Credibility, methodology, and practical execution in one place.

The Team & Approach page strengthens trust quickly. It lets prospective clients see who will perform the work, why the team is qualified, and how Digital Assurance Group turns assessment activity into business-ready results.

The team

120+ combined years of assessment and operational security experience.

Our team has performed global cybersecurity, AI governance, third-party risk, privacy, and compliance assessments while also operating security, risk, privacy, and governance programs across complex enterprise and regulated environments.

Profile image for Anthony Bisulca. Click to view professional bio.

Anthony Bisulca

Vice President Cybersecurity Assessment

Cybersecurity leader with deep experience building and leading global assessment, third-party risk, vendor risk, compliance, M&A security, and operational security programs across Fortune 500 and high-growth environments.

View professional bio
Profile image for David Doyle. Click to view professional bio.

David Doyle

Director Governance, Privacy & Executive Risk Advisor

Founder and CEO of Malama Advisory with 30+ years in cybersecurity, privacy, risk management, compliance, executive advisory, global assessments, and governance leadership across major technology and enterprise environments.

View professional bio
Profile image for Tom Brown. Click to view professional bio.

Tom Brown

Director International Cyber Risk & Critical Infrastructure

UK-based information security and cyber risk specialist with 30+ years across government, international programs, critical national infrastructure, finance, energy, aviation, high technology, privacy engineering, and global supply chain security.

View professional bio
Profile image for Matt Smith. Click to view professional bio.

Matt Smith

Director Technical Controls & Cybersecurity Assessment

Cybersecurity and information security professional with 30+ years of enterprise risk and global assessment experience across M&A, third-party risk, vulnerability assessment, and major security frameworks.

View professional bio
Profile image for Adam Hopkins. Click to view professional bio.

Adam Hopkins

Director AI Governance, Security Architecture & Compliance Automation

Cybersecurity and AI governance leader with 20+ years of experience across AI risk management, control framework development, M&A security due diligence, third-party risk, audit readiness, compliance automation, and enterprise security operations.

View professional bio
Cybersecurity control grid

Operating credibility

We assess controls through the lens of people who have owned the outcome.

Our assessments are not checklist exercises. We evaluate governance, evidence, implementation, ownership, monitoring, AI lifecycle controls, and remediation from the perspective of people who have built programs, led teams, defended production environments, managed audits, automated compliance workflows, and reported risk to executives.

Our methodology

Evidence-based assessments with practical outcomes.

We focus on what can be proven, what matters to the business, and what leaders can act on.

Scope and risk alignment

Define objectives, business context, systems, third parties, data sensitivity, frameworks, and stakeholders before assessment work begins.

Evidence and control review

Review policies, standards, artifacts, architecture, workflows, system evidence, ticketing data, control ownership, and operating records.

Stakeholder interviews and validation

Meet with control owners and operational teams to validate how controls are designed, implemented, monitored, and improved.

Risk analysis and prioritization

Identify gaps, assess impact and likelihood, distinguish design issues from operating issues, and prioritize remediation around business risk.

Executive reporting

Deliver clear reporting that includes strengths, gaps, risk themes, control effectiveness, remediation recommendations, and leadership-level decisions.

Remediation validation

Support follow-up validation so remediation progress can be measured, evidenced, and communicated with confidence.

Independent

We provide a clear view of risk and control effectiveness without unnecessary complexity or vendor-driven bias.

Practical

We recommend actions that can be implemented in real environments with real operational constraints.

Executive-ready

We communicate findings in a way that supports board, audit committee, procurement, legal, security, and technology decisions.

Let’s talk about the assessment you need to perform.

For scoping, availability, or general questions, contact Digital Assurance Group at the email below.