AI Business TransformationBusiness Ops
Our ApproachInsightsStart a Conversation

Information
Security

You run the one program that touches everything the organization builds, buys and operates. We work alongside CISO organizations to build, assess, run and mature that program: one security program, organized on the NIST Cybersecurity Framework 2.0, for everything you run, AI included.

Talk to Our Security Practice
47%

of cybersecurity teams say they have helped develop AI governance, up from 35 percent the year before.

ISACA · State of Cybersecurity 2025
41%

name AI as the top skills gap on their team, ahead of cloud security at 36 percent.

ISC2 · 2025 Cybersecurity Workforce Study
>50%

of respondents expect the security function to gain additional AI governance responsibility.

IAPP · AI Governance Profession Report 2025

AI plays two roles in your security program, and one program covers both

Many security teams have already put AI to work: in detection, in triage, in the analyst's day. That is the first role, and it is well underway. The second role is newer. The models, agents and AI features arriving inside your applications and your vendors' products are workloads, and they need what every workload needs from you: an identity, a data boundary, monitoring and an incident plan. Your organization's security program is yours to set and to run: the policy, the standards and the controls, under the risk appetite your leadership sets and your board oversees. For AI, the security function builds and runs the controls: an identity for every actor, including AI agents; the AI gateway your traffic to outside models passes through, and the data controls on it; discovery of shadow AI on the tooling you already operate; and the incident chain when a system misbehaves. What those controls enforce, the risk tiers, the permission table and the hard lines, is decided upstream in our AI Governance practice and arrives here already decided. The two practices are built to work together, and this page describes the security half.

"Security is the one function that touches everything the organization runs. Built well, it is the reason everyone else can move quickly."

Plaster Group Practice Principle

One program, six Functions, addressed together

We organize the practice on the six Functions of the NIST Cybersecurity Framework 2.0, because it is the structure the field has converged on: NIST's own incident response guidance, the CIS Critical Security Controls, CISA's Cross-Sector Cybersecurity Performance Goals and ISO/IEC 27002 all now align to it. The Framework is clear about what it is and is not. The Functions "should be addressed concurrently," GOVERN sits "in the center of the wheel because it informs how an organization will implement the other five Functions," and the Framework "does not prescribe outcomes nor how they may be achieved." So there is no gate here and no sequence: the six run at once, and the eight capabilities that follow are our arrangement of the work beneath them.

IDENTIFYPROTECTDETECTRESPONDRECOVERGOVERN

Securing the AI Estate spans all six Functions.

GOVERN

"The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored."

Security Program, Risk & Compliance

IDENTIFY

"The organization's current cybersecurity risks are understood."

Vulnerability & Exposure Management

PROTECT

"Safeguards to manage the organization's cybersecurity risks are used."

Identity, Access & Zero Trust · Cloud, Application & Data Security

DETECT

"Possible cybersecurity attacks and compromises are found and analyzed."

Detection Engineering & Security Operations

RESPOND

"Actions regarding a detected cybersecurity incident are taken."

Incident Response

RECOVER

"Assets and operations affected by a cybersecurity incident are restored."

Resilience & Recovery

The program, capability by capability

01GOVERN

Security Program, Risk & Compliance

Every security program already has a shape: a strategy someone wrote, policies that grew with the estate, a risk register, an audit calendar and a set of obligations the organization is held to. We work with you to make that shape deliberate: a strategy and roadmap the executive team can fund, policy and standards your engineers can build to, risk management that ranks what matters, and compliance work done once and evidenced for every regime that asks, including the reporting your board and audit committee expect from you.

  • Security strategy, roadmap and operating model
  • Policy and standards your engineers can build to
  • Risk assessment and a risk register that ranks what matters
  • Regulatory obligations across the regimes you carry: SEC cybersecurity disclosure, NYDFS Part 500, HIPAA, PCI DSS, CMMC at the phase in force, GDPR, and the EU's NIS2 and DORA where they apply
  • ISO/IEC 27001 information security management system (ISMS) design and certification readiness, and SOC 2 readiness
  • Third-party and supply chain risk, security awareness, and reporting to the board and audit committee
02IDENTIFY

Vulnerability & Exposure Management

You cannot defend what you have not counted, and you cannot fix everything at once. We help you build or mature the program that keeps an accurate inventory, finds what is exposed, and prioritizes by whether a weakness is actually being exploited rather than by its Common Vulnerability Scoring System (CVSS) severity alone: CISA's Known Exploited Vulnerabilities (KEV) catalog, the Exploit Prediction Scoring System (EPSS) probability FIRST publishes daily, and the Stakeholder-Specific Vulnerability Categorization (SSVC) decision method from Carnegie Mellon's CERT Division, with remediation service levels your engineering teams can meet.

