
Someone has to own security. It does not have to be a full-time hire.
Security, resilience, and governance, covered by one director-level advisor instead of three separate hires.

Our approach
Risk is what could happen. Resilience is what happens next.
Most organizations address one and assume the other. We assess exposure, reduce it where it can be reduced, and build the plan for what remains.
Assess, plan, maintain. A written picture of where you stand, a roadmap ordered by exposure, and ongoing oversight so the work does not go stale. On a retainer, that oversight extends through implementation: we coordinate the vendors and subcontractors carrying the plan out, not just the report that describes it.
What we do
Three disciplines, one point of accountability.
Security
What you are carrying, and what it would take to reduce it.
Resilience
How you keep operating, and how you get back to work.
Governance
The framework behind the decisions, and the record when they are questioned.

What we find
The same gaps, across almost every organization.
01 · Plans with no named decision-maker
The continuity binder is thorough on procedure and silent on who is authorized to close, release staff, and reopen. The decision gets made late because nobody was assigned to make it. Naming that authority in writing is often the single highest-leverage fix in the plan.
02 · Capital spent without a design basis
Equipment gets purchased before requirements are defined, so the system that arrives solves a different problem than the one the organization has. A design basis defined before procurement means the system that arrives actually solves the problem.
03 · Policies that were written but never trained
The workplace violence policy exists in the handbook. The people who would have to act on it have never walked through what they are supposed to do. A policy that has been walked through, not just filed, is one leadership can rely on when it matters.
04 · Credentials that never get revoked
Access lists carry former employees, former residents, and contractors whose work ended two years ago. The system works exactly as configured. Nobody configured it recently. A current access list is one of the fastest gaps to close, and one of the most commonly missed.
05 · Cameras that record but cannot testify
Coverage exists, but retention runs shorter than the time it takes to discover an incident, timestamps drift, and nobody on site knows how to export footage in a format an investigator can use. Coverage built to identification standards, not just detection, is coverage that holds up in an investigation.
06 · Recovery that was never tested
Organizations know how they would close. Almost none have walked through how they reopen. Power, access control without power, vendors never put under contract, staff who cannot get back. A recovery plan tested in advance is the difference between reopening in days and reopening in weeks.
Assessments and plans are delivered from templates built against ASIS International standards, not generic boilerplate, so findings hold up when your board, counsel, or carrier looks behind them.
A finding that’s been fixed stops being the same question asked twice. A plan that’s been tested stops being a document nobody’s opened since it was filed.

Independence
The recommendation is the product.
G.I.S. takes no vendor commissions and holds no financial interest in what gets installed. That independence is what makes an assessment worth commissioning, and what makes the findings usable by your board, your counsel, and your carrier.
Who we serve
Organizations carrying real exposure.
Commercial real estate
Professional and medical
Community spaces
Defense counsel and legal departments
Shopping plazas and restaurants
Where to start
Three ways to begin.
Plan review
We review your emergency or continuity plan against a published standard and deliver a written gap report with a prioritized remediation list. Fixed fee, ten business days, and you keep the document regardless of what comes next.
Security assessment
We walk your property and deliver a written report on access control, camera coverage, lighting, entry points, and daily procedures, with findings prioritized by exposure.
Business impact analysis
We identify your critical functions, the cost of downtime for each, and how fast recovery needs to happen. Fixed fee, a shorter engagement than a full continuity plan, and a foundation you can build on when you are ready for one.

Every engagement starts with a conversation.
Tell us what your organization is facing. If G.I.S. is the right fit, that will be clear quickly.
