Frequently Asked Questions
Clear answers before the first conversation.
Cybersecurity, compliance, and AI can become complicated quickly. These answers explain how Citadel Networks approaches the work and what organizations can expect.
Working with Citadel Networks
Who is Citadel Networks designed to serve?
Our work is designed for small and mid-sized organizations, healthcare organizations, government contractors, and professional or regulated businesses that need trusted cybersecurity guidance without building a large internal security department.
Do you provide managed IT support?
Citadel Networks is positioned primarily as a cybersecurity, compliance, and secure AI advisory and implementation firm. We can coordinate with internal IT teams and managed service providers so security responsibilities are clear.
Can you work with our existing IT provider?
Yes. Many organizations already have a trusted IT team or provider. Citadel Networks can assess risk, guide strategy, coordinate projects, define control requirements, and validate progress while the IT provider manages day-to-day technology.
Where do you work?
Citadel Networks is based in Oregon and can support remote engagements across the United States. On-site requirements can be discussed based on location and scope.
What is the best first step?
The best starting point is usually a short conversation about the business concern, requirement, or change driving the need. From there, we can recommend an assessment, readiness engagement, implementation project, or advisory relationship.
Cybersecurity Risk Assessments
What does a cybersecurity risk assessment evaluate?
A business-focused assessment evaluates people, processes, technology, data, vendors, governance, resilience, and relevant requirements. The objective is to identify business risk and provide a prioritized roadmap.
Is a risk assessment the same as a vulnerability scan?
No. A vulnerability scan identifies certain technical weaknesses. A risk assessment considers the broader business context, likelihood, impact, controls, dependencies, and decision-making needs. Technical testing may be included or recommended based on scope.
Will we receive a prioritized plan?
Yes. The assessment is designed to produce clear priorities organized by risk, urgency, effort, dependency, and business impact—not just a list of findings.
Can the assessment support cyber insurance or customer questionnaires?
It can help organize the current state, identify gaps, and provide supporting evidence. It does not guarantee insurance coverage, satisfy every customer request, or replace a formal audit.
Compliance Readiness
Do you certify organizations for HIPAA, CMMC, or SOC 2?
No. Citadel Networks provides readiness, implementation, documentation, evidence preparation, and coordination. Formal certifications, CMMC status, CPA attestations, legal opinions, and audit conclusions must come from the appropriate authorized or qualified professionals.
Can you help us determine which framework applies?
We can help identify likely drivers, scope, and information needs, but contracts and legal requirements should be confirmed with qualified legal, contracting, audit, or regulatory professionals.
Will you create policies for us?
Yes, policy and procedure development can be part of an engagement. The documents are built around the organization’s actual processes, control ownership, technology, and obligations rather than copied as generic templates.
Can you help implement the controls after the gap assessment?
Yes. Implementation is a core service. We can lead the roadmap, coordinate internal and external providers, implement technical and administrative controls, and help organize evidence.
Implementation and Ongoing Advisory
Do you require a specific security product stack?
No. We evaluate existing investments and recommend solutions based on risk, business requirements, integration, supportability, and budget.
What does ongoing cybersecurity advisory include?
Engagements can include strategy, roadmap management, risk register review, executive reporting, policy governance, vendor guidance, incident readiness, compliance coordination, and continuous improvement.
How do you measure progress?
Progress can be measured through roadmap completion, risk reduction, maturity profiles, control coverage, evidence quality, incident readiness, testing results, and leadership-approved metrics.
Can you help during a cybersecurity incident?
We can help clients prepare incident plans, roles, communications, and exercises. Active incident-response scope depends on the engagement and may require coordination with forensic, legal, insurance, law-enforcement, and other specialized providers.
AI Implementation and Security
Should we ban public AI tools?
A blanket ban is not always the most practical answer. Organizations need approved-tool guidance, data restrictions, use-case rules, human review, and enforcement that reflect their actual risk and obligations.
Can you help choose secure AI tools?
Yes. We can evaluate security, privacy, administration, data handling, contractual terms, integration, and business fit. Legal and privacy counsel should address legal interpretations and contract language where needed.
What belongs in an AI acceptable-use policy?
A practical policy should address approved tools, prohibited data, acceptable use cases, human review, output verification, intellectual property, privacy, security incidents, exceptions, and accountability.
Is AI governance necessary for a small business?
Yes, although the governance can be simple. Smaller businesses still handle confidential information, serve customers, make important decisions, and depend on employees knowing what is safe.
Still have a question?
Tell us what you are trying to solve. We will help you identify the right next step—even when that step is not a Citadel Networks engagement.