SMB owner
Get a plain-language security audit of your small business.
Plain-language audit of your actual posture, with a prioritized remediation plan your team or vendor can execute.
What you already know Your team is using AI without real oversight. Your security posture has never been written down. Both gaps compound.
One advisor working with one customer at a time. Security, AI governance, and the Intent discipline that keeps both honest. Delivered by David Borden under a single-retainer cap.
1 available retainer slot first-review lead time two weeks
SMB owner
Plain-language audit of your actual posture, with a prioritized remediation plan your team or vendor can execute.
Sole proprietor
Structured fluency across modern AI platforms. Intent first, guardrails before scale, reviewable artifacts.
Small team
Password managers, MFA, Passkeys, and credential automation. A running foundation your team owns and operates.
Exec
NIST AI RMF and ISO 42001-literate posture. Named intent per use-case, guardrails before scale, written risk register.
Named outcomes. Each is delivered by a specific engagement shape.
A structured program that moves an unprepared team from informal controls to audit-ready: gap list, drafted policies, control owners named, and a calendar the team can ship on.
AI-assisted productivity automation across Google Workspace, Microsoft 365, and iCloud. Structured data and a process the team can operate. Running automations the client owns after the program ends, not a deck of ideas.
SMB security audits. Security Leadership on Retainer. SOC 2 Readiness Enablement. Credential and Identity Foundation. Zero Trust applied proportionally.
See the Security practiceAI risk assessment, AI adoption enablement, AI-augmented productivity automation, and data organization. Intent first, guardrails before scale, systems the client owns and operates.
See the AI practiceThe discipline of clear outcomes, explicit constraints, real guardrails, and verifiable results. The methodology underneath the AI Practice offerings.
Read the methodologyStrategic partnership over quarters, one customer at a time, structured cadence.
A single scoped engagement producing a prioritized plan.
A working session that turns ambiguity into operational intent.
Training plus artifact production for teams adopting AI or pursuing SOC 2.
Not a logo wall. The advisor works these frameworks as a daily practice: policy, control mapping, audit posture, governance.
SOC 2
ISO 27001
NIST CSF
NIST AI RMF
ISO 42001
GDPR
HIPAA
These are David's career outcomes, not Forge & Ward client work.