Frequently Asked Questions


What services does Arrakis Consulting offer?

Arrakis Consulting offers numerous services ranging from pure consultation, managed services, managed security services, one off services, to staff augmentation.

For managed services, pricing is based on duration commitment, # of devices/users, and number of services committed to.

Arrakis offers consultative services for a variety of different purposes.  This could help a company prepare for a certification audit, support it through a certification audit, handle incident response, address Enterprise Risk, or other cybersecurity or privacy-related activities that might require an independent third party to weigh in.

All our managed services are designed to help you get regulatory compliant faster and with less effort.

Contract Management
Online Encrypted Backup
Patching of Operating System and 3rd Party software
Hardware and Software Inventory
Network/Data flow mapping
File Synchronization
Remote Access
Cloud Assessments
AND MORE!

Privilege Access Management (PAM)
Security Information Event Management (SIEM)
Data Loss Protection (DLP)
Anti-SPAM with AI
Cybersecurity Awareness Training (CSAT)
Web filter
DNS filter
Darkweb Monitoring
Vulnerability Assessments as a Service
Penetration Testing as a Service
Antivirus
Password Management
Threat Intelligence
Employee Surveillance
Multifactor Authentication
AND MORE!

Business Impact Analysis (BIA)
Disaster Recover\Business Continuity (DR\BC) Exercises
Penetration Testing
Internal Audit
Investigations
Incident Response

Virtual Chief Information Security Officer (vCISO)
Virtual Chief Information Officer (vCIO)
Virtual Chief Privacy Officer (vCPO)
Virtual Data Protection Officer (vDPO)
Project Manager
And others....

ISO 27001/2 - Information Security
ISO 27005 - Risk (supporting ISO 27001)
ISO 27032 - Cybersecurity
ISO 27033 - Network Security
ISO 27034 - Application Security
ISO 27035 - Incident Response
ISO 31000 - Enterprise Risk
ISO 42001 - Artificial Intelligence
CMMC - DoD/DoW cyber and information security
ISACA CISA - Information security auditing
ISACA CISM - Information security management
And much more!!


Contact us by filling out this form - Contact Us


Compliance

What does it take to get certified and stay certified.

Yes, currently all client companies have achieved their certification goals both initially and repeatedly.

SOC2 generally takes about 6-9 months, ISO 27001 takes 6–12 months, and CMMC takes 18–24 months. If you are starting from scratch, you are at the longer end of the compliance range. If you have some controls in place, then it's quicker.

Another factor is the size of the company; larger companies generally face more red tape. More technically diverse companies can also be more difficult to work with. Also, remember that you can reduce the audit footprint, thereby reducing effort, cost, and time. 

No, and here's why that's a problem most companies don't see coming. Certification isn't a finish line—it's a starting line.

Certification is a lifestyle, and as long as the lifestyle is maintained, staying compliant and keeping the certification are possible and much easier.  When companies start taking breaks or only care about compliance closer to surveillance audits, it becomes more difficult and expensive.

There will be a need for continuous monitoring, surveillance audits, recertification audits, documentation updates and reviews, penetration testing, and various types of exercises. It's a lot, and companies that try to do it all themselves generally set expectations that don't match reality. 

Arrakis offers "Phase 3", which is where we help companies stay vigilant and not backslide out of compliance.

The honest answer is that you could do it yourself; however, most companies vastly underestimate what needs to be done and interpret what is required in a way that favors the company rather than what is actually required to get, or maintain, certification.

This is where Arrakis plays a major role; we won't lie to you about what needs to be done or how to get there. Assuming you wanted to do it yourself, your internal team would spend ~12 months learning compliance rather than doing their jobs. Your company would likely implement controls in a manner that "sounds right" but isn't. Then, you would likely fail your first audit at a cost of ~$ 40K. Quite often, there is either disciplinary action for wasted effort and funds, or the company changes direction and convinces itself that it doesn't have to get certified... which impacts revenue... every time!

