Each service below is offered as a standalone engagement or as part of a combined roadmap. Program boundaries stay crisp so you always know which advisor owns which control.
P
SOC 2 Readiness Programs
A SOC 2 engagement is a controlled exercise in evidence. We run a readiness program that maps the five trust service criteria into a live control library, then pressure-tests each control through a mock walkthrough so the first official visit is a confirmation rather than a surprise.
The program begins with a scoping discussion to fix the system description and the boundary of trust. We then document the control environment, identify where gaps live in your tooling and team responsibilities, and sequence remediation so the work fits your release calendar rather than colliding with it.
We coach your operators on how to describe a control when the tester asks, because auditors write down how convincingly a control is demonstrated, not just whether a policy file exists. Evidence is organised in a chain that lets your team maintain it between reporting cycles.
At the close you receive a readiness report, a remediated control matrix and a written assertion package your CPA can use to move straight toward the report. We remain available to escort the external audit.
P
ISO 27001 Gap Assessments
An ISO 27001 project lives and dies by the statement of applicability and the evidence behind it. We run a disciplined gap assessment that catalogues your information assets, walks the applicable Annex A controls and measures the distance between what you do today and what the standard expects.
Interviews reach the people who actually operate the system, not just the managers who approve the roadmap. We inspect configurations, review access listings, check monitoring coverage and trace each policy statement to the point where it is enforced in daily work.
Every finding receives a rating of severity, a proposed owner and a practical remediation path tuned to your budget and current tooling. We distinguish the controls that must close before certification from the ones that can mature during a staged improvement plan.
You leave with a prioritised findings register, an updated statement of applicability and a retest pass that confirms the gaps identified at the start have genuinely closed, ready to present to your certification body.
P
Vendor Risk Reviews
Every subcontractor and cloud provider enlarges your attack surface while also strengthening your compliance story, provided the risk is actually managed. We run vendor risk reviews that replace scattered questionnaires with a structured, live view of the third parties touching your environment.
The first step is a clean inventory of your vendors grouped by the sensitivity of the data they handle and the criticality of the service they render. From there we define the shared responsibility boundary with each provider and identify where your own controls must compensate for their gaps.
We review contractual security terms, certification evidence, incident history and exit provisions, converting questions into tracked findings that procurement and security can act on together. A regular cadence keeps new vendors from arriving on faith alone.
The finished deliverable is a vendor risk register that reports to leadership in plain terms and feeds directly into your own SOC 2 or ISO program, so third-party assurance strengthens rather than duplicates your overall position.
P
Policy Suite Authoring
An auditor who cannot reconcile a policy with daily behaviour flags that policy as decoration. We author a policy suite that reflects how your team genuinely operates, written in direct language that an engineer, a support agent and a finance lead can all follow.
Our suite covers information security, acceptable use, access control, incident response, business continuity, change management and vendor management, with each policy mapped to the controls it supports. We draft against your naming conventions and integrate with the tooling where approvals and version control already live.
Each document carries a named owner, a scheduled review date and a visible revision history, so stewardship is provable to an auditor. Our drafts avoid legal padding and instead state the rule, the reason and the consequence of non-compliance in plain words.
Deliverables arrive in editable formats that your team can maintain and republish without routing every small amendment through us, keeping the suite a living asset rather than a shelf document.
P
Security Awareness Training
People are the control that decides whether a phishing email ends a quarter. We design security awareness training that rehearses genuine decisions through compact, role-aware modules rather than a long lecture of abstract best practice.
Content rotates across phishing, social engineering, remote access hygiene, data handling, clean desk discipline and incident reporting. We tailor examples to the roles in your company so a developer and a customer support lead face scenarios that resemble their real inbox.
Programs are paired with simulated events that measure behaviour change over time, giving you the numbers you need to show a skeptical auditor that training moves benchmarks rather than just marking attendance. Reporting summarises completion and demonstrated risk reduction.
The training log doubles as evidence for your annual workforce control, and refreshed content keeps pace with the threats your team will actually meet next quarter.
P
Audit Season Escort
When the external auditor arrives, small fumbles can unravel weeks of careful preparation. Our audit season escort puts an experienced advisor at your side to coordinate the evidence walkthrough, so your team can answer with confidence instead of hunting for a log upload during the interview.
Before the visit we stage the evidence library so every control referenced in the assertion has a named, timestamped artefact ready on a single channel. We rehearse management testimony and brief the staff who will face the tester, including the questions most likely to be asked in each lane.
During the audit our escort tracks every request, closes loops in real time and keeps a running register of what remains outstanding. Where an evidence item turns out to be thin, we triage it immediately rather than leaving it to drift into the final report.
The escort produces a close-out memo summarising what the auditor reviewed and what you should keep polished for the next cycle, so each season makes the next one easier.