Executive advisory services for founder-led and growth-stage businesses

Protect What You’ve Built

Fractional Chief Risk Officer and Chief Information Security Officer leadership that identifies risks between traditional advisory lanes, sets clear priorities, and helps founders make better-informed decisions.

28 yearsCybersecurity and mission-critical risk experience
Executive-levelCRO and CISO leadership for founder-led companies
One clear viewRisks identified across traditional advisory lanes

Veteran-Owned Business · U.S. Air Force Veteran-Led

Two distinct practices · One trusted advisory firm

Choose the executive leadership your business needs now.

01

Sanctuary Risk Solutions

Executive and founder-risk leadership

A Fractional Chief Risk Officer (CRO) practice for founders who need a clear, coordinated view of the business risks that can disrupt what they have built.

Explore Risk Solutions

02

Sanctuary Cyber Solutions

Cybersecurity governance and security leadership

A Fractional Chief Information Security Officer (CISO) practice for leaders who need accountable cybersecurity direction, vendor oversight, and an executive-level security program.

Explore Cyber Solutions

The Sanctuary approach

The biggest risks are often the ones no advisor owns.

Attorneys, accountants, insurers, IT providers, and managers may each understand one part of the business. Too often, no one owns the complete executive risk picture.

Sanctuary identifies the risks that sit between traditional advisory lanes, then turns them into clear priorities, accountable ownership, and better-informed decisions. Risk Solutions leads enterprise and founder risk; Cyber Solutions leads cybersecurity governance. Each practice remains distinct, with its own methodology, scope, and professional boundaries.

When Sanctuary fits

Recognize the moment before the risk becomes the event.

Sanctuary is most useful when growth, dependence, or outside scrutiny has made informal risk management insufficient.

01

The company has grown faster than its management structure.

02

Too much of the business still depends on the founder personally.

03

Several advisors cover individual issues, but no one sees the complete risk picture.

04

Customers, insurers, lenders, or investors are asking harder cybersecurity questions.

05

An MSP manages technology, but no executive owns cybersecurity decisions.

06

A major change, acquisition, new customer, or disruption has raised the stakes.

What you receive

Decision-ready work—not a report that sits on a shelf.

Every engagement is built to make the risk picture usable. The exact artifacts depend on the selected practice and scope, but the outcome is consistent: leaders can see what matters, what comes next, and who should own it.

01

Executive risk summary

A concise view of the exposures that require leadership attention—not an unfiltered list of concerns.

02

Prioritized findings

Material findings organized by severity, readiness, and the decisions that should come first.

03

90-Day Risk-Reduction Plan

Practical actions, accountable owners, and a focused sequence for reducing the most important exposure.

04

Executive readout

A private findings presentation that explains what matters, why it matters, and what to do next.

Cyber Solutions engagements also include a six-month cybersecurity roadmap aligned to the organization’s priorities and governance needs.

A clear engagement path

Assess. Build. Lead.

Both practices follow the same disciplined progression, with distinct methods and deliverables.

Risk SolutionsFractional CRO
01 · Assess

Founder Risk & Exposure Assessment™

Establish the executive risk picture and immediate priorities.

02 · Build

Protective Intelligence Buildout™

Turn findings into ownership, decision structure, and an operating plan.

03 · Lead

Sanctuary Executive™

Maintain priorities and support consequential decisions.

Cyber SolutionsFractional CISO
01 · Assess

Cybersecurity Governance Baseline

Establish current state, obligations, dependencies, and risk priorities.

02 · Build

Cybersecurity Program Buildout

Stand up governance, reporting, evidence, and provider accountability.

03 · Lead

Fractional CISO Leadership

Guide decisions, vendors, exceptions, and the six-month roadmap.

When the risks connect

One coordinated executive relationship—without blurring the disciplines.

Cyber events create operational, legal, financial, reputational, insurance, and founder-level consequences at the same time. Sanctuary coordinates enterprise-risk and cybersecurity leadership around one executive decision process, connected priorities, and clear ownership.

The result is less duplication and better synthesis—while each practice retains its own discovery, scope, artifacts, and accountability.

Discuss an integrated executive engagement
Joe DeAngelo, Founder of Sanctuary Principal AdvisoryJoe DeAngelo

Founder & Principal

Experienced judgment for consequential decisions.

