Advisory

    Engagements, not engagements-of-record.

    An engagement is scoped work with a named outcome: stand up the governance, run the risk assessment, get the evidence audit-ready. The program is then handed to the team that has to run it.

    Fixed-scope engagements · Advisory retainers · Workshops

    01 — The framework

    One model, three fields of work.

    Every engagement traces back to one model. Assets need protection; protection is ensured through governance and demonstrated through compliance, and both exist to manage risk. Select a field to read the work it holds.

    GRCIDE governance, risk and compliance frameworkAssets require protection; protection is ensured through governance and demonstrated through compliance; governance drives compliance; together they manage risks.requireensured throughdemonstrated throughdrivesmanageAssetsPhysical · Hardware · SoftwareInformation · PersonnelProtectionConfidentiality · IntegrityAvailabilityGovernancePolicies · ProceduresStandards · Due diligenceControl oversight · EthicsComplianceLegislation · RegulationIndustry best practiceInternal & external auditRisksNIST RMF 800-39 / 800-37ISO/IEC 27005
    The working model — assets, protection, governance, compliance, and risk.

    02 — Governance

    Ensure protection through governance.

    Governance is what makes security decisions on purpose rather than by accident: policy, roles, and the authority to enforce them. It sets what good means for an organisation and who answers for it when the answer slips.

    Capabilities

    • ISMS design and build-out to ISO/IEC 27001
    • Policy and standards architecture — a coherent set, not a binder nobody reads
    • Roles, responsibilities and decision rights, with named control owners
    • Security strategy and control objectives tied to the business
    • Management review, metrics and a reporting cadence that holds
    • Accountability that survives the next reorganisation

    Typical deliverables

    • ISMS charter and policy set
    • Decision-rights and ownership map
    • Security strategy on a page
    • Management-review pack

    Good fit when controls exist but nobody can say who owns them, or why.

    03 — Risk

    Know the risk before you treat it.

    Risk work is where governance and compliance earn their keep: identify what can go wrong, decide what to do about it, and record the reasoning. That means a register a team maintains, and for connected products it also means threat analysis and risk assessment.

    Capabilities

    • Risk assessment and treatment to ISO/IEC 27005
    • Third-party and supplier risk, from due diligence to monitoring
    • Asset and impact analysis that ties risk back to the business
    • Risk acceptance, treatment plans and residual-risk tracking
    • A register the organisation's own team can maintain afterwards
    • Threat analysis and risk assessment for connected products

    Typical deliverables

    • Risk register and treatment plan
    • Supplier risk assessment framework
    • Residual-risk report for sign-off
    • Threat-modelling workshop series

    Good fit when a defensible risk picture is owed to a regulator, a customer, or a board.

    04 — Compliance

    Demonstrate protection through compliance.

    Compliance is how an organisation proves to an auditor, a customer or an authority that the controls it claims actually run. The work builds toward the certificate or the audit and leaves the evidence trail behind it.

    Capabilities

    • ISO/IEC 27001 certification readiness, end to end
    • SOC 2 readiness for both report types, against the Trust Services Criteria
    • NIS2 and IEC 62443 mapped to what authorities expect
    • Statement of Applicability, control mapping and evidence design
    • Audit dry-runs and remediation before the real assessment
    • TISAX, R155 and ISO/SAE 21434 when in scope

    Typical deliverables

    • Statement of Applicability and evidence map
    • Control-to-requirement mapping
    • Audit dry-run report
    • Readiness assessment and remediation plan

    Good fit when an audit or certification date is on the calendar and the organisation intends to walk in ready.

    05 — AI security governance

    Govern AI systems on purpose.

    AI moved from pilot to production faster than most governance did. This track puts a use case through triage, decides what the obligations are, and wires the controls into the delivery process instead of a policy nobody reads.

    Capabilities

    • EU AI Act readiness: role, risk tier and the obligations that follow
    • AI use-case triage, with a register and a decision record per system
    • AI-SSDLC governance — model, data and prompt changes under change control
    • NIST AI RMF and ISO/IEC 42001 alignment for an existing management system
    • Model and supplier evaluation, including hosted and third-party models
    • Monitoring, incident handling and human oversight that is written down

    Typical deliverables

    • AI use-case register and triage criteria
    • Role and risk-tier determination per system
    • AI management-system gap analysis and roadmap
    • Oversight, evaluation and incident procedures

    Good fit when AI systems are already in production and the governance is still a slide.

    06 — Product & OT security

    When the product itself is in scope.

    Connected products, vehicles and plant carry their own regimes. The work is the same discipline applied to engineering: a management system the type-approval or conformity route can be assessed against, and evidence produced by the development process rather than after it.

    Capabilities

    • R155 and R156 management systems for vehicle type approval, when in scope
    • ISO/SAE 21434 engineering process, work products and assessment readiness
    • IEC 62443 for industrial automation and control environments
    • Cyber Resilience Act readiness for products with digital elements
    • Machinery Regulation and CE conformity where cybersecurity is in the route
    • Supplier interface agreements and the evidence they have to produce

    Typical deliverables

    • Management-system description and process map
    • Threat analysis and risk assessment work products
    • Conformity or type-approval evidence pack
    • Supplier requirement and interface set

    Good fit when a product regime is in scope and engineering, not only IT, has to carry the evidence.

    07 — How we work

    Assess, design, implement, operate.

    01

    Assess

    Understand the business, the obligations, and what already exists. No two programs start from the same baseline.

    02

    Design

    Shape controls and governance around how the organisation actually works — proportionate to the risk, not maximal.

    03

    Implement

    Do the work alongside the team: policies written, risks assessed, evidence built as it goes.

    04

    Operate

    Run it long enough to prove it holds, then hand it over — owned by the organisation's own people.

    Advisory enquiries welcome.