CSaaS Process

How Does Idril CSaaS Work?

From First Conversation to Ongoing Security Program

Idril follows a five-step CSaaS process that moves from an initial cyber risk assessment to an ongoing security program. First, we identify security gaps. Next, we select the right service tier, complete onboarding, begin recurring delivery, and scale the program as your needs grow.

To begin, the process starts with a 15–20 minute gap assessment at no cost or obligation. As a result, you get a clear view of what happens next, with defined scope, deliverables, and responsibilities.

1

Free Cyber Risk Assessment

What Happens in the Free Cyber Risk Assessment?

Duration: 15–20 minutes. No cost, no obligation.

First, we run a focused gap assessment against frameworks such as NIST CSF and CIS Controls. We review your policies, security controls, compliance status, and threat exposure.

After that, you receive a prioritized findings summary that identifies important gaps, quick wins, and your current security position.

If there is a fit, we recommend an appropriate CSaaS tier. However, if you decide not to continue, you can keep the findings without entering an ongoing engagement.

How Is Tier and Scope Determined?

Duration: 1–2 business days from assessment to signed scope.

Duration: Usually 1–2 business days from assessment to defined scope.

Next, we review the assessment findings with your team and identify the appropriate Essentials, Growth, or Advanced tier. In addition, we determine whether services such as AI Governance, Data Privacy, Cloud Security, or an Incident Response Retainer are relevant.

As a result, you receive a defined engagement scope with clear deliverables, timelines, and success measures. This makes it easier to understand what is included before the engagement begins.

2

Tier & Scope Selection

3

Onboarding

What Happens During Onboarding?

Duration: Weeks 1-4 of engagement.

Duration: Typically weeks 1–4 of the engagement.

Then, your dedicated team begins structured onboarding. We establish the security baseline, launch initial assessments, put foundational policies in place, and set communication and reporting routines.

By the end of onboarding, you receive a documented baseline, gap analysis, core policy set, initial vulnerability findings, and an executive summary based on your selected tier.

Most importantly, this stage creates an early time-to-value checkpoint with tangible security deliverables already in place.

4

Ongoing Delivery

What Does Ongoing Program Delivery Look Like?

Once onboarding is complete, cybersecurity activities continue on a structured schedule. Depending on your tier, this can include vulnerability scanning, compliance monitoring, vCISO leadership, risk management, and security testing.

In addition, you receive recurring deliverables such as scan reports, compliance dashboards, leadership briefings, penetration test reports, tabletop results, or board-level reporting where applicable.

At the same time, monthly or quarterly review meetings keep priorities aligned. Ongoing email or Slack support can also be used for day-to-day security questions.

Communication: Meanwhile, monthly or quarterly review calls (tier-dependent), plus ongoing Slack/email support for ad hoc questions.

How Does Your Security Program Scale Over Time?

What happens: Over time, periodic program reviews assess progress against your roadmap, update risk registers, and evaluate whether your current tier still fits. 

As your organization grows—new requirements, larger teams, board scrutiny—your program scales with you.

What you get: Finally, an annual program review with recommendations, a clear upgrade path to the next tier, and continuous alignment between your security program and business objectives.

5

Program Scaling

Frequently Asked Questions

What are the steps in Idril’s CSaaS process?

Idril’s Cybersecurity as a Service process has five main steps: a free cyber risk assessment, tier and scope selection, onboarding, ongoing program delivery, and program scaling. Each stage is designed to give the organization clear deliverables, responsibilities, and next steps.

What happens during the free cyber risk assessment?

The process begins with a 15–20 minute gap assessment at no cost or obligation. Idril reviews the organization’s security posture against frameworks such as NIST CSF and CIS Controls, including policies, controls, compliance status, and threat exposure. The organization then receives a prioritized summary of findings and key gaps.

How is the right CSaaS tier selected?

After the initial assessment, Idril works with the organization to select the appropriate Essentials, Growth, or Advanced tier. In addition, relevant add-on services can be identified based on security, compliance, privacy, cloud, AI governance, or incident response needs.

What happens during CSaaS onboarding?

During onboarding, Idril establishes the security baseline, begins initial assessments, implements foundational policies, and sets communication and reporting routines. By the end of onboarding, the organization receives initial findings, policy documentation, vulnerability results, and an executive summary based on the selected tier.

What does ongoing CSaaS delivery include?

Ongoing delivery follows a defined cadence and can include vulnerability scanning, compliance monitoring, vCISO leadership, risk management, security testing, reporting, and review meetings. The specific activities and frequency depend on the selected CSaaS tier. Idril Services | Your Technology Partner

How does the cybersecurity program scale over time?

Idril periodically reviews the organization’s progress, risk register, security roadmap, and current service tier. As requirements grow, the program can expand into higher tiers, additional frameworks, or specialized capabilities.

What happens if Idril is not the right fit after the assessment?

The initial cyber risk assessment does not require an ongoing engagement. If there is no fit, the organization can keep the findings from the assessment without moving forward with a CSaaS tier. Idril Services | Your Technology Partner

Contact Us

+1-404-937-3377

172 Prospect Pl, Alpharetta, GA 30005

Monday-Friday: 9am – 5pm

Start With a Free Cyber Risk Assessment

A 15-20 minute gap audit with no cost or obligation. You’ll get a prioritized findings summary-and if there’s a fit, we’ll recommend a tier and walk through what engagement looks like.