Joe DeAngelo is the founder of Sanctuary Principal Advisory. He brings 28 years of cybersecurity and infrastructure-risk experience across defense, federal, enterprise, and mission-critical environments, including United States Air Force service, special-operations support, and enterprise security architecture.

Through Sanctuary, he helps founders organize material business exposures, establish priorities and ownership, and maintain a practical executive-risk structure.

U.S. Air Force veteranDoD & federal missionsSpecial-operations supportEnterprise security architecture

Joe DeAngeloFounder, Sanctuary Principal Advisory
Chief Risk Officer Chief Information Security Officer

Founder perspectives

Clarity that changes how leaders see the business.

Three founders on what became visible—and actionable—through Sanctuary’s assessment process.

Building FFE Operations, I was focused on finding clients, delivering great service, and growing the business.

Sanctuary’s Founder Risk & Exposure Assessment helped me see risks I hadn’t considered—from client data and account security to business continuity and founder dependency.

The assessment didn’t just identify vulnerabilities. It gave me clear priorities, practical solutions, and helped me build stronger systems before problems became expensive.

I walked away with a stronger foundation, more confidence in the business, and a clearer path to building a company clients can trust and depend on.

ValeriaFounder, FFE Operations

Sanctuary made me look at my business differently. The assessment surfaced risks I had unknowingly accepted as normal and showed me how my own exposure and decisions could directly affect the company.

What stood out was the prioritization. I didn’t leave with a long list of things to worry about—I left knowing what actually mattered, what could wait, and what I could start improving immediately.

The value wasn’t simply finding vulnerabilities. It was helping me build a stronger, more resilient company around them. Every founder has blind spots. Sanctuary helped me see mine before they had the opportunity to become business problems.

CalebFounder, Sonneman Realty

I expected the assessment to focus primarily on cybersecurity. Instead, Sanctuary showed me how risks across my personal exposure, operations, digital footprint, and business continuity were connected in ways I hadn’t considered.

The process uncovered blind spots, but more importantly, it turned those findings into clear priorities and practical actions I could actually take.

That’s where I saw the real value. Sanctuary didn’t just show me where something could go wrong—it helped me understand what was worth fixing now to make the business stronger going forward. I came away with greater confidence in the company and a much clearer picture of what protecting what I’ve built actually requires.

ErikFounder, Southriver Visuals
Sanctuary Principal AdvisoryProtect What You’ve Built™

Common questions

Know what Sanctuary is—and what it is not.

Does Sanctuary replace our attorney, CPA, insurance broker, or IT provider?

No. Sanctuary connects the executive risk picture, clarifies ownership, and coordinates the right advisors and providers. Each specialist retains responsibility for work within their professional lane.

Is Cyber Solutions an MSP or cybersecurity contractor?

No. Sanctuary provides executive cybersecurity governance and Fractional CISO leadership. Your MSP, MSSP, and technical specialists implement and operate technology; Sanctuary helps leadership set direction, evaluate evidence, and hold providers accountable.

Do we need both Risk Solutions and Cyber Solutions?

Not necessarily. Each practice can stand alone. When enterprise and cybersecurity risks are tightly connected, Sanctuary can coordinate both practices through one executive relationship while preserving their distinct scope and methods.

What size company is the best fit?

Sanctuary is designed for founder-led and growth-stage operating companies, typically beginning around $3 million in annual revenue, where complexity and consequences have outgrown informal risk management.

What information is required for an assessment?

The process begins with interviews and a structured questionnaire. Relevant documents may be reviewed when they help establish context, but Sanctuary does not require access to passwords, production systems, or unrelated confidential information.

Can Sanctuary work with our existing advisors and vendors?

Yes. The model is designed to improve coordination across existing attorneys, accountants, insurers, IT providers, security vendors, and other specialists—not replace relationships that are working well.

What happens next

A confidential conversation—not an immediate commitment.

  1. 01
    Share what prompted the conversation.

    Provide a high-level outline of what changed, what is at stake, or where the risk feels unclear.

  2. 02
    Determine the right starting point.

    We identify the appropriate practice and whether an assessment or another scoped engagement fits.

  3. 03
    Confirm scope and expectations.

    Before work begins, you receive a clear description of the process, boundaries, and deliverables.

  4. 04
    Begin discovery.

    The engagement starts with structured conversation and only the information relevant to the agreed scope.

Private consultation

Begin with a confidential conversation.