Arrakis brings professionals with 20+ years of experience preparing companies for this and currently has a 100% success rate.

SOC2 is generally estimated at $50-60K, ISO 27001 is $60-75K, and CMMC is closer to $100K. All numbers can vary, though, based on the size and complexity of the company.  It is also important to note that the cost depends on the company's dedication and commitment.  The most common delay factor is "company culture," in that a company hasn't fully grasped the new requirements it must adhere to.

Internal labor isn't free and will require significant employee hours if attempted in-house.  This implies that you should either expect to hire twice as many people or face a significant number of daily tasks not being completed.

Penetration testing can range from $36K to $150K, depending on the type of test needed and the complexity of your company.

A GRC tool is likely going to be needed to increase the efficiency of getting, or staying, compliant, and that price can vary from $25K to well over $500K based on the complexity and size of your company.  Arrakis partners with several GRC providers and can work with you to explore potential discounts.

Ongoing maintenance is always an added cost and can vary based on the size and complexity of your company.  Arrakis offers numerous managed services to help reduce the internal effort your personnel may need to handle.

Training can also be a concern if it is required for compliance or to increase the individual's skill set.  Regardless, it is not uncommon for unique or customized training to be required due to the regulatory environment your company is subject to.

There are also one-off activities that need to be performed.  Business Continuity and Incident Response exercises are at the top of the list.

Regardless of your compliance initiatives, your company will need future audits to maintain certification.  Generally, the initial audit is the most expensive as it is the most detailed; however, some environments require detailed audits at every juncture.

Arrakis offers multiple levels of reporting. Phase 1 assessments are detailed, generally over 100 pages in length, and designed to act as audit evidence of a third party performing activities for a client.

Generalized reporting for Phase 2 is based on the client's needs but normally weekly. 

Internal Audit reports provide high-level details while going into detail on findings or OFIs. 

Penetration testing reports are generally several hundred pages with detailed information.

All reports with a possible audit function will be delivered by DocuSign to a single individual within the client environment.

Yes, if you handle sensitive data or operate in regulated environments, the rules apply to you as well.  Regulators do not ask about a company's size, nor do law enforcement or investigators care whether a company is a startup or not.  

Companies that believe they are "too small" to be targets of bad actors or to be investigated are simply creating a false sense of security that can lead to serious company and personal sanctions.

A vulnerability assessment scans and reviews your environment and devices, identifying what is vulnerable to compromise.  Vulnerability assessments are generally suggested to be performed at least every 30 days to better align with patching methodology.

A penetration test is a continuation of a vulnerability assessment. It attempts to compromise the affected device or environment to determine what can actually be done, rather than informing you of what "could be" done.  Penetration testing must be done at least annually.  Arrakis offers penetration testing as a one-off or as a managed service, where we perform a pentest monthly.

Yes, Arrakis can provide consultative support to help you get compliant, as well as numerous managed services, each designed to get you compliant faster and with less effort.

Great question. Here's the reality:

Most IT providers are excellent at keeping your systems running, but security and compliance are specialized disciplines that require different expertise.  Essentially, IT providers are offering a service, but they don't know "WHY" they are offering it... just that there is a market for it.

What traditional IT providers do well:
- Help desk and user support
- Network infrastructure
- Hardware and software procurement
- System uptime and performance
- Email and productivity tools

What traditional IT providers typically don't do (or don't do well):
- Compliance frameworks – ISO 27001, CMMC, SOC 2, HIPAA, GDPR require specialized knowledge.  This specialized knowledge is the result of extensive training and years of experience.
- Security architecture – Designing defense-in-depth, zero-trust, and risk-based security models with an active defense posture in mind while evaluating aggressive attack methods.
- Threat intelligence and incident response – Detecting, analyzing, and responding to sophisticated attacks.
- Audit preparation – Knowing what auditors look for and how to document evidence—understanding "the essence" of the control being audited.
- Continuous compliance monitoring – Tracking control effectiveness and maintaining certification.

