security posture assessment
Find out where you actually stand: which gaps matter, which don’t, and a short list in the order things should be fixed.
Compliance
What the standard or the review asks for, what you already have, and what is missing — documented plainly enough that a new hire or a different provider could pick it up. Delivery is aligned to published frameworks, including NIST CSF 2.0, and progress is reported in a form you can put in front of a board or an auditor.
ISO 27001 is the worked example on this page, because it is the one of the three with a public, checkable structure: Annex A of ISO/IEC 27001:2022. GDPR and SOC 2 readiness follow the same approach — what is asked for, what you already have, and what is missing.
Where this gets in
Findings ranked by real business impact, with a summary clear enough for your board — a document that drives fixes, not a 200-page PDF that sits in a drive.
A report from last year with findings nobody closed, and tools running that nobody has time to read. What is open needs an owner and a date against it.
Somebody has to answer what customers and investors send over, decide what matters first, and keep the written record. That is a role, not a document.
Progress you can put in front of a board or an auditor, written plainly enough that a new hire or a different provider could actually use it.
What this covers
Where you stand, who decides what matters first, and what a review or certification will ask.
What the standard or the review asks for, what you already have, and what is missing — documented plainly enough that a new hire or a different provider could pick it up. Delivery is aligned to published frameworks, including NIST CSF 2.0, and progress is reported in a form you can put in front of a board or an auditor.
a fact about the standard, not about us
93
controls in Annex A of ISO/IEC 27001:2022, across four themes
Where to start
A one-off look at where you stand, the person who owns the follow-through, and two engagements where the write-up already had to hold up to a review.
Find out where you actually stand: which gaps matter, which don’t, and a short list in the order things should be fixed.
The person who decides what matters first, answers what customers and investors ask, and keeps the written record — a few days a month.
The exposure was legal rather than technical. Consent recorded, purpose stated, retention defined, each session attributable — a data protection review answerable end to end.
Network access moved onto the identity system the company already had, so every connection is attributable to a named account rather than a shared secret — which is what an auditor asks for and what an investigation depends on.
Next step
Proof is a by-product of the work being done in an order somebody chose and wrote down. Once the record says what was decided, what was fixed and when, the audit stops being a project of its own.