Oman United Kingdom Norway Support portal
Talk to an expert
AboutContact

GRC and compliance

ISO, NIST, PDPL and Cyber Essentials programmes built with the people who will operate them, so the management system survives after the consultants leave.

Discuss compliance
Frameworks
ISO · NIST · NIS2 · GDPR · PDPL
Output
Audit-ready evidence
Reporting
Arabic and English

Why organisations get stuck

Compliance programmes stall when documents are written for auditors rather than for the people who have to follow them. Our GRC and compliance programme produces a management system your own teams can operate after we leave.

Everything in GRC and compliance

14 pages. Each one states what it covers, who delivers it and what you get at the end.

Standards and frameworks

ISO/IEC 27001

From gap assessment to a certification-ready management system: defensible scope, a risk method your team can run, and evidence collected…

Read more
Standards and frameworks

ISO/IEC 42001

An AI management system covering governance, risk, lifecycle controls and audit preparation, mapped alongside ISO/IEC 27001 so one programme serves…

Read more
Data protection

Oman PDPL

Data mapping, notices, policies and technical measures for Oman's Personal Data Protection Law, delivered in Arabic and English with the…

Read more
Standards and frameworks

NIST CSF

A risk-based programme across Govern, Identify, Protect, Detect, Respond and Recover, with a costed roadmap and target maturity by quarter…

Read more
Standards and frameworks

NIS2

Scope determination, risk management measures, supply-chain assurance and the 24-hour incident reporting duty, with evidence management accountability requires.

Read more
Data protection

GDPR and UK GDPR

Data mapping, lawful basis, subject rights, transfer mechanisms and processor agreements, built as a working programme rather than a folder…

Read more
Standards and frameworks

Cyber Essentials

Scoping, hands-on remediation and evidence for UK certification, including the fixes rather than just the list of what is wrong.

Read more
Risk and assurance

Risk assessments

Risk expressed in operational, financial and regulatory terms, with treatment decisions recorded, owned and reviewable, not a heat map nobody…

Read more
Risk and assurance

Security maturity assessment

An evidence-based score across six security domains, mapped to ISO/IEC 27001, NIST CSF and the regulation that applies to you,…

Read more
Risk and assurance

Security policies

A coherent policy framework written with the people expected to follow it, routed through your own governance, and given a…

Read more
Risk and assurance

Internal audit

Independent testing against the standard before the certification body arrives, with findings expressed as achievable corrective actions and tracked to…

Read more
Risk and assurance

Business continuity

Impact analysis, dependency mapping and plans people can follow under pressure, tested by exercises that expose the gaps before an…

Read more
Risk and assurance

Disaster recovery

Recovery objectives agreed with the business, immutable backups isolated from the production identity plane, and runbooks that work when key…

Read more
Risk and assurance

Virtual CISO

Senior security leadership on a defined commitment: strategy, board reporting, supplier assurance and programme oversight, without carrying a full-time executive…

Read more

How the work runs

The same sequence on every engagement, so you know what happens next.

STEP 01

Assess

A gap assessment against the standard, showing what already passes as well as what does not.

STEP 02

Design

Scope, risk method, policy framework and control set agreed with your management team.

STEP 03

Implement

Documents written with the people who will follow them, and controls embedded in existing processes.

STEP 04

Audit

Internal audit and management review run properly, producing the records the certification body expects.

STEP 05

Sustain

Ongoing operation of the management system, or handover to your team with training.

Before you enquire

How long does certification readiness take?
It depends on your starting point, which is what the gap assessment establishes. You get an indicative timeline with the assessment, not before it.
Can policies and reports be produced in Arabic?
Yes. Documentation, awareness material and audit evidence are available in Arabic and English, which matters where a regulator will read them.
Do you also perform the certification audit?
No, and no consultancy should. Certification is awarded by an accredited certification body. We prepare you for it and support you through it.

Discuss compliance

Tell us the outcome you need. We will tell you honestly whether we are the right people for it.

Discuss compliance
Talk to an expert