Ready for the audit.
Working all year.
Certification readiness, regulatory compliance, assurance and testing, risk and resilience, compliance operations, and compliance leadership — for the audit month and the eleven months after it.
A little more context
The certificate is the entry ticket. Keeping it true is the operation. We do both.
Most compliance work is bought for a date: the audit, the customer questionnaire, the certificate the deal depends on. We get you there — ISO 27001, SOC 2, PCI DSS, ISO 9001, ISO 22301, ISO 42001 and the regulations that apply to you — with a practical, documented approach that fits your business rather than a template.
Then we do the part that decides whether it was worth it. The eleven months between audits — the evidence, the controls, the changes, the new vendor, the person who left — is where a certificate stays true or quietly stops being true. We run that operation, and where you need it we provide the leadership: a virtual CISO, a compliance officer, a data protection officer, on the days you need them.
Open a service to see what it involves and how the work moves.
01Certification Readiness
From where you are today to audit-ready — with a plan, not a template.
Certification Readiness
From where you are today to audit-ready — with a plan, not a template.
Getting certified is a project with a lot of evidence attached. We run it end to end: ISO 27001, SOC 2 (Type I and Type II), ISO 9001, ISO 22301, ISO 42001 for AI management, and PCI DSS — starting with an honest gap assessment, then the policies, procedures and controls written for your business, the evidence collected the way auditors want to see it, internal audit and a mock assessment before the real one, and support through the audit itself.
You come out ready for independent assessment — and, more usefully, with a management system your team understands and can keep running. Certification or attestation is decided by the independent assessor.
- ISO 27001
- SOC 2 — Type I & II
- ISO 9001
- ISO 22301
- ISO 42001
- PCI DSS
- Gap assessmentWhere you stand, honestly
- DesignPolicies, controls, ownership
- ImplementWith your team, in your tools
- Internal auditMock assessment, remediation
- Independent assessmentAudit support, findings, next steps
Fixed fee per standard · Retainer for surveillance and recertification years
02Regulatory Compliance
The regulations that apply to you, understood and met — without stopping the business.
Regulatory Compliance
The regulations that apply to you, understood and met — without stopping the business.
Regulation follows your customers and your data across borders. We help you meet it: HIPAA for healthcare data, GDPR and UK GDPR for European and British customers, CCPA and US state privacy laws, India's DPDP Act, the NIST Cybersecurity Framework, SOX controls support, and EU AI Act readiness for AI systems that touch European users.
We translate each regulation into what it means for your operation — the notices, the records, the controls, the roles — and build it into how you already work. Where a law is new or changing, we tell you what is in force now and what is coming, so you spend on what matters first.
- HIPAA
- GDPR & UK GDPR
- CCPA & US State Privacy
- DPDP Act — India
- NIST CSF
- SOX Controls Support
- EU AI Act Readiness
- ScopeWhich laws, which data, which systems
- AssessGaps against each requirement
- BuildNotices, records, controls, roles
- EmbedInto your processes and training
- MaintainWatch for change, update, evidence
Fixed fee for assessment and implementation · Retainer for ongoing regulatory watch
03Assurance & Testing
Independent eyes on your controls — before the auditor's, and before an attacker's.
Assurance & Testing
Independent eyes on your controls — before the auditor's, and before an attacker's.
You should know whether your controls work before anyone else tests them. We provide readiness assessments and gap analysis, internal audit, audit support and evidence management, vulnerability assessment and scanning, and penetration testing delivered through our specialist partners — with findings written for the people who have to fix them, ranked by real risk, and tracked to closure.
For audit season, we manage the evidence: what each control needs, who owns it, where it lives, and whether it is current — so the audit becomes a review, not a scramble.
- Readiness Assessment
- Gap Analysis
- Internal Audit
- Audit Support & Evidence Management
- Vulnerability Assessment & Scanning
- Penetration Testing — partner delivered
- PlanScope, standard, evidence needed
- TestControls, systems, applications
- FindRanked by real risk
- FixTracked to closure, re-tested
- AssureAudit-ready, with the evidence
Fixed fee per assessment or test · Retainer for continuous internal audit
04Risk & Resilience
Know where your risk actually sits — and be ready when it happens.
Risk & Resilience
Know where your risk actually sits — and be ready when it happens.
Risk registers are easy to write and hard to use. We build ones that work: risk assessments tied to your real assets and processes, third-party and vendor risk management so the partners you rely on are assessed and monitored, business continuity and disaster recovery plans that are tested rather than filed, and incident response planning that tells everyone what to do in the first hour.
The output is not a document. It is a business that knows what it would do — and has practiced.
- Risk Assessment
- Third-Party & Vendor Risk Management
- Business Continuity & Disaster Recovery
- Incident Response Planning
- IdentifyAssets, processes, threats, vendors
- AssessLikelihood, impact, controls
- TreatDecisions, owners, actions
- PlanContinuity, recovery, response
- TestExercises, lessons, updates
Fixed fee for assessments and plans · Retainer for ongoing vendor risk and testing
05Compliance Build & Operations
The eleven months between audits, run properly.
Compliance Build & Operations
The eleven months between audits, run properly.
This is the service most compliance programs are missing. After the certificate, someone has to implement the remaining controls, remediate findings, keep policies and standards current, and monitor compliance continuously — collecting evidence as it is created, tracking changes, onboarding new vendors and systems into the framework, and catching drift before the next audit does.
We run it as an operation, with a calendar, an owner, dashboards you can see, and the same discipline we bring to any other process. It is what makes the certificate true in month eleven.
- Control Implementation
- Remediation
- Policy & Standards Development
- Continuous Compliance Monitoring
- CalendarEvery control, every evidence date
- OperateControls run, evidence collected
- MonitorDrift, exceptions, changes
- RemediateFindings fixed, verified
- ReportCompliance posture, monthly
Managed service per month · Per control or per framework with a monthly minimum
06Compliance Leadership
A CISO, a compliance officer, a data protection officer — on the days you need them.
Compliance Leadership
A CISO, a compliance officer, a data protection officer — on the days you need them.
Many businesses need senior security and compliance leadership long before they can justify a full-time hire. We provide it: a virtual CISO who owns your security strategy and answers to your board, a compliance officer as a service who runs your program and speaks to your regulators and customers, a data protection officer as a service where the law or your customers require one, and AI governance for the systems you are starting to depend on.
Experienced people, a defined number of days a month, a named deputy, and the rest of our team behind them.
- Virtual CISO
- Compliance Officer as a Service
- Data Protection Officer as a Service
- AI Governance
- AppointNamed leader, named deputy
- AssessPosture, program, priorities
- LeadStrategy, decisions, board reporting
- RepresentAuditors, regulators, customers
- Build the benchYour own capability over time
Retainer — days per month · Fixed fee for a defined leadership engagement
Nothing under that name.
Try another word, or tell us what you need.
Where could we take some weight off?
You don’t need to arrive with a brief or a service in mind. Tell us about your work, and what you would like to be different.
We’ll be honest about whether we can help.
