Frequently Asked Questions

Answers to the questions we most commonly receive from technology leaders, CIOs, and enterprise IT teams exploring an engagement with Enigma.

About Enigma & Engagements

Enigma primarily serves mid-market and enterprise organizations with annual revenues between $100M and $5B, across industries including financial services, healthcare, manufacturing, professional services, and technology. Our engagements are most valuable for organizations at an IT inflection point — planning a significant cloud migration, responding to a security incident, preparing for regulatory scrutiny, or navigating post-merger technology integration.

We work equally with clients whose internal IT team will execute against our recommendations and clients who need Enigma to provide or supplement execution capacity directly.

Three primary differences: First, our principals personally lead every engagement — you work directly with senior practitioners who have operated in CTO, CISO, and VP Engineering roles, not associates fresh from university. Second, we are vendor-independent. We have no reseller agreements, no preferred technology partners, and no financial incentives to recommend any specific product or platform. Third, our engagements are scoped for decisiveness — we produce actionable recommendations, not multi-volume reports designed to justify further consulting spend.

Engagement timelines vary by scope. A focused technology assessment (e.g., cloud readiness, cybersecurity gap analysis, IT strategy review) typically spans four to eight weeks. A full strategic roadmap development program runs eight to sixteen weeks. Managed advisory retainers operate on a monthly basis with an initial minimum commitment of six months.

Our fee structure is project-based for assessments and roadmap programs, and monthly retainer-based for ongoing advisory relationships. We provide a detailed scope of work and fixed-fee proposal following an initial discovery conversation, so there are no billing surprises.

Both. For clients who need advisory only — analysis, roadmaps, architecture design, vendor selection — Enigma delivers those outputs and your internal team executes. For clients who need execution support, we can provide program management, architecture oversight, and technical leadership for implementation programs. We intentionally avoid the model where advisory and implementation are bundled at scale, as it creates conflicts that compromise advisory quality.

Cloud & Infrastructure

We are entirely cloud-agnostic. Provider selection recommendations are based on an analysis of your existing technology investments, workload characteristics, team skill profile, regulatory constraints, and organizational relationship factors. In practice, most enterprise clients end up with a primary provider and one or two specialized use-case clouds, and we help structure governance for that reality rather than advocating for any single provider's platform.

Our Cloud Readiness Assessment covers five domains: (1) Application portfolio analysis and workload classification by cloud suitability; (2) Current infrastructure architecture review including network topology and data sovereignty considerations; (3) Security and compliance gap analysis against cloud baseline requirements; (4) Organizational readiness assessment covering skills, governance structures, and FinOps capability; and (5) Total cost of ownership modeling comparing current state to target cloud architectures.

Deliverables include an application migration registry, a cloud maturity scorecard, a recommended landing zone architecture, and a phased migration roadmap with business case modeling.

Cybersecurity

Our baseline is the NIST Cybersecurity Framework (CSF) 2.0, supplemented by the CIS Critical Security Controls v8 for practical implementation prioritization. For regulated industries, we layer in applicable requirements: HIPAA Security Rule for healthcare, SOC 2 for service organizations, PCI DSS for payment card environments, NERC CIP for energy, and CMMC for defense contractors. For cloud security specifically, we reference the CSA Cloud Controls Matrix and applicable CIS Benchmarks for each provider.

Yes. Enigma regularly supports clients in preparing for regulatory audits and third-party assessments. Our compliance advisory services include gap assessments against applicable frameworks, remediation program management, evidence collection process design, and audit preparation support. We do not serve as an independent auditor or certifying body — we work on the client side to prepare organizations for assessment by their designated auditor or certifying body.

Managed Services

Managed services clients receive a documented Incident Response Plan (IRP) tailored to their environment at the start of engagement. Our 24/7 NOC performs continuous monitoring and handles initial triage for security events classified as Severity 3 or lower. For Severity 1 and 2 incidents, our on-call security team is engaged immediately, and clients are notified per their defined escalation matrix. We coordinate with client legal, HR, and PR teams as required under your IRP and can engage third-party forensic investigators when warranted.

Yes. Co-managed IT is one of our most common delivery models. Your internal IT team retains ownership of strategic architecture, vendor relationships, and high-complexity problem solving, while Enigma supplements capacity in areas where coverage gaps exist — typically 24/7 monitoring, after-hours helpdesk, specialized security disciplines, or project execution capacity. We integrate into your existing ITSM tooling (ServiceNow, Jira Service Management, etc.) to maintain process continuity.