Five stages to secure, enterprise-grade AI, at speed.

bcx FORGE is how bostoncyberx moves a client from "we are not sure we are ready" to proven, secured, scaled AI capability, measured in weeks, not fiscal years. Every stage ends in an evidence gate and a decision the executive team can defend with numbers. Clients can enter at any stage and exit at any gate.

From first conversation to secured production in a single quarter

Speed is the promise, so it is stated as commitments rather than aspiration. The sequence below is the standard path. A client with a current strategy commonly skips Foundations and Objectives and starts at Rapid Pilots.

F

Foundations

Readiness baselined, shadow AI surfaced.
O

Objectives

R

Rapid Pilots

G

Growth

Production and adoption at scale.
E

Enterprise-Grade

Certification and assurance retainer.

Standard path: idea to secured production in one quarter. Entry at any stage. Exit at any gate. No stage is a prerequisite for purchase, only for sequence.

What makes FORGE different from a program plan

These five principles are the method, and they are what large integrators structurally cannot offer: their commercial model rewards duration, ours rewards evidence. Each principle shows up as a named artifact inside every stage, so the client can audit whether we are living it.

Speed as a commitment

Every stage has a stated duration and a first-evidence date written into the engagement. Weeks, not fiscal years, because a decision that takes a year is made in a market that no longer exists.

Prototype over proposal

The deliverable that changes minds is working software on the client's own data. We build the thing rather than describing the thing, and we demo every week.

Measured value or none

Each use case carries a value hypothesis with a baseline, a metric, a measurement method and a named business owner before a line of code is written.

Adapt at the gate

Four legitimate outcomes at every gate: advance, iterate, pivot, stop. Stopping early and cheaply is a result we charge for, not a failure we hide.

Secured by construction

Threat modeling, guardrails and adversarial testing happen inside the build, not in a review afterwards. Nothing we ship stalls in security review, because security was in the room.

The five stages

Positioning, activities, deliverables, value and gate

Each stage is written to stand alone as a sellable offering and to compose into the full journey. The security thread in each stage is deliberate: security is engineered from Foundations forward, not appended at Enterprise-Grade.

Stage 01

Foundations

"Are we ready?"

A fast, evidence-based read on whether the organization can absorb AI at all. Maturity across six dimensions, the AI already running whether anyone approved it or not, and the specific gaps that will stop the first pilot. Foundations is deliberately short and cheap: it exists to make the next decision well, not to produce a study. Most clients discover two things they did not know: how much unsanctioned AI is already touching their data, and which single gap is actually blocking them.

Velocity

1 to 2 weeks elapsed. Structured interviews and tooling discovery in week one, findings read-out in week two.

First evidence

Shadow AI inventory back to the client within 5 business days, usually the first moment the room goes quiet.

Engagement intensity

Light touch on the client: 6 to 10 interviews, read-only discovery, no project team required.

What happens

  • AI readiness assessment across strategy, value discipline, data and technology, people and culture, process and operating model, and AI governance, risk and security
  • Shadow and embedded AI discovery: unsanctioned tools, browser extensions, vendor AI features switched on by default, and the data flowing through them
  • Inventory of AI initiatives already in flight, their spend to date and what each was supposed to return
  • Data and integration reality check on the systems the first use cases would need to touch
  • Leadership AI literacy baseline: where the executive team's fluency actually sits, tested rather than assumed
  • Gap analysis identifying the specific blockers between today and a first production use case

Deliverables

  • AI Maturity Index, scored across six weighted dimensions, on a five-level scale, with the observable evidence for each placement
  • Shadow AI exposure report with data-flow mapping and immediate remediation list
  • AI initiative inventory: spend committed, value claimed, value evidenced
  • Readiness gap register, prioritized by what blocks the first pilot versus what can wait
  • Target maturity state by stage, so progress has a definition
  • Executive read-out deck and a one-page board summary

Business value received

  • An honest starting position, produced in two weeks instead of a two-month assessment engagement
  • Exposure already sitting in the environment is found before it becomes an incident or an audit finding
  • Spend on initiatives that were never going to return anything can be stopped immediately
  • The organization stops arguing about where it stands and starts deciding what to do

Gate and decision

Gate: proceed to Objectives, or remediate first. A client at maturity Level 1 with unmanaged data exposure gets a short remediation sprint before strategy work, because a roadmap built on unreachable data and ungoverned tooling is fiction. Advance when the blocking gaps are known and owned.

