Secure · Cyber & Networks
Governance, risk & compliance
Gap assessments, risk registers, policies and audit readiness against ISO 27001, SOC 2, PCI DSS and NIST CSF, built to be used rather than filed.
The challenge
Compliance programmes often produce documents that describe an organisation that does not exist. Policies are copied from templates, risk registers are updated once a year, and evidence is assembled in a rush before the auditor arrives.
That approach passes some audits but leaves real risk unmanaged, and it fails the moment a regulator or customer asks for proof that controls actually operate.
We build governance that reflects how you really work: risks that are owned and reviewed, controls that are evidenced as they run, and policies your staff can follow.
Our method
How the work is done.
- 01
Scope and context
We agree the scope, the frameworks that apply and the business services in question, and interview the people who own them.
- 02
Gap assessment
Current controls are assessed against the chosen framework, with each gap rated for risk and effort.
- 03
Risk assessment
We build or refresh a risk register with owners, treatment decisions and review dates.
- 04
Remediation support
We write policies and procedures, help implement controls, and set up evidence collection that runs continuously.
- 05
Audit readiness
A pre-audit review tests evidence against the auditor's likely sampling, and we support you through the audit itself.
Deliverables
What you receive.
- Gap assessment report against the chosen framework
- Risk register with owners and treatment plans
- Statement of Applicability for ISO 27001
- Policy and procedure set tailored to your organisation
- Control evidence map and collection schedule
- Pre-audit readiness report
- Board-level risk summary
Engagement options
Ways to buy it.
- 013 to 6 weeks
Gap assessment
A point-in-time view of compliance against one or more frameworks.
- 024 to 12 months
Certification programme
End-to-end support from gap assessment to audit.
- 03Rolling, reviewed annually
Ongoing compliance support
Regular risk reviews, internal audits and evidence checks.
Standards
Frameworks we work to.
- ISO 27001
- ISO 27002
- SOC 2
- PCI DSS
- NIST CSF
- CIS Controls
Questions
What buyers ask us.
Do you perform the certification audit?
No. Independence matters: we prepare you for the audit, and the certification or attestation is performed by an independent body.
Can one programme cover several frameworks?
Yes. We map controls once across frameworks so a single piece of evidence supports several requirements.
How much of our team's time will this take?
Control owners are needed for interviews and evidence. We do the drafting and coordination so their time is spent on decisions, not documents.
Will you use templates?
We start from proven structures but tailor every policy to how your organisation actually operates.
Related services
Often delivered together.
Secure
Virtual CISO
Senior security leadership on a part-time basis: strategy, risk ownership, board reporting and programme direction without a full-time hire.
Secure
Penetration testing
Controlled, evidence-led attacks on your applications, networks and cloud estate, reported in terms your engineers and your board can both act on.
Train
Executive cyber briefings
Focused sessions and tabletop exercises that equip boards and leadership teams to govern cyber risk and lead through an incident.
Discuss governance, risk & compliance.
A senior engineer reviews every enquiry and replies within one business day.