IT Consulting
IT Governance & Compliance
Policy frameworks, control design and audit preparation for ISO 27001, SOC 2, GDPR, PCI DSS and HIPAA.
Controls that survive an audit
Compliance frameworks are not the same as security, but they are how customers, insurers and regulators verify that you take it seriously. Failing an audit is a commercial problem regardless of how good your actual controls are.
We build governance that is proportionate to your business: policies people will follow, controls that are operable day to day, and evidence collection that happens as a by-product of normal work rather than a scramble before an audit.
What is included
- Policy and standard framework development
- ISO 27001 ISMS design and implementation support
- SOC 2 readiness assessment and control mapping
- GDPR data mapping, DPIAs and privacy documentation
- PCI DSS and HIPAA scoping and control implementation
- Internal audit and evidence-collection processes
What you get out of it
- Audits pass without a fire drill
- Controls that operate continuously, not just at audit time
- Faster completion of client security questionnaires
Frequently asked questions
- How long does ISO 27001 certification take?
- For a mid-sized organisation starting from a reasonable baseline, six to twelve months from kickoff to Stage 2 audit is realistic. The ISMS needs to be genuinely operating for a period before an auditor will certify it.
- Can you act as our vCISO?
- Yes. A fractional CISO engagement gives you named senior accountability for security governance without a full-time executive hire.
Ready to move on IT Governance & Compliance?
We will scope it against your actual environment, not a generic package, and give you a fixed price before any work starts.
