Skip to content

Compliance

compliance readiness.

What the standard or the review asks for, what you already have, and what is missing — documented plainly enough that a new hire or a different provider could pick it up. Delivery is aligned to published frameworks, including NIST CSF 2.0, and progress is reported in a form you can put in front of a board or an auditor.

ISO 27001 is the worked example on this page, because it is the one of the three with a public, checkable structure: Annex A of ISO/IEC 27001:2022. GDPR and SOC 2 readiness follow the same approach — what is asked for, what you already have, and what is missing.

Where this gets in

what you have to be able to prove.

Findings ranked by real business impact, with a summary clear enough for your board — a document that drives fixes, not a 200-page PDF that sits in a drive.

  • Findings nobody closed

    A report from last year with findings nobody closed, and tools running that nobody has time to read. What is open needs an owner and a date against it.

  • The questions customers ask

    Somebody has to answer what customers and investors send over, decide what matters first, and keep the written record. That is a role, not a document.

  • Proof in a form somebody will read

    Progress you can put in front of a board or an auditor, written plainly enough that a new hire or a different provider could actually use it.

What this covers

prove it, not just claim it.

Where you stand, who decides what matters first, and what a review or certification will ask.

ISO 27001, GDPR and SOC 2 readiness

What the standard or the review asks for, what you already have, and what is missing — documented plainly enough that a new hire or a different provider could pick it up. Delivery is aligned to published frameworks, including NIST CSF 2.0, and progress is reported in a form you can put in front of a board or an auditor.

  • the gap between what is asked for and what you have
  • documentation written so somebody else could take over
  • progress a board or an auditor can read
  • every access scoped to the work, logged in use, revoked at the end

a fact about the standard, not about us

93

controls in Annex A of ISO/IEC 27001:2022, across four themes

  • Organizational37
  • People8
  • Physical14
  • Technological34

Where to start

where this work usually starts.

A one-off look at where you stand, the person who owns the follow-through, and two engagements where the write-up already had to hold up to a review.

engagement

security posture assessment

Find out where you actually stand: which gaps matter, which don’t, and a short list in the order things should be fixed.

view details
engagement

vciso (fractional)

The person who decides what matters first, answers what customers and investors ask, and keeps the written record — a few days a month.

view scope
case study

Guest Wi-Fi that survives an audit

The exposure was legal rather than technical. Consent recorded, purpose stated, retention defined, each session attributable — a data protection review answerable end to end.

read the case study
case study

Wi-Fi that knows who you are

Network access moved onto the identity system the company already had, so every connection is attributable to a named account rather than a shared secret — which is what an auditor asks for and what an investigation depends on.

read the case study

Next step

get it in writing.

Proof is a by-product of the work being done in an order somebody chose and wrote down. Once the record says what was decided, what was fixed and when, the audit stops being a project of its own.