GRC and compliance
ISO, NIST, PDPL and Cyber Essentials programmes built with the people who will operate them, so the management system survives after the consultants leave.
Discuss compliance- Frameworks
- ISO · NIST · NIS2 · GDPR · PDPL
- Output
- Audit-ready evidence
- Reporting
- Arabic and English
Why organisations get stuck
Compliance programmes stall when documents are written for auditors rather than for the people who have to follow them. Our GRC and compliance programme produces a management system your own teams can operate after we leave.
Everything in GRC and compliance
14 pages. Each one states what it covers, who delivers it and what you get at the end.
ISO/IEC 27001
From gap assessment to a certification-ready management system: defensible scope, a risk method your team can run, and evidence collected…
Read moreStandards and frameworksISO/IEC 42001
An AI management system covering governance, risk, lifecycle controls and audit preparation, mapped alongside ISO/IEC 27001 so one programme serves…
Read moreData protectionOman PDPL
Data mapping, notices, policies and technical measures for Oman's Personal Data Protection Law, delivered in Arabic and English with the…
Read moreStandards and frameworksNIST CSF
A risk-based programme across Govern, Identify, Protect, Detect, Respond and Recover, with a costed roadmap and target maturity by quarter…
Read moreStandards and frameworksNIS2
Scope determination, risk management measures, supply-chain assurance and the 24-hour incident reporting duty, with evidence management accountability requires.
Read moreData protectionGDPR and UK GDPR
Data mapping, lawful basis, subject rights, transfer mechanisms and processor agreements, built as a working programme rather than a folder…
Read moreStandards and frameworksCyber Essentials
Scoping, hands-on remediation and evidence for UK certification, including the fixes rather than just the list of what is wrong.
Read moreRisk and assuranceRisk assessments
Risk expressed in operational, financial and regulatory terms, with treatment decisions recorded, owned and reviewable, not a heat map nobody…
Read moreRisk and assuranceSecurity maturity assessment
An evidence-based score across six security domains, mapped to ISO/IEC 27001, NIST CSF and the regulation that applies to you,…
Read moreRisk and assuranceSecurity policies
A coherent policy framework written with the people expected to follow it, routed through your own governance, and given a…
Read moreRisk and assuranceInternal audit
Independent testing against the standard before the certification body arrives, with findings expressed as achievable corrective actions and tracked to…
Read moreRisk and assuranceBusiness continuity
Impact analysis, dependency mapping and plans people can follow under pressure, tested by exercises that expose the gaps before an…
Read moreRisk and assuranceDisaster recovery
Recovery objectives agreed with the business, immutable backups isolated from the production identity plane, and runbooks that work when key…
Read moreRisk and assuranceVirtual CISO
Senior security leadership on a defined commitment: strategy, board reporting, supplier assurance and programme oversight, without carrying a full-time executive…
Read moreHow the work runs
The same sequence on every engagement, so you know what happens next.
Assess
A gap assessment against the standard, showing what already passes as well as what does not.
Design
Scope, risk method, policy framework and control set agreed with your management team.
Implement
Documents written with the people who will follow them, and controls embedded in existing processes.
Audit
Internal audit and management review run properly, producing the records the certification body expects.
Sustain
Ongoing operation of the management system, or handover to your team with training.
Technology partners
⚠ 24 partner logos are not yet authorised and show as wordmarks
Before you enquire
How long does certification readiness take?
Can policies and reports be produced in Arabic?
Do you also perform the certification audit?
Discuss compliance
Tell us the outcome you need. We will tell you honestly whether we are the right people for it.
