ISO 27001 · SOC 2 · PCI DSS Why you're here Who I am What you get Get in touch →

Certification, run end to end

Making controls work

Policies are the easy part. The work is designing controls that fit how your company already operates, putting them in place, gathering the evidence, and dealing with the auditor. I do all four, and I stay accountable through to the certificate.

Credentials

CISM · hundreds of engagements, first at PwC, then inside the businesses

Sectors

Banking, funds and trust · telecom · energy, utilities and mining · manufacturing and chemicals · retail · media · transport · intellectual property · public sector

Regimes

EMEA and US owned groups — SOX ITGC · ISA 315 · CSSF · DORA

W/P A-1 · Lead scheduleStatus · Open
Scope
01ISO 27001:2022
02SOC 2 Type 1 & Type 2
03PCI DSS
04GDPR · DORA
05Cloud, hybrid and on premise
Who does what
Prepared byCISM, ex PwC
EvidenceChased down across your teams
Follow upsAuditor's questions come to me
Your sideOne sponsor who opens doors
Reviewed byYour auditor, independently
Opinion
Audit opinion Certificate issued Signed off independently
AContext

You're probably here because

  • A customer sent you a security questionnaire and you don't want to answer it with guesses.
  • You've been told you need ISO 27001 or SOC 2 by a date somebody else picked, and nobody in house has done it before.
  • An enterprise deal is sitting on the certificate and every week it slips costs more than the programme does.
  • A consultant already wrote you the policies and you have since worked out that policies are not the hard part.
  • Your board asked how exposed you are and the honest answer was that nobody knows.
  • You're the one who has to fix it and you need a list that's ordered, not a 200 page tool export.
BBackground

Who you'd be working with

Most of this career was spent producing work that somebody else had to sign off: a group audit team, an external auditor, a regulator. That is a higher bar than an internal review, and it is still the bar the work is built to.

Both sides of the audit

Hundreds of engagements, first at PwC and then inside the businesses themselves: ITGC and SOX, SOC 1 and SOC 2, ISAE, PCI DSS, ISO 27001. Advisory work across retail, telecom, energy, utilities and mining, manufacturing, financial services and the public sector, in EMEA and in US owned and managed groups. Then the other side of it — accountable for every IT audit across a group, and taking companies from nothing to a signed certificate.

  • QualifiedCISM · Certified in Cybersecurity (ISC2) · MSc Computer Science · BSc Information Technology
  • PerspectiveAudit, advisory and in house, on the same controls
  • ScaleFrom a single SaaS tenant to a multi entity group

Jurisdictions, supervisors and frameworks

Work where the regulator, the external auditor and the client all end up reading the same working paper, and each of them is entitled to disagree with it. Nothing vague survives that room, so nothing vague gets written.

  • JurisdictionsUS · UK · UAE · Ireland · Luxembourg · Channel Islands · Cayman · BVI · Singapore · South Africa · Australia
  • SupervisorsFCA · JFSC · CSSF · CBI · MAS · PCAOB
  • AssuranceSOX · ISA 315 · ISAE 3402 · SSAE 18 · SOC 1 · SOC 2 · DORA
  • SecurityISO 27001:2013 and :2022 · PCI DSS · CMMC · NIST 800-53 · MITRE ATT&CK

Not every environment is a clean cloud tenant

Certification tooling assumes AWS, a single identity provider and everything in one place. Real companies have on premise servers, inherited databases, an ERP nobody wants to touch and a network that grew rather than got designed. Those environments still certify. They just need somebody who has audited them.

  • Cloud: AWS, Azure, GCP
  • Identity: Entra ID, Active Directory, Okta
  • On premise and hybrid infrastructure
  • Enterprise applications and their IT dependencies

Most of your auditor's questions are ones I have asked myself, under the same standards. That removes the part of an engagement usually spent working out what they are looking for.

CServices

What you can buy

Three ways in. Fixed price agreed before anything starts.

End to end · accountable for the outcome

Turnkey compliance

You need the certificate. Not a folder of policies, not a gap report, not advice. I take the whole programme from wherever you are now through to the auditor signing off, and I stay accountable for it the entire way.

  • The processes get built, not just described. Controls designed around how your teams already work, then implemented.
  • The evidence gets collected. I chase the screenshots, exports and approvals, including from teams and systems I have no access to.
  • I am the auditor's point of contact. Their questions come to me, not to your engineers mid sprint.
  • The work is coordinated across your organisation, so it does not stall every time it needs something from another team.
Talk about your certification → ISO 27001:2022 · SOC 2 · PCI DSS · GDPR · DORA — fixed price, agreed up front

Advisory work is cheap to sell and easy to walk away from. This is the opposite arrangement: a fixed scope, a named date, and my name on the outcome. If the audit turns up something unexpected, it is my problem to solve.

Most requested · fixed price

Microsoft 365 security assessment

Your tenant reviewed the way an auditor reviews it, against the CISA ScubaGear baselines plus the manual checks automated tools miss. You get every gap, what it puts at risk, and the fix, in the order to do them.

  • Every finding with the risk in plain terms and the specific setting to change.
  • Remediation ordered by impact and effort, so week one is obvious.
  • Mapped to ISO 27001, NIST and CIS, so it feeds straight into your certification work.
  • A call to walk your team through it, included.
Get your tenant reviewed → Fixed price · report within two weeks

ScubaGear is free and published by CISA — anyone can run it, and you should. The assessment is about what the output means: which findings your auditor will care about, which are noise in your setup, and what order to fix them in.

Already have a team

Readiness review

You have people doing the work and you want to know whether it will hold up. A straight read on where you stand, so the audit produces no surprises. If it turns out you need more than a review, the turnkey option is there.

  • Where you stand against the standard, without hedging.
  • A fix list ordered by what the audit will actually test, not by what's easy.
  • Your evidence reviewed before it leaves the building.
Check where you stand → Fixed price, scoped on a call
DProcess

How it goes

You tell me what's going on

Thirty minutes, no charge. The environment, the deadline, who is asking for the certificate. I tell you straight if it isn't worth doing.

You get a plan and a price, in writing

Scope, milestones, what I need from your side, dates and cost. Nothing open ended, and no invoice that grows on its own.

I run it, you get the certificate

Controls built, evidence gathered, auditor handled. You hear from me on progress, not on every request I could have chased myself.

On a turnkey programme I need one sponsor inside your organisation who can open doors. Everything else I can carry.

EDeliverable

Your board reads page one. Your engineers read the rest.

Every finding is written up, ranked, and paired with the change that closes it, rather than pasted in as a tool export. A sanitised sample is available on request.

  • 01Executive summary, one page
  • 02Scope and how it was tested
  • 03Findings: what, why it matters, the fix, the priority
  • 04Remediation plan in running order
  • 05Mapping to ISO 27001, NIST and CIS
FExample

Controls, start to finish

Two controls taken end to end, at the same depth a programme gets. Free to read, no signup.

Privileged access

Nobody should have standing access to production. Including you.

The most common finding in this kind of work, and the first thing an enterprise customer asks about. What a working version looks like without slowing your engineers down, how it gets tested, and the five places it tends to break.

GContact

Not sure which one you need?

Tell me the situation in a couple of lines. If it's not something I should be doing, I'll say so and point you somewhere better.

Thirty minutes · no charge · no obligation