Evidence you already
produce.
Most compliance programmes are a parallel exercise: a consultant, a spreadsheet, and evidence assembled the month before an audit. Ours comes out of the operation that is already running, because a SOC investigating properly produces most of what an auditor asks to see.
We are not
a GRC consultancy.
And we are not going to pretend to be one. There are firms who will sell you six months of workshops and a document set, and for some organisations that is genuinely the right purchase.
What we are is an operation that already produces evidence. Detection coverage, incident records, investigation timelines, response actions, access reviews, supplier assessments: an auditor asking how you know a control works wants exactly that, and it is a by-product of running a SOC properly rather than something we have to go and manufacture.
On top of that sits a specialist platform, operated by us, that carries the assessment, the control mapping across frameworks, the policy set and the evidence trail. That is the part that is normally a consultant with a spreadsheet, and automating it is why this is sellable without us building a consultancy practice we do not want.
- Assessment and control mapping carried by a platform, not by billable hours.
- Operational evidence produced continuously by the SOC rather than assembled before an audit.
- Consultants for the judgement calls, which is the part that genuinely needs a person.
- One control set mapped across every framework you are held to, so answering one answers most of the next.
- An honest line: we prepare and evidence. Somebody independent certifies.
We do not certify you,
and we do not audit you.
Worth stating plainly, because the market is vague about it and the distinction matters when you are choosing a supplier.
Certification against a standard is awarded by an accredited certification body, and an audit is performed by somebody independent of the people who built the controls. We are neither. We get you ready, we produce and hold the evidence, and we sit with you through the process, which is a different and entirely legitimate job.
We also do not deliver Cyber Essentials. It is a fixed-fee certification sold at volume by accredited bodies, it is a UK-only scheme, and it is not what we are good at. If that is what you need, a certification body will do it better and cheaper than we would.
Anyone who tells you they can both build your controls and independently certify them is describing a conflict of interest, not a convenience.
Two things
we actually do here.
Deliberately narrow. These are the two where the operation behind us makes a real difference, rather than the full GRC catalogue.
Risk and compliance, answered.
Do you do GRC consultancy?
Not in the traditional sense, and we would rather say so. We do not sell six months of workshops and a document set. We run a platform that carries the assessment, mapping and evidence, and we put consultants on the judgement calls. If you want a classic GRC practice, other firms do that well.
Can you certify us to ISO 27001?
No. Certification is awarded by an accredited certification body, and a supplier who builds your controls should not also be the one certifying them. We prepare you, produce and hold the evidence, and support you through the audit. The certificate comes from someone independent.
Do you do Cyber Essentials?
No. It is a UK-only, fixed-fee certification sold at volume by accredited bodies, and they will do it better and cheaper than we would. We would rather point you at one than take work we are not the right home for.
What makes your evidence different?
It is produced by an operation that is already running rather than assembled before an audit. Incident records, investigation timelines, response actions and detection coverage exist because the SOC does the work, not because somebody went looking for proof in week eleven.
Do we have to use your SOC?
No, and the compliance work stands on its own. It is materially stronger where we also run detection and response, because then the operational evidence is a by-product rather than something you have to collect yourself. We will tell you which version you are buying.
Which frameworks do you work to?
ISO 27001, NIS2, DORA, SOC 2, NIST CSF, CIS, GDPR and the NCSC frameworks among others. Controls are mapped across frameworks rather than assessed separately, so most of the work of answering one framework answers the next.
Tell us who is asking
and what they want to see.
A regulator, a customer questionnaire or an insurer all want different evidence. Knowing which one is driving this makes the first conversation considerably shorter.