How we work together:  We don't replace your IT provider—we complement them. Think of it this way:
- Your IT provider = Helps keeps the lights on
- Arrakis = Makes sure the lights are secure and compliant

We collaborate with your existing IT team, provide guidance on security configurations, and handle specialized security and compliance work they're not equipped to handle or don't have the experience for.

We even work with other MSPs who need cybersecurity expertise for their clients. We provide white-label services so they can offer enterprise-grade security without building that capability in-house.

First, let's be clear: With Arrakis, the chances of that happening are very low. We have a 100% client pass rate, but we also don't promise or guarantee that you will pass.  If you do what we tell you to do, then you are very likely to pass.

But let's talk about what failure looks like (because understanding the stakes matters):

Immediate consequences:
- No certification – You don't get the cert, which means you can't bid on contracts or meet customer requirements, and in some cases, you will be removed from the contract.
- Remediation costs – You have to fix the gaps and pay for a re-audit, which is generally the same cost as the initial audit.
- Timeline delays – Add 3–6 months to your certification timeline
- Lost opportunities – Contracts you can't bid on, customers you can't onboard, revenue you can't capture

Longer-term impacts:
- Reputation damage – Word spreads in regulated industries
- Customer trust issues – Existing clients may question your security posture
- Increased scrutiny – Future audits may be more rigorous

Common reasons companies fail audits:
- Incomplete documentation – Missing policies, procedures, or evidence
- Control gaps – Implementing controls that don't actually meet requirements
- Lack of evidence – Can't prove controls are working
- Scope creep – Auditor finds systems you didn't include in scope
- Poor preparation – Not understanding what the auditor will look for

How do we prevent failure?
- Pre-audit internal audits – We audit you before the real auditor does
- Gap remediation – We fix issues before they become audit findings
- Real-time audit support – We're there during your certification audit to answer technical questions
- Evidence management – We help you build and maintain the documentation auditors need

Our approach: We don't just implement controls—we validate and test them, ensuring they'll pass scrutiny. That's why our pass rate is currently 100%.

You're not paranoid—you probably need it. Here's how to know for sure:

You DEFINITELY need compliance certification if:
- You're a government contractor or subcontractor (CMMC required)
- You handle credit card data (PCI-DSS required)
- You process healthcare data (HIPAA required)
- You handle EU citizen data (GDPR required)
- Your contracts explicitly require ISO 27001, SOC 2, or other certifications
- You're in a regulated industry (finance, defense, healthcare)

You PROBABLY need it if:
- Customers are asking about your security practices
- You're losing deals because you can't prove compliance
- You're handling sensitive customer data
- You're growing and need to formalize security
- You're preparing for an acquisition or investment
- Your cyber insurance requires it
- Has your company ever been contacted by the FTC

You MIGHT not need formal certification if:
- You're a small business with no regulatory requirements
- You don't handle sensitive data
- Your customers don't require it
- You're comfortable with informal security practices

The business case beyond compliance:

Revenue protection:
- 67% of B2B buyers require security certifications
- Average deal size increases 40% with ISO 27001 or SOC 2
- Certification can be the difference between winning and losing contracts

Cost avoidance:
- Average data breach costs $4.45M (IBM 2023)
- Cyber insurance premiums drop 15-30% with certification
- Regulatory fines can reach millions for non-compliance

Operational efficiency:
- Formalized processes reduce security incidents by 60%
- Clear policies reduce employee confusion and mistakes
- Audit readiness eliminates last-minute scrambles

The smart question: "What's the minimum we need to do?" Start with a risk assessment (Arrakis offers free initial assessments).

This will tell you:
- What regulations actually apply to you
- Your current security gaps
- Estimated cost and timeline for compliance
- ROI analysis for certification

Bottom line: If you're asking the question, you probably need to explore it at least a bit. A 30-minute conversation with Arrakis can save you months of uncertainty and potentially millions in risk exposure.

Yes and No.  It depends on how you are going to use AI.  If you are in a regulated environment of any kind and the AI is involved in any transaction involving protected information, then "yes, absolutely".

