Skip to main content

A policy that has never been exercised does not reach daily operations

Compliance gap assessment, security governance and tiered training

Passing an audit and running an effective security programme are different things. We assess and close gaps against MLPS 2.0, ISO/IEC 27001, GDPR and third-party risk, build the governance system and a GRC operating rhythm, and deliver awareness, secure development and SOC drill training, so policy is executed day to day and the audit is a by-product.

Our approach

One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.

01

One assessment, several standards

MLPS, ISO 27001 and GDPR controls overlap heavily. The assessment runs once across a unified control set and maps results to each standard's clauses, avoiding repeated interviews and evidence collection.

02

Governance built around an operating rhythm

Delivery includes meeting cadence, metrics, internal audit and a remediation loop, with our team alongside for the first quarter, so someone is running the system beyond the documents.

03

Training by role, verified by exercise

Executives, managers, developers and operators get different courses. Each ends with a phishing simulation, code audit or SOC drill, with results on record.

Deliverables

01

Compliance gap report

Gaps, risk levels and remediation by control domain, mapped to each standard, with effort estimates.

02

Governance documents and operating rhythm

Organisation, policy, process and metrics, with GRC platform configuration and first-quarter operating records.

03

Training plan and records

Tiered courses, phishing simulations and SOC drills with records and evaluation data.

How we deliver

Four stages, each with defined inputs, outputs and a client sign-off.

01Week 1

Scope and standards

Applicable standards, assessment scope and interviewees.

02Weeks 2–5

Gap assessment

Document review, interviews, technical checks; gap report delivered.

032–4 months

System build and remediation

Policy drafting, GRC go-live, remediation tracking.

04Per plan

Training and audit readiness

Tiered training, exercises, internal audit and certification support.

Frequently asked questions

Notes on scope, execution and delivery standards. Contact us for anything not covered here.

MLPS evaluation is performed by a licensed evaluation body that issues the report. We provide the pre-evaluation gap assessment, remediation and documentation, and post-evaluation fixes; we do not replace the evaluation body.

Start from where you stand

Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.