Security thread

Shadow AI discovery and data-flow mapping are security work delivered as business insight. This is where the bostoncyberx wedge lands first. No generalist AI consultancy opens with an exposure finding, and no client forgets the meeting where they saw one.

Stage 02

Objectives

"What are we solving for?"

A facilitated workshop that converts ambition into a funded, sequenced plan: objectives the leadership team actually agrees on, use cases scored on value and risk, an ROI model that survives contact with the CFO, and a roadmap with named owners. The output is not a strategy document; it is a set of decisions with money and people attached. Speed matters as much here as anywhere: the roadmap lands five business days after the room breaks up, while the alignment is still warm.

Velocity

1 to 2 day facilitated workshop. Roadmap, ROI model and charter delivered within 5 business days of the session.

First evidence

Prioritized use case shortlist and the first pilot candidate agreed before anyone leaves the room.

Engagement intensity

High intensity, short duration: executives, IT, risk and business owners in the same room for one to two days.

What happens

  • Executive AI literacy and value-pool discovery. Leaders learn by making live decisions about their own business, not by sitting through curriculum
  • Objective setting: what the business is trying to achieve, and which of those objectives AI can credibly move
  • Use case generation and scoring against value, feasibility, data availability, time-to-evidence and risk
  • Value hypothesis authoring for the top candidates: baseline, target metric, measurement method, accountable owner
  • Model, tool and platform selection, and definition of the AI operating layer: architecture, data access, guardrails and the roles that run it
  • Financial and ROI modelling, staged funding design, and roadmap sequencing with stage gates

Deliverables

  • AI strategy and governance charter: objectives, decision rights, funding gates, operating model
  • Scored and prioritized use case portfolio with value hypotheses and named business owners
  • ROI and investment model, staged so funding is released against evidence rather than committed up front
  • AI operating layer design: reference architecture, tooling standards, guardrails and control requirements
  • Sequenced roadmap across people, process and technology, with the first pilot scoped and ready to start
  • Stakeholder alignment record: what was agreed, by whom, and what each owner committed to

Business value received

  • One agreed set of priorities replaces competing departmental AI agendas
  • A board-fundable plan with real numbers, produced in days rather than a quarter-long strategy study
  • Leadership can defend the AI investment case in their own words, because they built it
  • The first pilot starts the following week instead of entering a planning cycle

Gate and decision

Gate: commit the first pilot, or re-scope. Advance when at least one use case has a signed value hypothesis, a named business owner, available data and a funded 2 to 6 week pilot window. Objectives that cannot produce one such use case is a signal to revisit the objectives, not to start building.

Security thread

Use cases are scored on risk alongside value, and each carries its control requirements from the moment it is prioritized. Nothing enters the roadmap that cannot be governed, which is what stops the familiar collision between an approved pilot and an unimpressed CISO six weeks later.

Stage 03

Rapid Pilots

"Can we prove it fast?"

Where FORGE earns its name. A small joint bcx and client pod builds a working prototype against real systems and real data, puts it in front of real users, and measures it against the value hypothesis, in two to six weeks. The client sees working software every week, not status reports. The pilot is instrumented for value, adoption, quality and risk simultaneously, and it is adversarially tested before real users touch it, so the evidence pack that reaches the gate answers the value question and the security question at once.

Velocity

2 to 6 weeks per pilot. Weekly demo of working software. First measured result within 30 days of pilot start.

First evidence

A working prototype on real client data inside the first two weeks. A demo, not a mockup.

Engagement intensity

Embedded pod. Client engineers, analysts and process owners are staffed into the build, not briefed on it.

