Services
Risk-First Advisory. Scoped Security. Controlled Support.
Three focused service lines — sized for firms that need real protection without a full-time IT department.
01 · Primary Revenue Driver
IT Risk & Compliance Management
We help you understand, document, and reduce the risk your firm carries — in language your partners, your insurer, and your regulators all accept. This is where enterprise GRC experience meets small-firm reality.
What’s Included
- Risk assessments aligned to NIST CSF / NIST 800-53 (scaled for small firms)
- IT General Controls (ITGC) evaluations — access, change management, backups
- Policy development (acceptable use, data handling, incident response, remote work)
- Vendor and third-party risk assessments
- Annual compliance readiness reviews
- Control testing and documentation
What You Receive
- A formal risk register
- A gap assessment report
- Control testing workpapers
- Ready-to-adopt policy templates
02 · Scoped, Not Heavy MSP
Network & Security Services
We harden the systems your firm actually depends on day-to-day.
What’s Included
- Secure remote access configuration
- Multi-factor authentication (MFA) implementation
- Endpoint protection standardization
- Backup validation and testing
- Basic vulnerability scanning coordination
- Email security hardening (SPF/DKIM/DMARC, phishing controls)
A Strong Baseline
Not 24/7 SOC monitoring — sized to what a 2–20 person firm actually needs. We focus on the controls that most reduce breach and liability risk.
03 · Controlled Scope
Helpdesk Support
Support is intentionally narrow — remote, ticket-based, and defined in the engagement agreement rather than open-ended, so both sides know exactly what is covered.
How It Works
- Remote support only
- Ticket-based intake and tracking
- Coverage hours and response expectations set per engagement
- Escalation path agreed in writing before work begins
A Note on Scope
RGC Consulting is a risk and compliance practice first. Helpdesk support exists to keep the controls working — it is not a replacement for a full-service MSP.
Risk First, Then Controls
Every engagement starts by establishing where a firm’s real exposure sits — in fines, malpractice risk, and client trust — before any tooling or spend is recommended.
