Advisory & Compliance

Compliance and Risk Advisory

We prepare organisations for security audits and customer assurance reviews: gap assessment against the target framework, practical control design, automated evidence collection, and direct support through the audit itself.

The problem we solve

Compliance projects usually start because a deal is blocked. That urgency tends to produce the worst possible version of the work — policies copied from templates, controls that exist only on paper, and an evidence scramble every quarter.

Engineering teams end up carrying the cost. Screenshots, spreadsheets and manual attestations consume weeks per cycle, and none of it makes the organisation measurably harder to attack.

Then a second framework arrives. Without a common control set, SOC 2, ISO 27001 and PCI DSS get run as three separate programmes over the same underlying systems.

Compliance is a floor, not a ceiling — but a well-run compliance programme is still one of the most reliable ways to get security funded. The trick is choosing controls that would be worth implementing even if no auditor were coming.

Our approach

Adapted to your environment and constraints — but the shape of the work is consistent.

  1. Gap assessment against the real target

    We assess current state against the specific framework in scope — SOC 2 Trust Services Criteria, ISO 27001 Annex A, PCI DSS requirements or NIST CSF — and produce a gap list with effort, owner and priority. No generic checklist.

  2. Design controls that do something

    Wherever possible we satisfy a requirement with a technical control that also reduces risk: enforced SSO and MFA, IaC-enforced encryption, pipeline gating, automated access reviews, CSPM alerting. Policy documents describe what the systems already enforce.

  3. Automate the evidence

    We wire evidence collection into the systems that generate it — cloud configuration, ticketing, CI/CD, identity provider, endpoint management — so the quarterly cycle becomes a review rather than an archaeology project. Compliance automation platforms are integrated where they fit.

  4. Build one control set, map it many ways

    A single internal control library mapped to every framework you carry. Implement once, evidence once, satisfy several auditors.

  5. Support the audit

    We prepare the team, run readiness reviews, work directly with auditors during fieldwork, and help manage findings through to closure.

Expected outcomes

What changes as a result of the engagement.

  • A clear, costed picture of what stands between you and the certification
  • Controls implemented as enforced technical configuration, not aspiration
  • Evidence collected automatically rather than assembled by hand
  • One control set satisfying multiple frameworks
  • A maintained risk register that stands up to auditor questioning
  • Faster completion of customer security questionnaires
  • Reduced engineering time lost to each audit cycle

Typical deliverables

Confirmed in the proposal before work starts, and adjusted to scope.

  • Compliance gap assessment against the target framework
  • Prioritised remediation plan with owners and effort estimates
  • Internal control library with cross-framework mapping
  • Security policy framework — technical, operational and management policies
  • Risk assessment methodology and populated risk register
  • Evidence collection plan and automation design
  • Access review, change management and vendor management processes
  • Third-party / vendor due-diligence workflow
  • Audit readiness review and mock-audit findings
  • Auditor liaison and findings remediation tracking

What this covers

The specific capabilities available under this service. Engagements usually draw on a subset — we scope to the problem, not the catalogue.

Frameworks

  • SOC 2 Type I and Type II readiness
  • ISO 27001 readiness and ISMS design
  • PCI DSS gap assessment
  • NIST Cybersecurity Framework alignment
  • CIS Controls implementation
  • Cross-framework control mapping

Programme

  • Security policy framework development
  • Risk assessment and risk register
  • Third-party risk and vendor due diligence
  • Access review and joiner-mover-leaver process
  • Change management and SDLC controls
  • Business continuity and DR documentation

Evidence & automation

  • Evidence collection automation
  • Compliance automation platform integration
  • Cloud configuration evidence (CSPM)
  • Continuous control monitoring
  • Audit-ready reporting and dashboards

Audit support

  • Mock audit and readiness review
  • Auditor liaison during fieldwork
  • Findings management and remediation tracking
  • Customer security questionnaire support
  • Trust and assurance documentation

Who this is for

  • SaaS companies pursuing SOC 2 Type I or Type II
  • Organisations working towards ISO 27001 certification
  • Businesses handling cardholder data with PCI DSS obligations
  • Teams that hold a certification but dread each audit cycle
  • Companies losing enterprise deals on security questionnaires

Recognise your situation? A 30-minute discovery call is the fastest way to find out whether this is the right engagement.

Book a security consultation

Common questions

Do you issue the certification?

No — that requires an independent audit firm, and it would be a conflict of interest for the party implementing controls to also attest to them. We prepare you, work alongside your chosen auditor, and help close findings.

Can compliance work and real security improvement be the same project?

Largely, if it is designed that way. We deliberately choose enforced technical controls over paper controls wherever a requirement allows it, so the audit outcome and the risk reduction come from the same work.

We already use a compliance automation platform. Does that change anything?

It helps with evidence, not with control design. We integrate with what you have and focus on the parts those platforms cannot do for you — designing the controls, fixing the underlying configuration and defending the decisions to an auditor.

These engagements are often scoped together — the underlying risks overlap.

Advisory & Compliance

Cybersecurity Advisory

Security strategy, architecture review, maturity assessment, vulnerability management and incident readiness — built into a programme with owners, metrics and a roadmap leadership can fund.

Cloud Security

AWS Security

Secure AWS architecture, least-privilege IAM, detection with GuardDuty and Security Hub, and posture management that keeps multi-account estates defensible as they grow.

DevSecOps & AppSec

DevSecOps

Build security into the delivery pipeline instead of bolting it on at the end — secure SDLC, CI/CD hardening, IaC scanning, supply-chain controls and guardrails engineers will actually keep.

Discuss your security challenges

Tell us what you are trying to secure and where it hurts. We will tell you what we would do first, whether or not you engage us.