Skip to main content

Common Questions

Direct Answers to the Questions We Get Most Often

Questions about the Ascend Framework, compliance requirements, AI governance, and how DOYB engagements work — answered plainly, without filler.

Assessment Methodology

The Ascend Framework

What is the Ascend Framework?

The Ascend Framework is DOYB's structured assessment methodology — a documented process for evaluating an organization's actual security posture, compliance gaps, infrastructure health, and AI readiness before any service scope is defined. It exists because most security and IT engagements begin with assumptions about what the environment looks like. The Ascend Framework replaces those assumptions with documented findings. Every Ascend product produces a written assessment report, a risk-rated findings list, and a prioritized remediation roadmap.

Why does DOYB require an assessment before scoping services?

Because service scope defined without a documented baseline is essentially guesswork. An organization that completes an Ascend assessment has a verified record of their current state — what controls exist, what gaps exist, and what risks are rated at what severity. That baseline changes the entire engagement: recommendations are tied to actual findings, remediation is sequenced by risk priority, and outcomes are measurable against a documented starting condition. DOYB does not sell services to organizations whose risk posture hasn't been documented.

How many Ascend assessment types are there?

Eight. Ascend Cyber evaluates cybersecurity posture. Ascend Cyber 360 is the full-scope enterprise cybersecurity review. Ascend Infrastructure evaluates your IT infrastructure health. Ascend Compliance maps your environment against applicable regulatory frameworks. Ascend Physical evaluates physical security controls. Ascend AI Readiness evaluates your organization's readiness to implement AI. Ascend AI Implementation evaluates an active AI deployment. Ascend Enterprise is the comprehensive multi-domain assessment for organizations that need coverage across all dimensions.

How long does an Ascend assessment take?

Scope and complexity determine timeline. A focused Ascend Cyber assessment for a mid-size organization typically runs 2–4 weeks from kickoff to final report. An Ascend Enterprise assessment covering multiple domains and locations runs longer. Timeline is defined in the engagement proposal before any work begins — there are no open-ended assessments.

What does an Ascend assessment produce?

Every assessment produces three deliverables: a written assessment report documenting current state and methodology, a risk-rated findings list with severity classification for each identified gap, and a prioritized remediation roadmap sequencing remediation by risk level. These documents are designed to withstand scrutiny from auditors, insurers, regulators, and board members.

Compliance Programs

Compliance & Regulatory Requirements

Which compliance frameworks does DOYB cover?

NIST CSF 2.0, NIST SP 800-53, SOC 2 Type II, HIPAA/HITECH, PCI DSS v4.0, CMMC 2.0, GLBA Safeguards Rule, GDPR, CJIS Security Policy, FERPA/CIPA, CIS Controls v8, and ISO 27001. The applicable frameworks for your organization depend on your industry, the types of data you handle, your customer requirements, and whether you operate in regulated markets. An Ascend Compliance assessment identifies which frameworks apply and where your gaps are.

What does CMMC 2.0 require and who needs it?

The Cybersecurity Maturity Model Certification applies to Department of Defense contractors and subcontractors that handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). CMMC 2.0 establishes three levels — Foundational (Level 1), Advanced (Level 2), and Expert (Level 3). Most contractors that handle CUI must achieve Level 2, which requires third-party assessment by a C3PAO. Organizations that haven't started CMMC preparation should treat it as urgent — third-party assessment timelines are extending as demand increases.

How long does SOC 2 Type II readiness take?

A SOC 2 Type II audit covers a defined observation period — typically 6 or 12 months — during which controls must be operating effectively. Before the observation period begins, most organizations need a readiness assessment to identify control gaps and implement missing controls. Organizations with no existing security program should plan for 9–18 months from readiness assessment to audit completion. Organizations with existing documentation and controls in place may move faster.

What's the difference between HIPAA compliance and HIPAA certification?

There is no official HIPAA certification. HIPAA is enforced through HHS Office for Civil Rights investigations, typically triggered by breach reports or complaints. "HIPAA compliant" means your organization has implemented the required administrative, physical, and technical safeguards and has documentation to demonstrate it — not that a third party has issued a certificate. DOYB's compliance engagements produce documentation structured to satisfy HHS OCR scrutiny, not a certificate of uncertain value.

Does DOYB help with cyber insurance compliance requirements?

Yes. Cyber insurance underwriters have significantly increased their security requirements over the past several years. Common requirements now include MFA on all remote access and privileged accounts, endpoint detection and response, documented incident response plans, offline backups, and regular security assessments. An Ascend Cyber assessment produces documentation structured to satisfy underwriter questionnaires. DOYB can work directly with your broker's technical requirements.

Service Delivery

Services & Engagement Model

What's the difference between DOYB's managed security and a standard MSP?

Most managed service providers offer a fixed service catalog applied uniformly. DOYB's service delivery begins with an assessment of your actual environment — the service scope reflects what the assessment found, not what fits a standard package. Additionally, DOYB's service portfolio spans security operations, compliance programs, virtual executive advisory, and AI readiness — functions that most traditional MSPs don't offer. The engagement model is also different: DOYB acts as an advisory partner with documented outcomes, not a help desk with a monthly retainer.

What is a vCISO and does my organization need one?

