Virtual CISO & Compliance Support
IT Risk Consulting for Mission-Driven Organizations
ETTE gives nonprofits, associations and small businesses clear risk ownership, written policies and board-ready reporting, backed by CISSP and CISA certified leadership.
- Risk register, policies and vendor-risk review you own
- Answers for insurer, funder and audit questionnaires
- GuardRail posture scores your board can actually read
Serving Washington, D.C. organizations since 2002. CISSP and CISA certified.
Prefer to talk? Call 202-345-1965
Request an IT risk consultation
Tell us about your organization and the risk or compliance pressure you face. We reply with next steps and a scoped proposal.
Why organizations choose ETTE for risk and compliance
Someone owns the risk
Our Virtual CISO service takes ownership of your risk register, policies and security governance, so it stops sitting on a busy director's desk.
Reporting your board understands
ETTE GuardRail scores your security posture and reports it in plain language, so leaders can act without a technical background.
Questionnaires answered with evidence
We help with insurer and funder questionnaires, evidence requests, vendor-risk review and audit coordination.
Familiar control families
Work is organized around CIS Controls and NIST-style categories, so your findings map to what auditors and funders expect.
Certified security leadership
CISSP and CISA certified expertise guiding your policies, controls and decisions.
Built for lean teams
We work with nonprofits, associations and small businesses of roughly 10 to 150 staff, with or without internal IT.
What IT risk and compliance consulting covers
Most nonprofits and associations do not need a full-time security officer. They need someone accountable for risk, a set of current policies, and clear answers when a funder, insurer or auditor asks how data is protected. That is what ETTE's Virtual CISO and compliance work delivers.
We start with what you already have, document the environment, and organize controls around familiar CIS and NIST-style control families. Then we keep it current with steady advisory, plain-language reporting and GuardRail posture scoring your board can read.
- Risk register ownership and ongoing risk review
- Security policy development and maintained documentation
- Insurer, funder and client security questionnaire support
- Audit coordination and evidence requests
- Vendor-risk review for the tools and partners you rely on
- Board and leadership security reporting through ETTE GuardRail
- Day-one managed security controls: MDR, endpoint protection, email and web filtering, managed firewall where applicable
- Identity and access protection with MFA and least-privilege access
- Security awareness training and simulated phishing for staff
A long-term DC partner, not a one-off project
“ETTE is the Gold Standard for IT providers. I could write an essay about all of the ways in which they've helped our organization. If you are looking for an IT and Cyber Security provider, look no further!”
“They sought the expertise of IT consultants and were immensely impressed with the results. The pragmatic project management and quality-first mindset of the consultants helped the bank bring their internal IT processes to new heights.”
“The firm appreciated the highly skilled and uniquely capable team of IT consultants that helped them achieve utmost success on a number of diverse projects.”
What happens after you submit
We talk through your risk
A short call to understand your size, systems, and what is driving the compliance or risk need.
We scope the engagement
Advisory work is scoped on cadence, decision rights and deliverables, so you see exactly what you get.
You get a written proposal
Clear scope and pricing. If you move ahead, our 30-day Smooth Start onboarding documents your environment.
Frequently asked questions
How is IT risk consulting priced?
Virtual CISO and advisory engagements are scoped separately, with pricing based on cadence, decision rights and deliverables. Managed IT plans are priced separately: Fully Managed starts at $150+/user/month with a $2,500/month minimum, and Remote-Only starts at $125+/user/month with a $1,500/month minimum.
Do you offer nonprofit pricing?
Yes. Nonprofit pricing is available and is scoped during the proposal based on headcount, support model and service mix.
Can you help us answer a funder or insurer security questionnaire?
Yes. Evidence requests, insurer and funder questionnaires, vendor-risk review and audit coordination are part of our Virtual CISO and compliance support.
Do we have to buy managed IT to get risk consulting?
Virtual CISO and strategic advisory are scoped as separate engagements. Many clients pair them with our managed security baseline. We will explain what fits during scoping.
Which frameworks do you work with?
We organize controls around familiar control families such as CIS Controls and NIST-style categories, so your documentation supports board, audit and evidence conversations.
Do you work outside Washington, D.C.?
On-site support is for the Washington, D.C. metro area. Remote-only managed IT and advisory work is available to distributed teams across the United States.
Get clear ownership of your IT risk
Tell us what is driving the review, whether it is an audit, a funder questionnaire or a board request. We will scope the right level of support and send a written proposal.
- Risk register, policies and vendor-risk review you own
- Answers for insurer, funder and audit questionnaires
- GuardRail posture scores your board can actually read
Prefer to talk? Call 202-345-1965