Our approach

From security questions to prioritized action.

Calderstone uses a straightforward five-stage process designed to keep assessments understandable, evidence-based and useful.

01 — UNDERSTAND

Business & Scope

Identify business priorities, users, systems, sensitive information, key vendors and the purpose of the engagement.

02 — ASSESS

Controls & Evidence

Review the controls, configurations, documentation and evidence relevant to the agreed scope.

03 — PRIORITIZE

Risk & Findings

Organize findings around severity, likelihood, business impact and realistic remediation priority.

04 — REMEDIATE

Practical Improvements

Where included in scope, help implement agreed changes and document what was changed.

05 — VALIDATE

Confirm & Communicate

Validate completed improvements and communicate remaining risk and recommended next steps.

Framework-informed, not checklist-driven.

Where appropriate, Calderstone can use recognized cybersecurity practices and frameworks such as the NIST Cybersecurity Framework and NIST security controls to structure reviews. The objective is not paperwork for its own sake; it is to connect security controls to actual business risk.