Companies

Eight briefs. Real artifacts waiting to be built.

Each brief has systems, regulatory exposure, relevant frameworks, risks, control priorities, audit concerns, vendor risk, BCP/DR concerns, and the analyst task to actually do.

SaaS
North America
Northbeam Analytics

Series-B observability platform with 180 employees, mostly remote engineers, processing customer telemetry in AWS.

Analyst task

You joined as the lead GRC analyst last month. Produce a 90-day plan that addresses the most material audit findings, stands up a vendor risk program, and gets the org to its first SOC 2 Type I readiness assessment.

Open brief →
Healthcare
US
Atlas Health Partners

Regional integrated delivery network with 14 clinics and a shared EHR, recently completed a merger with a smaller group.

Analyst task

You inherited a half-finished HITRUST journey and a recent OCR inquiry letter. Sequence the next 60 days: which HITRUST controls do you close first, what do you send the OCR, and how do you get the post-merger combined entity onto one risk register?

Open brief →
Fintech
United States + EU
Trellis Pay

Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.

Analyst task

Design a control universe to underpin an ISO 27001 certification attempt within 12 months. Show how PCI, SOC 2, and ISO controls overlap and where Annex A adds policies that are not yet in the program.

Open brief →
Retail
Global
WovenCart

D2C apparel brand with 400 employees, peak-season traffic concentrated in November-December.

Analyst task

Quantify the PCI scope question for the next QSA and write the internal page that walks finance through what is and is not in PCI scope at WovenCart.

Open brief →
Government Contractor
US
Ironfield Defense Systems

Mid-sized defense contractor with cleared personnel, handling Controlled Unclassified Information (CUI) and some ITAR data.

Analyst task

You are 90 days from a CMMC L2 assessment. Write the readiness plan and the briefing for the COO on what is at risk if any of the top three POA&M items slip.

Open brief →
Education
EU
Lumora Learning

Online K-12 tutoring platform with 1.2M students across the EU, processing minors' data and special category data (educational records).

Analyst task

Plan the privacy program uplift before launching the new AI-recommendation feature. Produce the DPIA outline, the data-minimisation argument, and the parental-consent UX changes required.

Open brief →
Manufacturing
North America + Mexico
Cobalt Industrial

Industrial OEM with eight plants, 3,000 employees, and a recently acquired IT/OT convergence program.

Analyst task

You inherited an OT security program in its first year. Write the 12-month roadmap that justifies the spend to the plant managers — they do not care about frameworks, only uptime.

Open brief →
SaaS
APAC
VergeWorks

Singapore-headquartered dev tooling company with 60 employees and enterprise customers in JP, AU, and SG.

Analyst task

You are the first GRC hire. Write the first 90 days for a one-person program: what do you build, what do you defer, and what gets you the most audit mileage first?

Open brief →