However, if you are using AI in a way that only benefits the company from an efficiency standpoint, then likely not.

Regardless of whether you have concerns, you should also understand the potential security risks of AI.  An initial concern should be exactly what AI is in use and what information will be shared with the AI platform.  If the AI platform is external and you are uploading company-sensitive information (intellectual property), you should understand that your IP is on an external system. You may not have a clear understanding of how your data is protected.  It's not uncommon at all that external cloud-based AI platforms are actually learning (think of it as a child maturing over time) from your IP, which may reduce your company's competitiveness.  This includes AI platforms that are government-sponsored or under the control of a foreign government.

In general, Arrakis recommends considering how your company can incorporate AI into your business processes, given the increased benefits it will derive.  But do so safely.  Because of the potential for dangerous AI-related activity, Arrakis recommends that you require personnel to complete AI-related security training, such as ISO 42001 or the Certified Artificial Intelligence Professional.


Contact us by filling out this form - Contact Us


Training

How you can expand your skill sets and increase your value to your company.

Yes, all students who have attended Arrakis training have passed their certification tests.

Arrakis offers training in a variety of formats, including: onsite, online, and at-your-own-pace.  We also offer what we call micro-courses, focusing on very detailed and specific subject areas.

Training duration depends on the type of course and could vary from a few hours to a couple of weeks.

Some of our courses are accredited for CE credit and include test vouchers leading to certification.

Arrakis can teach almost all courses offered by PECB; however, some courses can only be taught "at your own pace," while others can be online or in person.  Arrakis can teach all courses offered by CompTIA.  Accredited PECB courses include two test vouchers that must be used within 12 months of purchase, as well as CE credits for attending.  Other courses taught by Arrakis may or may not be accredited; however, all are valuable to those seeking knowledge.

The short answer is "yes"; however, you must be able to demonstrate mastery of the course you are teaching and hold, or have held, certification in that course.  Our requirements are very strict when it comes to representing the Arrakis logo.


Contact us by filling out this form - Contact Us


General FAQ

Questions not answered earlier!

Numerous!  Arrakis consultants hold a variety of individual certifications, and not all are listed here. Common certifications for Arrakis consultants are CISSP, CISA, CISM, ISO27001 Senior Lead Auditor, CAIP, CAIM, ISO27005 Senior Lead Risk Manager, ISO27032 Senior Lead Cybersecurity Manager, ISO27033 Senior Lead Network Security Manager, ISO27034 Senior Lead Application Security Manager, ISO27035 Senior Lead Incident Manager, ISO42001 Senior Lead Auditor, Certified Data Protection Officer, SOC2 Senior Lead Analyst, CIMSA, CMMC Registered Practitioner, NIST Cybersecurity Consultant, Security+, Pentest+, Linux+, Server+, and CySA+.

Arrakis uses a three-phase methodology:

phase 1 is an assessment - generally 6-8 weeks long
phase 2 is remediation - duration is based on the findings of phase 1
phase 3 is long-term support

Yes, Arrakis is certified as a service-disabled, veteran-owned small business and is registered with the SBA as a small business.

Arrakis offers support in any geographic location that is not under an embargo or listed on the Department of State's banned list as a company, location, or named individual.

Arrakis will hire or contract any qualified individual or company that can meet Arrakis' needs, legally work with or for Arrakis, and meet the unique requirements of Arrakis' clients or client regulatory environments.  Arrakis does not engage in any illegal discrimination; however, it does discriminate in favor of those who can "accomplish the mission" in the best interests of the client and Arrakis.

The certifications required to work with Arrakis vary based on the type of work expected from the employee or consultant. Employees or consultants will only be engaged if they meet the minimum requirements to support the work and the client's needs.  Certifications are also expected to be maintained and not allowed to expire.  Personnel assigned to a project based on a particular certification will be expected to maintain that certification to remain on the project.

Contact Us

SDVOSB Logo
CMMC RPO