THRESHOLD
SECURITY · GOVERNANCE · RISK · COMPLIANCE

Own the judgment calls,
not just the paperwork.

Fractional CISO and GRC advisory for post-Series B and PE-backed companies under real investor, customer, or regulatory pressure.

01 — The problem

Most programs stall in the same three places.

I
Evidence without judgment

A control matrix gets filled in, the auditor is satisfied, and no one has decided what risk the company is actually willing to carry.

II
Sequencing by framework

Work runs in the order the standard is written, not the order the business needs it — so the expensive controls land before the load-bearing ones.

III
No one owns the call

Consultants advise, the team executes, and the trade-off between a control and a business decision sits unmade until an audit forces it.

02 — Services

Engagements, not deliverables.

01
Fractional CISO

An ongoing retainer where the security decisions have a named owner — board reporting, roadmap, and the judgment calls in between.

02
Audit readiness

SOC 2, ISO 27001, and PCI — scoped, sequenced, and evidenced to pass the first time rather than the second.

03
Programs built from zero

For companies with no security function yet: policy, control set, and operating cadence stood up in the order that actually reduces risk.

04
Third-party risk, both directions

Answering the questionnaire that's blocking a deal, and reviewing the vendors the business depends on — same judgment, either seat at the table.

05
Board-level risk reporting

Risk stated in terms a board can act on, with the posture and the open trade-offs both on the page.

03 — Method

Five phases. One of them is missing everywhere else.

Most GRC methods skip straight from assessment to implementation. Decide is where scope, sequence, risk tolerance, and the practical approach for each requirement get set and owned — before a single control is built.

Diagnose

What is actually in scope, what is already true, and where the real exposure sits.

Decide

Scope, sequence, risk tolerance, and the approach for each requirement — set, written down, and owned.

Build

Controls, policy, and tooling implemented against the decisions already made.

Defend

Audit, diligence, and customer review — the program held up under someone else's scrutiny.

Hold

The operating cadence that keeps it true after the certificate is issued.

What the call actually looks like

Faced with a control that assumed a tool we couldn't justify buying, I made the call to build a compensating approach instead and defended it as meeting the requirement's intent. It cleared on the first pass.

Faced with no playbook for AI in the development pipeline, I worked with engineering to understand not just how they were using it, but why — so the controls could bound the risk without slowing the work. Then I made the call: accept the residual risk for the speed it bought us. Not risk-free — bounded.

04 — Frameworks

The standards, and what they're for.

SOC 2

The one enterprise buyers ask for. Scoped tightly so it closes deals without swallowing the roadmap.

ISO 27001

A management system rather than a point-in-time report — the right choice when the buyers are international.

PCI DSS

Cardholder data, scoped to shrink the environment first and certify second.

NIST CSF

The common language for boards and regulators when no certificate is required.

05 — About

Zach Couasnon

CISSP · Security executive

Three roles, three different kinds of pressure: public-company scrutiny, startup speed, and platform scale.

LinkedIn
CISO — PublicSquare

Owned security and GRC across four business units in a public fintech — chairing the ERM committee, building the payments program to PCI Level 1, and authoring the company's SEC cybersecurity disclosure.

Head of Security — Basis Theory

Owned the full security function as an individual contributor embedded with engineering, taking ISO 27001 from zero to certificate in six months while keeping PCI continuous through the Azure-to-AWS migration and the 3.2.1-to-4.0 transition.

Third-party risk — Sony Interactive Entertainment

Led third-party risk and security compliance for PlayStation — including the first PCI 3DS assessment of the PSN storefront, risk assessments of its most critical systems, and business continuity planning across the program.

Start with a conversation — whether you're under pressure now or building ahead of it.

Most conversations start with a short call to determine whether this is the right engagement.

Engagements are scoped after that conversation, then structured as project or retainer work depending on what the risk posture requires.

Start a conversation