Compliance Consulting (SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS)
Readiness, controls and evidence for the frameworks your customers ask about — without stalling delivery.
Read moreAn independent view of your security position, expressed as risk the board can weigh rather than findings it cannot.
Boards and executives do not need a control matrix; they need to know which risks are unacceptable, what it would cost to reduce them, and which ones the organisation is consciously choosing to carry.
We audit technical controls, process and governance together, then express the result in business terms — likelihood, impact, current controls and the cost of improvement — so the decisions can be made by the people accountable for them.
An outside review that is not invested in defending decisions made previously.
Findings translated into likelihood and consequence rather than left as technical control gaps.
Remediation sequenced across quarters with effort and cost attached to each item.
Documentation you can put in front of insurers, customers and your own board.
Systems, processes and the framework being assessed against are agreed with the sponsor.
Technical review, documentation review and interviews with the people who operate the controls daily.
Each risk rated on likelihood and impact, accounting for controls that genuinely work as intended.
A board-ready summary and a technical appendix, with a remediation roadmap and clear ownership.
No. We prepare organisations for certification and identify gaps, but formal ISO 27001 or SOC 2 certification must be issued by an accredited body.
Typically three to five weeks depending on scope and how quickly interviews can be arranged.
Yes. Where full independence is required for a certification path, we will tell you plainly which work we should not perform ourselves.
Readiness, controls and evidence for the frameworks your customers ask about — without stalling delivery.
Read morePosture review and hardening across AWS, Azure and GCP, ending in a prioritised remediation plan.
Read moreA response plan your team has rehearsed, including who decides, who speaks, and who to notify.
Read moreWe will tell you what we would do, roughly what it costs, and whether it is worth doing yet.