Service
Security & compliance readiness
Security due diligence and audit readiness for ISO 27001, SOC 2 and Cyber Essentials — gap assessment, remediation and evidence, delivered by engineers.
What we do
We assess where you stand against the framework you need — ISO/IEC 27001, SOC 2 or Cyber Essentials — and then do the engineering that closes the gap: identity and access control, logging and retention, backup and recovery testing, change management, vendor review, secure development practice and incident response.
Most compliance work fails because it is written as policy and never implemented. We are engineers, so the control and the evidence for it get built at the same time.
Where certification comes from
We are not a certification body, and we will not tell you otherwise. ISO 27001 certificates are issued by accredited registrars; SOC 2 reports are issued by licensed CPA firms. Our job is to get you audit-ready, prepare the evidence, and sit beside you during the audit — not to mark your own homework.
What you get
- A gap assessment mapped control by control, with severity and effort
- A remediation plan that is costed, sequenced and owned
- The technical work delivered, not merely recommended
- An evidence pack structured the way an auditor expects
- Runbooks so the controls survive after we leave
Who it is for
Companies where a customer or investor has made certification a condition of the deal. Businesses handling sensitive data with no formal framework in place. Teams who failed a first audit and need the findings closed properly.