The ETEMAS Methodology

A business-driven method for making technology decisions.

We do not start with products or predetermined solutions. We begin by understanding the organization’s objectives, current capabilities, and areas of risk, then build a traceable path from business priorities to technology decisions.

1

Executive Technology Alignment Review (ETAR)

Question: Where does the organization stand today?

Every engagement begins with the Executive Technology Alignment Review (ETAR). This executive-level assessment evaluates technology, cybersecurity, and AI readiness to establish a common understanding of the organization's current state before strategic recommendations are made.

2

Executive Discovery

Question: Where is the business trying to go?

Leadership interviews, strategic initiatives, operating constraints, trigger events, competitive pressures, and success criteria.

3

Business Capability Mapping

Question: What must the organization be able to do?

We define the capabilities required to support growth, service delivery, acquisitions, workforce change, customer experience, compliance, and resilience.

4

Technology Enablement Review

Question: Does current technology enable those capabilities?

Applications, infrastructure, cloud, identity, cybersecurity, data, AI, automation, vendors, integrations, governance, and talent.

5

Risk & Opportunity Analysis

Question: What threatens the plan—and what could accelerate it?

We consider cyber risk, operational resilience, technical debt, vendor concentration, skills, compliance, data, and emerging technology opportunities.

6

Executive Prioritization

Question: What should leadership do first?

Recommendations are compared by business impact, strategic alignment, risk reduction, cost and effort, urgency, and time to value.

7

Executive Technology Roadmap

Question: What is the practical sequence?

The roadmap separates immediate action, foundational work, growth investments, longer-term initiatives, items to monitor, and initiatives to avoid or defer.

Every score should tell a story. Every recommendation explains why it matters, why now, what could happen if the organization waits, and what success looks like.
Framework-Informed. Business-Driven.

Recognized frameworks help inform our assessment methodology.

ETEMAS combines business context with recognized technology, cybersecurity, governance, and AI risk management practices. Frameworks are used to help structure assessment logic, contextualize risk, and identify areas that may warrant deeper consultant-led analysis.

NIST Cybersecurity Framework 2.0

Used to inform cybersecurity governance, risk identification, protection, detection, response, and recovery considerations.

NIST AI Risk Management Framework

Used to inform AI governance, risk identification, measurement, responsible adoption, and ongoing management.

COBIT & ITIL Practices

Governance and service management concepts help inform technology alignment, operational maturity, accountability, and technology decision-making.

HIPAA Security Rule

Healthcare-specific assessments may incorporate applicable HIPAA Security Rule considerations to identify areas requiring deeper security and compliance analysis.

CMMC & NIST SP 800-171

Defense-sector assessments may incorporate applicable CMMC requirements and NIST SP 800-171 security requirements when evaluating organizations and systems that process, store, or transmit Controlled Unclassified Information (CUI).

ISO/IEC 27001

Information security management principles may be used to inform governance, risk management, policy, control, and continuous-improvement considerations.

ETAR is not a certification, compliance audit, or substitute for a formal regulatory assessment. Frameworks and recognized practices are used to inform assessment logic, contextualize risk, and identify areas that may warrant deeper consultant-led analysis.