Phase 0 — The Enterprise AI Risk Assessment
The front-door methodology: map the whole AI and security footprint — sanctioned and shadow — against the frameworks that matter, then produce a current-state map, a future-state design, and a sequenced six-pillar build plan. Scoped assessment, not a build guide.
The front door to the whole programme. Before any pillar is built, Phase 0 maps the ecosystem it will be built into — and nothing downstream gets a number until it is delivered. This is that assessment as a methodology you can run yourself.
You cannot architect a security department for an organisation you have not mapped. Phase 0 lays out the whole current ecosystem, start to finish, so the six pillars snap into real infrastructure instead of assumptions. It is the diagnostic that earns the right to name the programme.
A scoped methodology, not a build guide. The pillar guides tell you how to construct a capability. This one tells you how to find out what you actually have, rate it honestly, and sequence what to build first. Different artifact, different job.
What it maps. Every AI system in use — sanctioned and shadow. The DevSecOps reality rather than the diagram. The data and identity stack. The SIEM, EDR and tooling landscape. And where testing should start.
Map once against NIST AI RMF, comply across the rest. The methodology collects risk from humans, technology and policy, then maps it against the frameworks that matter, so one assessment answers to several regimes rather than being redone per framework.
The risks the classic frameworks are structurally blind to. Traditional control catalogues were not written for systems that behave differently on Tuesday than they did on Monday, and the assessment is explicit about where they stop being sufficient.
Scope → collect → map → rate → sequence. Five stages, each with its worksheet. The output is a holistic architecture: the current-state map, the future-state design, and a sequenced build plan for the six pillars — scoped to your size, your stack and your risk.
It turns the pillars into entry points. A full department is the sum, not the ask. After Phase 0 each pillar is a scoped piece of work you can start independently — AI-SOC this quarter, PTaaS next, an IR capability because a cyber-insurance renewal requires it. You buy the sequence your risk dictates rather than making one all-or-nothing decision.
Designs the seams, not a rip-and-replace. Where the programme snaps into what you already run: whichever AI platform your teams have deployed becomes the read-only seam into your SIEM and AV. For distributed estates, the deployment topology includes a collection plane running in parallel — federating zero trust and reaching every site and segment without a per-site VPN.
Run it yourself with this methodology, or have CISO Marketplace run Phase 0 as the scoped, fixed-fee engagement it is designed to be.
Also available in 3 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Phase 0 + Shadow AI Pack
The assessment that finds every AI system in your estate, paired with the workbook that inventories and scores them. Map the footprint, then govern it. 20% off buying separately.
Phase 0 + Risk & Readiness Pack
The front-door assessment plus the four workbooks that prove readiness to the people who ask — ransomware, tabletop, cyber insurance and shadow AI. 25% off buying separately.
Complete Security Program Pillars
The whole programme — the Phase 0 assessment that scopes it, all six pillars, and the C2 command layer that conducts them — the compliance operating system, the DevSecOps risk register, the Bug-Hunter discovery layer, the PTaaS proof lane, both halves of the AI-SOC pillar, and the Fractional CISO operating system they all report into. Discovery to detection to remediation as one program. 20% off buying separately.
What's included
- PDF — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
Complete your toolkit
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee