: policy, oversight, decision rights, escalation paths, and the evidence trail that proves they work.

04

Sustained engagement

Named practitioners inside your organization on a renewable interval, carrying the program forward and executing what they find. The principal service, described below.

The sustained engagement model

The structure answers the three questions every advisory buyer has: who exactly is doing the work, what are they committed to, and how do I hold them to it.

Renewable six-month intervals

Every engagement runs in a defined interval with stated objectives and deliverables. You are never committed beyond the interval you are in.

A gate every interval

In month five, a formal gate review: the work is measured against the objectives, and you renew, rescope, scale, or conclude. The gate is ours to pass, not yours to avoid.

Named practitioners

An Engagement Principal directs delivery. A Principal Advisor serves as Executive Sponsor with standing accountability for the engagement. You know who is on your account, by name.

Execution included

Findings do not become your backlog. The engagement pairs leadership with hands-on delivery, so what we find gets closed, not handed back to your team as homework.

Stepped allocation

As the program matures, allocation steps down by design. A well-governed program should need less of us over time, and the commercial structure says so out loud.

Knowledge transfer

A stated objective of every interval, not a courtesy. Your team should be more capable at the gate than it was at the kickoff, and the gate review measures that too.

Service by domain

Any of the four services can be scoped to any of the three domains. Domain is the axis you recognize; service is the axis we scope on.

Cyber RiskPhysical RiskHuman Risk
Assessment
Strategy
Governance design
Sustained engagement

The cybersecurity services catalog (posture reviews, audits, compliance, AI governance, and the rest) lives under Cyber Risk.

Engagement use cases

Client-agnostic accounts of real engagements, so you know what hiring us looks like in practice.

Enterprise Software (Identity & Access Management)

AI Security Posture & Governance Assessment

Independent assurance over an expanding AI footprint

A global enterprise software provider needed an independent read on the security of its expanding AI stack. Apogee ran a six-week, evidence-led assessment against NIST CSF 2.0, with no system access required, and delivered board-ready findings on architecture, governance, and remediation priorities.

AI SaaS Serving the Defense Industrial Base

FedRAMP Moderate Equivalency

From gap analysis to audit-ready in 90 days

A cloud-native software company needed FedRAMP Moderate equivalency to sell to DoD contractors. Apogee led the 90-day program: Rev 5 gap analysis, control remediation across the cloud environment, a full body of evidence, and 3PAO readiness through independent assessment.

Executive Education

Three-to-Five-Year Growth Strategy

Turning a world ranking into regional growth

A top-ranked executive education institution held the leading global ranking but not the market perception to match it. Apogee delivered a four-phase, 90-day strategy engagement covering competitive analysis, region-by-region assessment, and an organizational-structure review, culminating in a board-ready growth plan.

"Your adversaries don't separate digital from physical. Neither do we, and most of what surfaces in either began with a person."

The case for one discipline across cyber, physical, and human risk

What we do not do

Focus is a feature. These are boundaries, not apologies.

No implementation sold as standalone capacity

Execution rides inside an engagement with objectives and a gate. We do not rent out hands.

No commercial staffing

We assess, verify, and govern the people function. The one exception is deliberate and narrow: talent placement for public sector entities requiring program management or technology focused roles. Commercial organizations seeking placement should engage a search firm; we will refer you to one.

No operating client infrastructure

We build the program and the people who run it. We do not become your outsourced operations.

No attesting to programs we built

The firm that prepares an organization should not be the firm that grades it. Somebody else does the assessing.

Where we work

Headquartered in Silicon Valley with a presence in Washington, D.C. Engagements delivered across three continents.

World map showing Apogee Global RMS presence
Silicon Valley (HQ)
Washington, D.C.

Ready to take a unified view of enterprise risk?

Schedule a conversation with M.K. Palmore to explore how Apogee Global RMS can serve your organization.

Schedule a Consultation