Compliance that makes sense.
Boutique information security consulting for startups and small companies that want more than a certificate on the wall.
What we do
Why us
No templates
Every project is different. The processes are yours, not copied from a textbook.
No disappearing
We stay after the audit. The certificate is the beginning, not the end.
No jargon
We speak plain language. If something isn't clear - we haven't explained it well enough.
From the blog
All articles →ISO 27001 Clause 10.1: Continual Improvement
Clause 10.1 requires you to continually improve the ISMS. What continual improvement means in practice, how to evidence it, and why the 2022 revision put it first in Clause 10.
ISO 27001 Clause 9.3: Management Review
Clause 9.3 requires top management to review the ISMS at planned intervals. The required inputs, the decisions expected as outputs, and what auditors look for in the minutes.
ISO 27001 Clause 9.2: Internal Audit
Clause 9.2 requires internal audits at planned intervals to test whether your ISMS conforms and works. How to build an audit programme, stay impartial, and pass certification.
We work with
Not sure where to start?
Let's start with a conversation - no commitment, no jargon. Even if we're not the right fit, we'll point you in the right direction.
Book a free consultation →