Skip to content

What we protect

Governance & compliance.

What you have to be able to prove.

Customers, investors and auditors ask for the same thing in different words: show us. This is the work of knowing where you stand, having somebody accountable for the order things get fixed in, and keeping a written record that another provider or a new hire could pick up.

Where this gets in

what you have to be able to prove.

Findings ranked by real business impact, with a summary clear enough for your board — a document that drives fixes, not a 200-page PDF that sits in a drive.

  • Findings nobody closed

    A report from last year with findings nobody closed, and tools running that nobody has time to read. What is open needs an owner and a date against it.

  • The questions customers ask

    Somebody has to answer what customers and investors send over, decide what matters first, and keep the written record. That is a role, not a document.

  • Proof in a form somebody will read

    Progress you can put in front of a board or an auditor, written plainly enough that a new hire or a different provider could actually use it.

The services

three services, and what each one covers.

Where you stand, who decides what matters first, and what a review or certification will ask.

/ 01

security posture assessment

Find out where you actually stand.

We look at what you have and tell you which gaps matter and which don’t, then give you a short list in the order things should be fixed. It is a one-off look rather than a programme: the point is to replace an argument about priorities with a sequence.

  • what’s exposed now
  • what audits ask for
  • what to fix first

/ 02

vciso (fractional)

A security lead without hiring one.

You get the person who decides what matters first, answers the questions customers and investors ask, and keeps the written record — for a few days a month rather than a salary. Ownership gets written down rather than assumed, which is what makes the rest of the programme auditable.

  • priorities and decisions
  • answers for customers
  • the written record

/ 03

iso 27001 / gdpr / soc 2 readiness

Be able to prove it, not just claim it.

What the standard or the review asks for, what you already have, and what is missing — documented plainly enough that a new hire or a different provider could pick it up. Delivery is aligned to published frameworks, including NIST CSF 2.0, and progress is reported in a form you can put in front of a board or an auditor.

  • the gap between what is asked for and what you have
  • documentation written so somebody else could take over
  • progress a board or an auditor can read
  • every access scoped to the work, logged in use, revoked at the end

Where to start

where this work usually starts.

What a review asks for, and two engagements where the answer had to exist in writing.

compliance

ISO 27001

What the standard asks for, what you already have, and what is missing — with the documentation written so that somebody else could take it over.

view compliance
case study

Guest Wi-Fi that survives an audit

The exposure was legal rather than technical. Consent recorded, purpose stated, retention defined, each session attributable — a data protection review answerable end to end.

read the case study
case study

Wi-Fi that knows who you are

Network access moved onto the identity system the company already had, so every connection is attributable to a named account rather than a shared secret — which is what an auditor asks for and what an investigation depends on.

read the case study

the other five things we protect.

People

The inbox, and the person reading it.

4 services

Devices

Laptops nobody manages.

2 services

Offices

The front door, and the room behind it.

2 services
See all 18 services in one list

Next step

get it in writing.

Proof is a by-product of the work being done in an order somebody chose and wrote down. Once the record says what was decided, what was fixed and when, the audit stops being a project of its own.