Compliance that makes sense.
Boutique information security consulting for startups and small companies that want more than a certificate on the wall.
What we do
Why us
No templates
Every project is different. The processes are yours, not copied from a textbook.
No disappearing
We stay after the audit. The certificate is the beginning, not the end.
No jargon
We speak plain language. If something isn't clear - we haven't explained it well enough.
From the blog
All articles →ISO 27001 Control A.6.3: Information Security Awareness, Education and Training
Annex A control 6.3 requires staff to receive appropriate security awareness, education and training. How to build a programme that changes behaviour and evidences it for audit.
ISO 27001 Control A.6.4: Disciplinary Process
Annex A control 6.4 requires a formal, communicated disciplinary process for security violations. How to build one that is fair, lawful, and gives your other controls teeth.
ISO 27001 Control A.6.5: Responsibilities After Termination or Change of Employment
Annex A control 6.5 requires security duties that survive a role change or exit to be defined and enforced. How to run secure offboarding and what auditors check.
We work with
Not sure where to start?
Let's start with a conversation - no commitment, no jargon. Even if we're not the right fit, we'll point you in the right direction.
Book a free consultation →