What happens

  • Pilot charter: scope held deliberately small, success defined in advance, measurement instrumented on day one
  • Rapid prototyping against actual client systems and data in a controlled, monitored environment
  • Weekly build-demo-adapt cycles with the business owner in the room and empowered to change direction
  • Live pilot with a real user cohort, instrumented for impact, adoption, output quality and risk
  • AI red team and adversarial testing: prompt injection, data leakage, model and agent abuse, output integrity
  • Value measurement against the baseline, and an evidence pack with a recommended gate decision

Deliverables

  • Working prototype running on real client systems and data, not a sandbox demo
  • Instrumentation and measurement harness the client keeps and reuses on the next use case
  • Value measurement report: measured result against baseline, with confidence and caveats stated plainly
  • Adversarial test findings and the guardrail set built alongside the prototype
  • Iteration and decision log: what was tried, what worked, what was deliberately abandoned and why
  • Evidence pack and gate recommendation with security sign-off already attached
  • Scale-readiness assessment for anything that clears the gate

Business value received

  • Value is proven or disproven in weeks, against the client's own data, before major commitment
  • Weak ideas die cheaply instead of consuming a year of budget and a reputation
  • Client teams build real capability by co-creating, so the second pilot is faster than the first
  • Working software replaces vendor assertion as the basis for the scaling decision
  • Nothing stalls in security review, because security testing happened inside the build

Gate and decision

Gate: advance, iterate, pivot or stop. Advance to Growth when the measured result clears the hypothesis and the control set holds. Iterate when the signal is real but the approach is wrong. Pivot back to Objectives when the value hypothesis itself was wrong. Stop, and release the funding to the next candidate, when the measurement says so. The stop rate is tracked and reported deliberately, as evidence the method has teeth.

Security thread

Adversarial testing is part of the pilot, not a subsequent phase. The prototype arrives at the gate with its AI-specific failure modes already probed by bostoncyberx rather than discovered later by an attacker, an auditor or a customer.

Stage 04

Growth

"How do we scale it?"

Taking one proven pilot and turning it into capability the business runs at scale: more users, more workflows, real integration into core systems, and the change work that determines whether anyone actually uses it. Growth is where most organizations lose their AI investment: the pilot worked, the rollout did not. The scarce resource here is adoption, not technology, so the plan is weighted accordingly across people, process and technology, and realized value continues to be measured rather than assumed.

Velocity

1 to 2 quarters, run in fortnightly increments with value re-measured at every increment rather than at the end.

First evidence

Production deployment to the first expanded user group within 30 days of the gate decision.

Engagement intensity

Ramping bcx pod alongside a named client owner, with capability transfer milestones as an explicit deliverable.

What happens

  • Production engineering and integration into the systems that actually run the business
  • Scale roadmap across people, process and technology, sequenced by adoption capacity rather than technical readiness
  • Training, enablement and change program built for the specific roles whose work is changing
  • Deployment to expanded user groups in waves, each wave measured before the next is released
  • Workflow redesign: the difference between AI that assists the old process and AI that changes it
  • Realized value tracking against the original hypothesis, with variance investigated rather than explained away
  • Capability transfer: client engineers and owners taking operational ownership on a defined schedule

Deliverables

  • Production-deployed capability, integrated and monitored
  • Scale roadmap covering people, process and technology with wave-by-wave sequencing
  • Training and adoption plan with role-based enablement assets the client owns
  • Integration architecture and deployment documentation
  • Adoption and realized value dashboard, reported on a set cadence
  • Named operational owners, run model and support path
  • Capability transfer scorecard against agreed competency milestones

Business value received

  • Proven prototypes become dependable business capability instead of stranded pilots
  • Adoption is engineered rather than hoped for, so the measured pilot benefit actually materializes at scale
  • Benefits are tracked into the operating numbers, so the AI investment defends itself at budget time
  • The client's own team can run and extend the capability, reducing dependency on us by design
  • Scaling capacity is directed at the highest-return opportunity in the portfolio, not the loudest one

Gate and decision

Gate: harden and hand over, or hold. Advance to Enterprise-Grade when the capability is in production, adoption is measured and trending to target, and realized value is tracking to the hypothesis. Hold, and fix adoption, when usage is below plan. Scaling a capability nobody uses only makes the write-off larger.

Security thread

Controls designed during the pilot are implemented at production scale: identity and access for agents and services, data protection across the integrated path, and monitoring that grows with the user base. The control surface expands with the attack surface rather than behind it.

