Security services tailored to your business
Consulting and auditing that help your organisation do business securely.
Every organisation is different. We tailor our consulting and auditing to your business, your risks, and your goals, giving pragmatic advice aligned to recognised standards, frameworks, and regulations, without unnecessary complexity.
Consulting
We provide trustworthy and pragmatic consulting to help you implement, improve, and certify against recognised standards and meet your regulatory obligations:
- Information security: ISO/IEC 27001
- Privacy: ISO/IEC 27701 and GDPR compliance
- Business continuity: ISO 22301
- AI governance: ISO/IEC 42001 and the NIST AI Risk Management Framework
- NCSC: Cyber Essentials and Cyber Essentials Plus, and the Cyber Assessment Framework (CAF)
- NIST: Cybersecurity Framework (CSF) and the SP 800 series
- Belgian CyberFundamentals (CyFun)
- TISAX for the automotive supply chain
- Regulations: NIS2, DORA, and GDPR
- Information risk management and cyber security strategy
- GRC platforms: implementation and operation using ISMS.online, Drata, Adoptech, and CISO Assistant
Auditing
We conduct 2nd-party and internal audits, giving you objective confidence in your own compliance programmes or against internationally recognised standards and frameworks, such as:
- ISO/IEC 27001 and ISO/IEC 27701
- ISO 22301
- ISO/IEC 42001
- Cyber Essentials readiness and NCSC CAF assessments
- NIST Cybersecurity Framework
- CyberFundamentals (CyFun) and TISAX readiness
- NIS2, DORA, and GDPR compliance reviews
- Supplier and third-party security audits
AI governance
As organisations adopt AI, customers and regulators expect it to be governed responsibly. We help you establish and audit an AI management system that is proportionate to your risks:
- ISO/IEC 42001 gap analysis, implementation, and certification readiness
- NIST AI Risk Management Framework (AI RMF) assessments
- AI inventories, risk assessments, and impact assessments
- Internal and supplier audits of AI management systems
- Integration with your existing ISO 27001 and ISO 27701 management systems
Standards & frameworks
ISO/IEC 27001, 27701 & 22301
Information security (ISMS), privacy information management (PIMS), and business continuity (BCMS) management systems.
NCSC
Cyber Essentials and Cyber Essentials Plus consulting, and the Cyber Assessment Framework (CAF) for essential services and critical infrastructure.
NIST
The NIST Cybersecurity Framework (CSF 2.0) and the SP 800 series of security and privacy controls and guidance.
Belgian CyberFundamentals
The CyFun framework from the Centre for Cybersecurity Belgium, a recognised route to demonstrating NIS2 compliance in Belgium.
TISAX
The automotive industry’s information security assessment and exchange mechanism, based on the VDA ISA catalogue.
AI governance
ISO/IEC 42001 AI management systems and the NIST AI Risk Management Framework (AI RMF).
Regulations
NIS2
The EU Network and Information Security Directive, strengthening cyber security risk management and incident reporting for essential and important entities.
GDPR
UK GDPR and EU GDPR: protecting personal data through lawful, transparent, and secure processing, supported by ISO/IEC 27701.
DORA
The EU Digital Operational Resilience Act for financial entities and their critical ICT third-party providers.
GRC platforms we work with
We are familiar with implementing and operating compliance programmes on leading governance, risk and compliance (GRC) platforms, and can help you get the most from the tools you already use.
ISMS.online
A UK compliance platform for building and running ISO 27001, ISO 27701, ISO 42001, and other management systems.
Drata
A compliance automation platform with continuous control monitoring across frameworks such as ISO 27001.
Adoptech
A UK platform helping growing businesses automate and maintain compliance with security frameworks such as ISO 27001.
CISO Assistant
An open-source GRC platform with an extensive library of frameworks, supporting risk assessments, audits, and compliance tracking.