Every engagement began the same way. None ended the same way.
Every one started with an assessment. What came next followed from what we found.
Not every conversation ends in a mandate. If the assessment shows you can do it yourself, the report says so and we do not propose a mandate.
The cases
The assessment
A trading company
Their largest customer had set a deadline: ISO 27001 or no new framework agreement. No ISMS, no security staff.
After three weeks we had a strategy with a defensible timeline, and the customer accepted it. The pressure was off.
After eight months the ISMS stood: risk register, Statement of Applicability, 22 management documents, approved by leadership. Certification is underway.
A GRC platform is set up, followed by vCISO on a mandate.
From day one we run the conversations with the major customer's risk team.
The ISMS stood, but their own IT could not run the standards. The CISO saw his DORA requirements unimplemented, and IT was never told what to do technically. A binding cryptography standard had to be ready before the DORA deadline, not a whole program.
A cryptography standard based on DORA and ISO 27001.
A logging standard and a logging concept.
Translated between CISO and IT: a document fitted exactly to their own stack. The IT lead could implement precisely and measure progress, the CISO got his DORA compliance.
Both written so their own team understands it and can run it. That was the condition, not the bonus.
After an incident: attackers had taken over accounts through phishing. The acute response ran through the cyber insurer; we came afterwards, for the rebuild. Inside the house no one had seen what happened, and access had never been put in order.
Access and identities put in order: accounts, rights, who may reach what, from one source.
MDR and EDR rolled out across the house.
An ISMS set up: governance, responsibilities, a state that holds.
Six to eight weeks from forensic report to a provable state.
Today the operation sees an attack, and the door it came through is closed.