A virtual Chief Information Security Officer (vCISO) provides executive-level security leadership without the cost of a full-time hire. The vCISO owns security strategy, policy governance, board reporting, vendor management, incident response oversight, and compliance program direction. Organizations that need executive security leadership but can't justify a $250,000+ full-time CISO are the primary vCISO customer — which includes most organizations under 500 employees and many larger organizations in cost-constrained industries. An Ascend Cyber assessment will identify whether your organization has the security governance gap that a vCISO fills.

Does DOYB provide on-site services or only remote delivery?

Both. Most Ascend assessments, compliance programs, and virtual executive advisory engagements deliver effectively via secure remote collaboration. Physical security assessments, data center evaluations, and infrastructure deployments require on-site presence and DOYB coordinates travel to client sites nationally. DOYB maintains offices in Atlanta and Macon, Georgia and serves clients across the United States.

How does DOYB handle incident response?

DOYB's managed security service includes incident response as part of ongoing coverage — clients don't pay separately for IR when an incident occurs during active managed service coverage. Organizations not currently on a managed security engagement can engage DOYB for incident response on a retainer or emergency basis. DOYB recommends having an incident response retainer in place before an incident occurs — engaging a firm mid-breach is significantly more expensive and slower than activating a pre-existing relationship.

What does DOYB's AI readiness assessment cover?

The Ascend AI Readiness assessment evaluates four dimensions: technical readiness (infrastructure, data quality, integration capability), governance readiness (AI policy, acceptable use frameworks, risk management), compliance readiness (EU AI Act risk classification, sector-specific AI requirements, data privacy obligations), and organizational readiness (training, change management, leadership alignment). The output is a documented baseline and a prioritized readiness roadmap — not a recommendation to buy a specific AI product.

AI & Emerging Technology

AI Readiness & Governance

What is the EU AI Act and does it apply to US companies?

The EU AI Act is a comprehensive regulatory framework for AI systems operating in or affecting EU markets. It classifies AI systems by risk level (unacceptable, high, limited, and minimal risk) and establishes conformity assessment requirements for high-risk applications. US companies are affected if they deploy AI systems to EU customers, use AI in products or services offered in EU markets, or use cloud infrastructure that processes EU data through AI systems. The Act's compliance deadlines are phased — high-risk system requirements are already in effect for some categories.

What AI governance risks should organizations prioritize?

Data privacy (what data AI systems process and whether that processing is authorized), model transparency (can decisions made by AI be explained to regulators, customers, or employees affected by them), vendor dependency (what access do AI vendors have to your data), shadow AI (employees using unauthorized AI tools with organizational data), and compliance gaps in existing data processing agreements that predate AI feature deployment. Most organizations have AI governance gaps they're not aware of — they've deployed AI capabilities faster than governance frameworks have been updated to cover them.

Is ChatGPT or Microsoft Copilot safe to use with business data?

It depends on configuration and contract terms, not the product name. Microsoft 365 Copilot has specific data residency and processing commitments that differ from the consumer ChatGPT service. Enterprise agreements with AI vendors typically include data processing commitments that consumer terms don't. Organizations using AI tools for business purposes should review their contracts, configure data handling settings appropriately, and document what organizational data flows through which AI systems. DOYB's AI Readiness assessment includes an AI tool inventory and data flow analysis.

What's the difference between AI readiness and AI implementation?

Readiness covers the question: is your organization prepared to adopt AI responsibly? Implementation covers the question: is this specific AI deployment working as intended, securely, and in compliance with applicable requirements? An organization that hasn't completed a readiness assessment before deploying AI has skipped a step — which typically surfaces as governance gaps, compliance exposure, or integration failures discovered after deployment. The Ascend AI Readiness and Ascend AI Implementation assessments address these as sequential steps in a responsible AI adoption lifecycle.

Starting an Engagement

How to Get Started

What's the first step to working with DOYB?

A 30-minute consultation. DOYB doesn't define engagement scope before understanding your organization — your industry, current security posture, compliance obligations, and what's driving the need for an assessment. The consultation is free, takes 30 minutes, and produces a recommendation for which Ascend assessment is the right starting point for your situation. You can schedule directly via the link on this page or contact us by phone or email.

Does DOYB work with small organizations?

Yes, with a caveat. DOYB's engagement model is structured around documented assessments and formal service delivery — which carries overhead. Organizations with fewer than 10 employees and no compliance obligations may not get the value from a formal Ascend engagement that a larger or regulated organization would. DOYB will tell you this directly in a consultation if it applies to your situation. The consultation is free and there's no commitment to proceed.

How is DOYB's pricing structured?

Engagement-based pricing tied to assessment scope. Every engagement begins with a fixed-scope proposal — scope, methodology, deliverables, timeline, and price are all defined before any work begins. There are no open-ended retainers that grow without client approval and no surprise change orders. Ongoing managed services (managed security, managed IT, virtual executive advisory) are priced on a monthly basis against a defined scope of coverage. Pricing is discussed in the consultation after the right assessment type is identified.

Work With DOYB

Still Have Questions? Start With a Free Consultation.

A 30-minute call answers the questions specific to your organization — your industry, your compliance obligations, your risk posture. No commitment to proceed, no generic pitch.