01 / 06
🎓
Customized Security Awareness Training

Generic training fails. JDV Cyber designs programs tailored to your industry, regulatory environment, and actual threat landscape.

  • Curriculum aligned to HIPAA, PCI-DSS, GDPR, and other regulatory requirements
  • Live instructor-led sessions and phishing simulation campaigns
  • Pre/post assessments with measurable knowledge gain reporting
  • Annual refresher scheduling for compliance documentation
$2,500–$5,000 initial build · $1,500–$3,000 refresh
Phishing simulations from $500/quarter
02 / 06
🔍
Cybersecurity Risk Assessments

The foundation of any security program. Structured assessments aligned to NIST SP 800-30, NIST CSF, and HIPAA Security Rule — producing actionable findings and a prioritized remediation roadmap.

  • Asset inventory review and data flow documentation
  • Threat and vulnerability identification using industry-standard methodologies
  • Control gap analysis against NIST CSF, NIST 800-53, HIPAA, ISO 27001
  • Risk register development and POA&M creation with owner assignments
  • Executive summary and board-ready risk report
$3,500–$8,000 per assessment
Annual reassessment packages at 20% discount
03 / 06
🤖
AI Governance Plans

As organizations adopt AI tools, they face new risks around data privacy, bias, accountability, and regulatory compliance. JDV Cyber develops AI governance frameworks aligned to NIST AI RMF 1.0 and ISO/IEC 42001.

  • AI inventory and use case documentation
  • Risk assessment of AI tools in use including third-party AI providers
  • AI acceptable use policy development
  • Governance plan aligned to NIST AI RMF Govern, Map, Measure, Manage
  • Ongoing AI risk review as part of vCIO retainer
$4,000–$7,500 per plan
Standalone or bundled with risk assessment
04 / 06
📋
Policy & Procedure Review and Creation

Documented policies are required by every regulatory framework and every cyber insurance application. JDV Cyber audits existing libraries for gaps and develops new policies aligned to your requirements.

  • Full policy library gap analysis against framework requirements
  • New policies: AUP, Incident Response, Access Control, Data Classification, Media Disposal, Remote Work, Vendor Management
  • Annual review cadence with tracked changes and leadership sign-off
  • Employee policy acknowledgment and signature tracking
$500–$1,500 per policy · Full libraries from $5,000–$12,000
Annual review retainers from $2,400/year
05 / 06
📝
Security Questionnaire Completion Support

Completing VSQs, SIG Lite, CAIQ, and customer due diligence requests is time-consuming and high-stakes. Incorrect responses can cost a contract or trigger a compliance finding. We manage this on your behalf.

  • Review and analysis of incoming questionnaire requirements
  • Mapping of existing policies, controls, and certifications to responses
  • Gap identification and recommended response language
  • Coordination with your technical staff for evidence collection
  • Knowledge base development so repeat questionnaires get faster
$150/hour · SIG Lite: $1,500
NIST 800-171 VSQ: $2,500–$4,000
06 / 06 — FLAGSHIP
⚙️
Virtual CIO (vCIO) Services

Our flagship recurring product. A dedicated senior cybersecurity advisor functioning as your part-time CISO/CIO — managing your security calendar, vendor relationships, and program maturity over time.

  • Monthly or quarterly security steering meetings with leadership
  • Annual governance calendar management: policy reviews, risk assessments, vendor renewals, training
  • Vendor and third-party risk management including questionnaire review
  • Cyber insurance application support and annual renewal preparation
  • Incident response planning and tabletop exercise facilitation
  • Board and executive reporting on security posture and compliance
  • Priority access for ad hoc questions and emerging threat guidance
Tier 1: $2,500/mo · Tier 2: $4,000/mo · Tier 3: $7,500/mo
Annual contracts receive one month free — see Pricing

Start with a free cybersecurity assessment.

We'll help you identify which offering fits your organization's current stage — no pressure, no jargon.