Governance, risk and compliance

Compliance that leaves you safer, not just auditable.

Compliance work is only worth doing if the organisation ends up genuinely safer as well as able to prove it. We help you meet the obligation and fix the underlying weakness at the same time, rather than producing evidence for its own sake.

What is included

ISO 27001 and Cyber Essentials Plus readiness
Support for achieving and maintaining ISO 27001 and Cyber Essentials Plus, through gap analysis, control implementation, documentation and audit preparation.
Regulatory compliance advisory
Guidance on UK GDPR, the Data Protection Act 2018 and sector-specific regulation, to reduce regulatory risk through proactive compliance programmes.
Third party risk management
Assessment and monitoring of vendor and supply chain security risk: supplier questionnaires, contract review, risk scoring and continuous vendor monitoring.
Board level risk reporting
Security risk reporting aligned with the UK Corporate Governance Code, translating technical metrics into board-level risk language.

We prepare you for certification and audit. We are not a certification body and we do not issue certificates.

Who this is for

Organisations facing certification, a regulator, or a customer whose procurement process has become the hardest part of the sale.

Request a free consultation

Tell us what you are trying to protect.