Services

Twelve disciplines, one assurance programme

Strengthening security, empowering growth — engage a single service or let us run an integrated programme spanning security, privacy, continuity, AI and the people who operate them.

ISO/IEC 27001 Information Security

End-to-end ISMS design, gap assessment, risk treatment and audit readiness up to certification.

  • Scoping & gap analysis
  • Statement of Applicability
  • Internal audit & Stage 1/2 support

ISO/IEC 42001 AI Management

Build an AI management system that stands up to regulators, boards and enterprise customers.

  • AI inventory & impact assessment
  • AIMS documentation
  • Model lifecycle controls

ISO/IEC 27701 Privacy

Privacy information management aligned to GDPR, CCPA and cross-border transfer obligations.

  • PIMS implementation
  • RoPA & DPIA programmes
  • Data subject rights operations

Business Continuity (ISO 22301)

Continuity and resilience programmes that survive real incidents, not just tabletop exercises.

  • Business impact analysis
  • Recovery strategies & RTO/RPO
  • Crisis simulation

Cloud Security

Secure architecture and posture management across AWS, Azure and Google Cloud estates.

  • Landing zone review
  • CSPM & IAM hardening
  • Container & Kubernetes security

AI Governance

Policy, oversight and assurance for generative and predictive AI under the EU AI Act and NIST AI RMF.

  • Governance operating model
  • Model risk & red-teaming
  • Vendor AI due diligence

Risk Management

Quantified, board-ready cyber risk management integrated with enterprise risk frameworks.

  • Risk register design
  • Third-party risk
  • Quantification & reporting

Security Audits

Independent technical and control audits benchmarked against ISO, NIST CSF and CIS controls.

  • Control effectiveness testing
  • Technical configuration review
  • Remediation roadmaps

Virtual CISO

Executive security leadership on subscription — strategy, board reporting and programme delivery.

  • Security strategy & budget
  • Board & audit committee reporting
  • Team mentoring

GRC Consulting

Unified governance, risk and compliance operating models that reduce audit fatigue.

  • Control harmonisation
  • GRC tooling selection
  • Continuous compliance

Data Privacy & Protection

One privacy control set answering many regulators — GDPR, India's DPDP Act, HIPAA, CCPA and sectoral rules.

  • DPDP Act, GDPR & HIPAA readiness
  • RoPA, DPIA & consent architecture
  • Cross-border transfer, DLP & encryption design

Corporate Training & Mentorship

Capability built inside your teams — cloud security, privacy and lead auditor programmes taught by a practitioner.

  • Cloud & DevSecOps security training (AWS · Azure · GCP · OCI)
  • ISMS, PIMS & BCMS Lead Auditor and GDPR/DPDP workshops
  • Executive briefings and one-to-one career mentorship