SecOps consulting
Security work that matches the operation.
Small and mid-size companies rarely need a new security department on day one. They need the controls, the access, and the evidence to describe the same operation the floor already runs. That is the SecOps consulting Coalesce Ops does.
Why this search starts
An audit date, a customer security questionnaire, a near miss, or a stack of tools that each send an alert to a different inbox. Leadership hears one account. The people doing the work live another. A control written for the auditor can describe a different week than the one that shipped.
Hiring someone to watch a dashboard does not close that gap. It adds a person to a flow that is still split. The work is the same work as the rest of the practice: analyze how the operation actually moves, review what is split, and align it so the people you have can run it.
What is in scope
Security and compliance, including SOC 2 and PCI, with evidence that matches the controls in use. Identity and access sit in the same review: who can reach the systems that hold customer data, money, and production, and who checks that list. Onboarding, offboarding, and access review are part of it, including automation that keeps those records current.
Executives get one account of the operation, not a separate security story. The systems service is the wider pass. This page is the pass that starts from the control and the access.
Before the first call
Use this as a working list. Bring the answers you have, and say plainly where you do not have them.
- Name the systems that would matter in a breach: customer data, payments, production, and identity. One owner for each.
- Write down who has access to those systems. Note anything shared, anything still held by someone who left, and anything no one can explain.
- Write down the last time access was reviewed, and who signed it. If there is no date, that is the finding.
- If you are in SOC 2 or PCI, pick one control and walk the path the work actually takes. Mark where the evidence and the path disagree.
- List the vendors that hold data or can change a system. Note the cost if you know it, and the person who owns the relationship.
- Note where two products disagree about the same person or the same job. Identity is the usual seam.
You do not need a polished packet. The first visit is scoped in writing before it is scheduled. A rough list is enough to scope it. The method is map, name, join, prove, leave.
Where AI fits
AI pays when it carries a step your people already do, such as collecting evidence you already produce. We review the exposure and the cost, and we align it with the flow. A model that needs its own team to watch it is not an advantage, and it is not a control.
If the evidence is already wrong, automating the collection only makes the wrong record faster. Align the path first.
What this is not
This is not a security operations center, and it is not a retainer that takes the keyboard during an active breach. If that is the need, say so in the first note. We will tell you if the work is not a fit.
Readiness, as a way of working your own team can run, is a separate page: incident response readiness. It uses the same method. It does not quote a response time, because this practice does not sell one.
What you leave with
A direct account: what is already sound, what is split, and the sequence in which to join it. Procedures, owners, and the record stay with you. The engagement is finished when your team can run the cadence without us in the room.
Contact
Describe the security gap.
Tell us whether the pressure is an audit, access, a questionnaire, or an incident that had no owner. We reply with a scoped visit, or a clear reason the work is not a fit.