Service line · GRC
A governance foundation your clients, auditors and insurers accept
From assessment to evidence: policies mapped to NIST CSF, ISO 27001, CIS Controls and LGPD, delivered with the adoption plan, the training and the processes to put them into practice.
- CEOs and CTOs of technology companies
- Mid-market under compliance pressure
- SaaS selling to enterprise clients
Offers
Five products, from first assessment to continuous evidence
Every offer has a defined scope, deliverables and duration. The posture assessment is the recommended starting point.
- Start here
Security Posture Assessment
Structured assessment of assets, processes, business objectives and risks, with a maturity snapshot against NIST CSF and CIS Controls.
- Assessment report and risk register
- Maturity scorecard
- Costed 12-month roadmap
- Executive readout
3–4 weeks
GRC Baseline Sprint: zero to governed
The governance foundation for companies with no formal programme: 15–20 policies referencing NIST CSF, ISO 27001, LGPD and CIS Controls.
- Policy set and control matrix
- Processes, roles and responsibilities
- Implementation plan + staff briefing
2–3 months
ISO 27001 Readiness
Gap analysis against Annex A, ISMS documentation, risk methodology, Statement of Applicability and internal-audit preparation.
- Readiness and implementation support
- Certification-body liaison preparation
3–6 months (part-time)
LGPD Security Compliance Package
The security side of LGPD: data-protection policies and controls, security measures documentation (Art. 46+) and incident-response readiness.
- Data-protection policies and controls
- Vendor security requirements
4–8 weeks
Questionnaires & Compliance Evidence
Credible answers to enterprise security questionnaires and a reusable evidence library, so each questionnaire stops being a fire drill.
- Evidence library (policies, attestations, architecture)
- Audit-ready training records
Retainer add-on