  • Asset inventory and attack surface visibility
  • Vulnerability management program design, and platform selection or migration
  • Prioritization on CISA's KEV catalog, EPSS and SSVC alongside CVSS severity
  • Remediation service levels and ownership across engineering teams
  • Cloud, application and container findings brought into one view
  • Metrics the CISO can report and the board can follow
03PROTECT

Identity, Access & Zero Trust

Identity is the control plane everything else depends on, and it now has to cover people, services and AI agents alike. We design and implement identity and access programs and zero trust architectures on NIST SP 800-207 and CISA's Zero Trust Maturity Model: least-privilege access, privileged access management, continuous verification and segmentation, and, for AI, an identity for every agent, scoped to its task, expiring when the task ends and bound to a named human owner.

  • Identity and access management (IAM) program design and modernization
  • Privileged access management (PAM)
  • Zero trust architecture on NIST SP 800-207 and CISA's Zero Trust Maturity Model
  • Network segmentation and lateral movement prevention
  • Identity for AI agents and non-human actors, task-scoped and bound to a named owner
  • Access reviews, certification and least-privilege enforcement
04PROTECT

Cloud, Application & Data Security

Most estates now run across AWS, Azure or Google Cloud, ship software continuously, and move sensitive data through more systems than any one team can watch by hand. We help you set the architecture and the controls that keep all three secure by design: cloud posture and configuration, secure development and application security in the pipeline, and data security and data loss prevention (DLP), including the data controls on the traffic your organization sends to AI models.

  • Cloud security posture and architecture across AWS, Azure and Google Cloud
  • Secure development lifecycle and application security testing
  • API and integration security
  • Data classification, encryption and data loss prevention
  • Data controls on AI traffic and the AI gateway
  • Security architecture review and design
05DETECT

Detection Engineering & Security Operations

Detection is engineering: the right telemetry, the right rules, and a security operations function that spends its attention on what matters. We design and build detection programs on your platforms, whether you run your own security operations center (SOC) or work with a managed detection and response (MDR) partner, and we use AI where it helps analysts, in triage, correlation and hunting, as a component of the program rather than its headline.

  • Detection engineering mapped to MITRE ATT&CK, the catalog of adversary tactics and techniques
  • Security information and event management (SIEM) and security data architecture
  • SOC design, or oversight of an MDR provider
  • Threat hunting and threat intelligence programs
  • AI-assisted triage, correlation and investigation
  • Detection coverage measured and reported
06RESPOND

Incident Response

Response quality is decided before the incident. We build incident response programs on NIST SP 800-61 Revision 3, the incident handling guide now organized on the same six Functions as this page: a plan your responders have rehearsed, playbooks by incident type, notification procedures mapped to the clocks you carry, and forensics readiness. AI incidents join the same chain, with their own categories, because in an AI incident the system is often up and running while doing something it should not.

  • Incident response program and plan on NIST SP 800-61 Revision 3
  • Playbooks by incident category, including ransomware and business email compromise
  • Tabletop exercises, with every finding closed
  • Regulatory notification mapped to the clocks you carry, including the SEC's four business days
  • Forensics readiness and evidence handling
  • AI incident response as an extension of the enterprise process
07RECOVER

Resilience & Recovery

The measure of a security program is not only what it prevents but how quickly the organization is back when something gets through. We design and test the recovery side: business continuity and disaster recovery plans that reflect how the business actually runs, backup architecture that has been restored from rather than merely written to, ransomware readiness, and the crisis communication that keeps customers, regulators and employees informed.

