Certification, run end to end
Policies are the easy part. The work is designing controls that fit how your company already operates, putting them in place, gathering the evidence, and dealing with the auditor. I do all four, and I stay accountable through to the certificate.
CISM · hundreds of engagements, first at PwC, then inside the businesses
Banking, funds and trust · telecom · energy, utilities and mining · manufacturing and chemicals · retail · media · transport · intellectual property · public sector
EMEA and US owned groups — SOX ITGC · ISA 315 · CSSF · DORA
Most of this career was spent producing work that somebody else had to sign off: a group audit team, an external auditor, a regulator. That is a higher bar than an internal review, and it is still the bar the work is built to.
Hundreds of engagements, first at PwC and then inside the businesses themselves: ITGC and SOX, SOC 1 and SOC 2, ISAE, PCI DSS, ISO 27001. Advisory work across retail, telecom, energy, utilities and mining, manufacturing, financial services and the public sector, in EMEA and in US owned and managed groups. Then the other side of it — accountable for every IT audit across a group, and taking companies from nothing to a signed certificate.
Work where the regulator, the external auditor and the client all end up reading the same working paper, and each of them is entitled to disagree with it. Nothing vague survives that room, so nothing vague gets written.
Certification tooling assumes AWS, a single identity provider and everything in one place. Real companies have on premise servers, inherited databases, an ERP nobody wants to touch and a network that grew rather than got designed. Those environments still certify. They just need somebody who has audited them.
Most of your auditor's questions are ones I have asked myself, under the same standards. That removes the part of an engagement usually spent working out what they are looking for.
Three ways in. Fixed price agreed before anything starts.
End to end · accountable for the outcome
You need the certificate. Not a folder of policies, not a gap report, not advice. I take the whole programme from wherever you are now through to the auditor signing off, and I stay accountable for it the entire way.
Advisory work is cheap to sell and easy to walk away from. This is the opposite arrangement: a fixed scope, a named date, and my name on the outcome. If the audit turns up something unexpected, it is my problem to solve.
Most requested · fixed price
Your tenant reviewed the way an auditor reviews it, against the CISA ScubaGear baselines plus the manual checks automated tools miss. You get every gap, what it puts at risk, and the fix, in the order to do them.
ScubaGear is free and published by CISA — anyone can run it, and you should. The assessment is about what the output means: which findings your auditor will care about, which are noise in your setup, and what order to fix them in.
Already have a team
You have people doing the work and you want to know whether it will hold up. A straight read on where you stand, so the audit produces no surprises. If it turns out you need more than a review, the turnkey option is there.
Thirty minutes, no charge. The environment, the deadline, who is asking for the certificate. I tell you straight if it isn't worth doing.
Scope, milestones, what I need from your side, dates and cost. Nothing open ended, and no invoice that grows on its own.
Controls built, evidence gathered, auditor handled. You hear from me on progress, not on every request I could have chased myself.
On a turnkey programme I need one sponsor inside your organisation who can open doors. Everything else I can carry.
Every finding is written up, ranked, and paired with the change that closes it, rather than pasted in as a tool export. A sanitised sample is available on request.
Two controls taken end to end, at the same depth a programme gets. Free to read, no signup.
Privileged access
The most common finding in this kind of work, and the first thing an enterprise customer asks about. What a working version looks like without slowing your engineers down, how it gets tested, and the five places it tends to break.
Tell me the situation in a couple of lines. If it's not something I should be doing, I'll say so and point you somewhere better.