GRC
Governance, risk and compliance
Compliance work fails in a predictable way. A consultant writes forty policies, everyone signs them, nobody opens them again, and eighteen months later an auditor asks for proof that the quarterly access review actually happened. Certification is not a document exercise. It is evidence that a control operated over a period of time, and that evidence has to be produced as you go — it cannot be assembled the week before an assessment.
What is included.
For organizations facing a certification deadline, an enterprise client's security questionnaire, or a regulator asking for a risk register nobody has updated in two years.
- Framework selection and gap assessmentISO/IEC 27001, SOC 2, PCI DSS and NIST CSF mapped against what you already do, so a single control set reports to several frameworks instead of running three parallel programs.
- Risk managementAn asset-based risk register with named owners, scored likelihood and impact, documented treatment decisions and a review cycle that survives staff turnover.
- Policy lifecycleDrafting, approval, version control, distribution, attestation tracking and scheduled review — rather than a shared folder of PDFs nobody has opened since induction.
- Control operation and evidenceThe recurring calendar — access reviews, restore tests, vulnerability scans, awareness training, vendor reviews — plus the evidence capture that proves each one ran on time.
- Third-party and vendor riskSupplier tiering by the damage they could do, due diligence questionnaires, security clauses for contracts, and ongoing monitoring of the vendors inside your perimeter.
- Audit managementInternal audit, mock assessment, auditor liaison, and finding tracking through corrective action to documented closure.
Four phases, in this order.
The order matters more than the speed. Every phase has an exit condition you sign off before the next one starts.
Scope and select
Decide which frameworks genuinely apply and define the boundary precisely. Over-scoping a certificate is the most expensive mistake in this field and the hardest to unwind later.
Assess and register
Control gap assessment plus a populated risk register with real owners and real treatment decisions — not a template with your logo on it.
Implement and evidence
Controls put into operation with the evidence mechanism built at the same moment, because evidence reconstructed afterwards rarely convinces an assessor and never convinces a good one.
Sustain and audit
Internal audit, management review and mock assessment, then we sit with you through the external audit and handle the findings.
What you receive.
- Framework gap assessment with scored control status
- Risk register with owners, treatment plans and review dates
- Approved policy set with version control and attestation records
- Compliance calendar and structured evidence repository
- Internal audit report and corrective action tracker
What we work with.
- ISO/IEC 27001
- ISO 27005
- SOC 2
- PCI DSS 4.0
- NIST CSF 2.0
- NIST 800-53
- CIS Controls v8
- COBIT
- GDPR
- HIPAA
- Compliance automation platforms
We hold no exclusive reseller obligations. Recommendations are made on fit, your team's capacity to operate the thing, and local support availability — in that order.
GRC, specifically.
How is this different from your cybersecurity advisory service?
Advisory is engineering-led: find the technical gaps and close them. GRC is evidence-led: prove the controls operate, keep the register current, and carry you through an assessment. Most organizations need both, because advisory closes the holes and GRC demonstrates they stay closed. If an auditor is already booked and you can only fund one, start here.
Can you certify us?
No, and neither can any consultancy — that is worth being blunt about. Certification is issued by an accredited certification body following an independent audit. We do the gap assessment, implementation, evidence structure and mock audit, then support you through the real assessment. Any firm offering to sell you a certificate directly is selling something that is not a certificate.
Do we need a full-time compliance hire?
Below roughly 200 staff, usually not. What you need is a named owner with a few hours each week and a calendar that tells them what falls due and when. We build that, train the owner, and review quarterly. Above that size, or in regulated finance, a dedicated role starts to pay for itself.
Often scoped alongside this.
Cybersecurity
Full-program security: risk assessment, policy, controls, audit readiness and the people to run it.
→VAPT
We break in the way an attacker would, then hand you the exact path, the evidence and the fix.
→SIEM
Logs collected, correlated and actually watched — with named analysts and a response time you can hold us to.
→Scope your grc engagement.
Send us the shape of your environment. You will get a written scope, a fixed price and a delivery timeline — usually within two business days.
Scoping calls are free · Reply within one business day