Stage 05

Enterprise-Grade

"Is it safe long-term?"

The stage that makes AI durable rather than merely live. Hardening and certification against a defined standard, governance that operates on a cadence, continuous monitoring for the ways AI systems degrade (drift, misuse, data exposure, runaway cost, quality decay), and audit evidence that holds up in front of a regulator or an enterprise customer's due diligence team. This is where bostoncyberx's core discipline becomes an ongoing service rather than a project, and where the client stops carrying AI risk alone.

Velocity

Certification in 4 to 6 weeks, then continuous. Governance on a monthly cadence, posture reporting quarterly.

First evidence

Hardening certification and the first assurance report, giving the CISO and the board something signed to point at.

Engagement intensity

Retained service. Lean continuous monitoring and governance support, scaling with the size of the AI estate.

What happens

  • Security hardening against a defined AI control standard, with the gaps closed rather than logged
  • Hardening certification and attestation the client can present to auditors, regulators and their own customers
  • AI governance operation: model and agent registry, approval and audit trails, policy enforcement, review forums
  • Continuous monitoring for drift, misuse, data exposure, cost, quality and adoption decay
  • AI incident response playbooks integrated into existing security operations, and exercised rather than filed
  • Compliance mapping and audit evidence packs for the regimes that apply to the client
  • Portfolio feedback: operating cost, risk and realized value returned to Objectives to shape the next cycle

Deliverables

  • Hardening certification and attestation pack
  • Operating AI governance framework: registry, policy enforcement, decision records, review cadence
  • Continuous AI risk and performance monitoring with defined alerting and escalation
  • AI incident response playbooks, integrated and exercised with the security operations function
  • Compliance mapping and audit evidence packs, maintained rather than reconstructed under pressure
  • Quarterly AI posture and realized value report for the executive team and the board
  • Governance retainer with defined service levels and escalation paths

Business value received

  • AI scales without the attack surface outrunning the control surface
  • Audit, regulatory and enterprise customer due diligence questions have documented, current answers
  • The value already proven is protected rather than quietly eroded by drift, misuse or cost creep
  • Executive and board confidence to keep investing, because risk is visibly under management
  • Operating evidence continuously sharpens the next cycle's priorities and ROI assumptions

Gate and decision

Gate: continuous assurance, and re-enter the loop. There is no exit. The estate is under management, and every operating quarter feeds cost, risk and realized value back into Objectives. The next cycle starts with the client's own evidence rather than a vendor's benchmark, which is why cycle two is faster and cheaper than cycle one.

Security thread

Here security is the offering rather than a thread through it. Continuous assurance for the AI estate, delivered by a firm whose original discipline is cyber defense. It is also the strongest recurring commercial relationship in the framework.

The loop

FORGE is a cycle, not a staircase

Adaptation is the point. A stage gate has four legitimate outcomes, and three of them are not "proceed." Rapid Pilots can send a use case back to Objectives because the value hypothesis was wrong, forward to Growth because the evidence is strong, around again because the approach needs another iteration, or to a clean stop because the measured result does not justify the spend. Naming stop as a success makes the other three credible.

Evidence flows backwards as well as forwards. What Growth learns about adoption and what Enterprise-Grade learns in operation refreshes the Objectives portfolio: priorities, ROI assumptions, sequencing and the next hypothesis. By the second cycle the client is choosing use cases with real operating data from their own environment rather than vendor benchmarks, which is why cycle two is consistently faster and cheaper than cycle one.

Multiple use cases occupy different stages at once. Mature clients run a portfolio: two pilots in Rapid Pilots, one capability in Growth, three in Enterprise-Grade operation. FORGE governs the portfolio, not a single project.

Gate routes

  • Advance: go to the next stage
  • Iterate: stay in the same stage with a revised approach
  • Pivot: go back to Objectives
  • Stop: funding is released to the next candidate

Feedback loops

  • Growth returns adoption reality to Objectives
  • Enterprise-Grade returns operating cost, risk and realized value to Objectives
  • Every stage re-baselines Foundations

See where FORGE starts for you.

Take the free AI Assessment for a scored baseline, or talk through your first stage with a senior practitioner.

Book a Discovery Call Take the free AI Assessment