Don’t do SECURITY. Do business SECURELY.

Security services tailored to your business

Consulting and auditing that help your organisation do business securely.

Every organisation is different. We tailor our consulting and auditing to your business, your risks, and your goals, giving pragmatic advice aligned to recognised standards, frameworks, and regulations, without unnecessary complexity.

Consulting Blue

Consulting

We provide trustworthy and pragmatic consulting to help you implement, improve, and certify against recognised standards and meet your regulatory obligations:

  • Information security: ISO/IEC 27001
  • Privacy: ISO/IEC 27701 and GDPR compliance
  • Business continuity: ISO 22301
  • AI governance: ISO/IEC 42001 and the NIST AI Risk Management Framework
  • NCSC: Cyber Essentials and Cyber Essentials Plus, and the Cyber Assessment Framework (CAF)
  • NIST: Cybersecurity Framework (CSF) and the SP 800 series
  • Belgian CyberFundamentals (CyFun)
  • TISAX for the automotive supply chain
  • Regulations: NIS2, DORA, and GDPR
  • Information risk management and cyber security strategy
  • GRC platforms: implementation and operation using ISMS.online, Drata, Adoptech, and CISO Assistant

Auditing

We conduct 2nd-party and internal audits, giving you objective confidence in your own compliance programmes or against internationally recognised standards and frameworks, such as:

  • ISO/IEC 27001 and ISO/IEC 27701
  • ISO 22301
  • ISO/IEC 42001
  • Cyber Essentials readiness and NCSC CAF assessments
  • NIST Cybersecurity Framework
  • CyberFundamentals (CyFun) and TISAX readiness
  • NIS2, DORA, and GDPR compliance reviews
  • Supplier and third-party security audits
Auditing Blue
AI Governance

AI governance

As organisations adopt AI, customers and regulators expect it to be governed responsibly. We help you establish and audit an AI management system that is proportionate to your risks:

  • ISO/IEC 42001 gap analysis, implementation, and certification readiness
  • NIST AI Risk Management Framework (AI RMF) assessments
  • AI inventories, risk assessments, and impact assessments
  • Internal and supplier audits of AI management systems
  • Integration with your existing ISO 27001 and ISO 27701 management systems

Find out more about ISO 42001 and the NIST AI RMF »

Standards & frameworks

ISO/IEC 27001, 27701 & 22301

Information security (ISMS), privacy information management (PIMS), and business continuity (BCMS) management systems.

NCSC

Cyber Essentials and Cyber Essentials Plus consulting, and the Cyber Assessment Framework (CAF) for essential services and critical infrastructure.

NIST

The NIST Cybersecurity Framework (CSF 2.0) and the SP 800 series of security and privacy controls and guidance.

Belgian CyberFundamentals

The CyFun framework from the Centre for Cybersecurity Belgium, a recognised route to demonstrating NIS2 compliance in Belgium.

TISAX

The automotive industry’s information security assessment and exchange mechanism, based on the VDA ISA catalogue.

AI governance

ISO/IEC 42001 AI management systems and the NIST AI Risk Management Framework (AI RMF).

Regulations

NIS2

The EU Network and Information Security Directive, strengthening cyber security risk management and incident reporting for essential and important entities.

GDPR

UK GDPR and EU GDPR: protecting personal data through lawful, transparent, and secure processing, supported by ISO/IEC 27701.

DORA

The EU Digital Operational Resilience Act for financial entities and their critical ICT third-party providers.

GRC platforms we work with

We are familiar with implementing and operating compliance programmes on leading governance, risk and compliance (GRC) platforms, and can help you get the most from the tools you already use.

ISMS.online

A UK compliance platform for building and running ISO 27001, ISO 27701, ISO 42001, and other management systems.

Drata

A compliance automation platform with continuous control monitoring across frameworks such as ISO 27001.

Adoptech

A UK platform helping growing businesses automate and maintain compliance with security frameworks such as ISO 27001.

CISO Assistant

An open-source GRC platform with an extensive library of frameworks, supporting risk assessments, audits, and compliance tracking.