  • Business continuity and disaster recovery planning
  • Ransomware readiness and recovery
  • Backup architecture and restoration testing
  • Crisis communication and executive response
  • Recovery objectives tied to the business processes they protect
  • Post-incident review that improves the program
08ALL SIX FUNCTIONS

Securing the AI Estate

AI is arriving built, bought or homegrown, and all of it runs on the estate you already protect. We help you bring it inside the program: an AI gateway that controls which models are reachable, who may call them and what is logged; an identity for every agent; discovery of shadow AI on the tooling you already operate; security review of AI applications, AI vendors and the AI features vendors add to products you already own; controls mapped to the OWASP Top 10 for LLM Applications (large language models), the OWASP Top 10 for Agentic Applications and MITRE ATLAS; and AI incident response inside your existing chain. These are the controls. What they enforce is decided upstream in our AI Governance practice.

  • AI gateway controls: which models, which teams, what is logged and what it costs
  • Identity and least-privilege access for AI agents and non-human actors
  • Shadow AI discovery and inventory on the tooling you already operate
  • Security review of AI applications, AI vendors and AI features inside existing software
  • Controls mapped to the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications and MITRE ATLAS
  • AI incident response inside the enterprise incident chain

The frameworks a program can be audited against, and the references its engineers already work from

NIST Cybersecurity Framework 2.0

The structure this program is organized on: six Functions, addressed concurrently, with GOVERN informing the other five. Voluntary, widely adopted, and the structure the rest of the field now aligns to.

ISO/IEC 27001:2022

The international standard for an information security management system, and the one an organization can be certified against. Its 2022 edition names information security and cybersecurity together in its title, and ISO/IEC 27002 supplies the control catalog beneath it.

CISA

The Cybersecurity and Infrastructure Security Agency's published guidance: the Cross-Sector Cybersecurity Performance Goals, the Known Exploited Vulnerabilities catalog that sets our remediation priorities, and the Zero Trust Maturity Model.

The working references the program uses day to day: MITRE ATT&CK, the catalog of adversary tactics and techniques, and MITRE ATLAS, its counterpart for attacks on AI systems; the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications; the CIS Critical Security Controls; CVSS severity scoring and EPSS exploitation probabilities from FIRST; and SSVC, the vulnerability decision method from the CERT Division at Carnegie Mellon University.

These are the frameworks a CISO can name when the board asks what the program is built on. They describe outcomes and leave the arrangement to each organization, and that arrangement is the work.

Three ways in, and none of them asks you to start over

A program assessment

A structured read of your program against the six Functions and the obligations you carry, with a prioritized roadmap and honest sizing. Most programs are further along than their documentation suggests, and the assessment is built to show that.

A single or multiple capabilities

A defined engagement in a single or multiple capabilities: standing up vulnerability management on KEV, EPSS and SSVC, preparing for ISO/IEC 27001 certification, building the detection program, or bringing AI inside the controls you already run.

Senior practitioners on your team

Security engineers, architects and program leaders embedded with your team, on your stack, for as long as the work needs. The same practice, the same standards, in the form that suits how you work.

One program. Everything you run. Protected.

Whether you are maturing a program you have run for years, standing up a capability you have not needed before, or bringing AI inside the controls you already operate, we start from what you have built and add what the evidence says comes next.

Frequently asked questions

How does AI change a security program?

In two ways, and one program covers both. Security teams are using AI in detection, triage and investigation, and that work is well underway. At the same time, the models, agents and AI features arriving inside applications and vendor products are workloads, and they need what every workload needs: an identity, a data boundary, monitoring and an incident plan. The security function builds and runs those controls. What they enforce, the risk tiers, the permission table and the hard lines, is decided upstream in Plaster Group's AI Governance practice and arrives already decided, so the two practices are built to work together.

Does Plaster Group help with ISO/IEC 27001 and regulatory compliance?

Yes. We design information security management systems, run gap assessments and prepare organizations for ISO/IEC 27001 certification, and we help with SOC 2 readiness and the regimes a security program is held to, including SEC cybersecurity disclosure, NYDFS Part 500, HIPAA, PCI DSS, CMMC at the phase in force, GDPR, and the EU's NIS2 and DORA where they apply. The work is organized so that evidence is produced once and serves every regime that asks for it.

How does Plaster Group engage with a security organization?

In whatever form suits how you work: a program assessment against the six Functions of the NIST Cybersecurity Framework 2.0 with a prioritized roadmap, a defined engagement in a single or multiple capabilities, or senior security practitioners embedded with your team on your stack for as long as the work needs. Every engagement starts from what you have already built.