Governance, risk & compliance

Advisory & Compliance

Practical advice on security risk, policies and regulation from people who also do the hands-on work. We help you meet GDPR, NIS2 and DORA requirements without burying you in paperwork.

Sound familiar?

If any of this rings a bell, we can help

A client sent you a long security questionnaire and you don't know how to answer it.

You've heard that NIS2 or DORA may apply to you, but you're not sure what it means in practice.

Your security policies are out of date, or you don't have any.

Staff keep clicking on phishing emails.

What's included

What our advisory & compliance covers

01

Security assessment

An honest look at where you stand today, covering your systems, your processes and your people.

02

Risk assessment

We identify the risks that matter most to your business and what they would cost you if they happened.

03

Compliance gap analysis

We compare your setup with GDPR, NIS2, DORA or ISO 27001 and list exactly what is missing.

04

Policies and procedures

Clear, usable policies written for your business, not copied from a template.

05

Security awareness training

Short, practical sessions and phishing exercises that change how staff behave.

06

Ongoing security leadership

A part-time security lead, often called a virtual CISO, who joins your planning and reports to your management.

What you get

The result

The aim is a business that is genuinely safer, with the paperwork to prove it.

  • A clear picture of your risks, in plain language
  • A prioritised roadmap that fits your budget
  • Policies you can show to clients and auditors
  • Staff who recognise a phishing email
  • Confident answers to client security questionnaires
  • Fewer surprises when a regulator or client asks questions
Ways to work with us

Pick what suits you

You get the scope and cost in writing before any work begins.

01

One-off assessment

A single test or review with a written report, a good first step if you are not sure where you stand.

02

Project

A defined piece of work, such as fixing findings, a cloud migration or a compliance programme, with an agreed scope and cost.

03

Ongoing service

Monitoring, hosting and security support on a monthly basis, so everything stays looked after.

04

Emergency response

Immediate help when something has gone wrong, whether or not you are already a client.

Questions

Advisory & Compliance: common questions

It depends on your sector and size, and on whether you supply companies that fall under it. We can check this with you in a short call.

Other services