A policy that has never been exercised does not reach daily operations
Compliance gap assessment, security governance and tiered training
Passing an audit and running an effective security programme are different things. We assess and close gaps against MLPS 2.0, ISO/IEC 27001, GDPR and third-party risk, build the governance system and a GRC operating rhythm, and deliver awareness, secure development and SOC drill training, so policy is executed day to day and the audit is a by-product.
Our approach
One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.
One assessment, several standards
MLPS, ISO 27001 and GDPR controls overlap heavily. The assessment runs once across a unified control set and maps results to each standard's clauses, avoiding repeated interviews and evidence collection.
Governance built around an operating rhythm
Delivery includes meeting cadence, metrics, internal audit and a remediation loop, with our team alongside for the first quarter, so someone is running the system beyond the documents.
Training by role, verified by exercise
Executives, managers, developers and operators get different courses. Each ends with a phishing simulation, code audit or SOC drill, with results on record.
Deliverables
Compliance gap report
Gaps, risk levels and remediation by control domain, mapped to each standard, with effort estimates.
Governance documents and operating rhythm
Organisation, policy, process and metrics, with GRC platform configuration and first-quarter operating records.
Training plan and records
Tiered courses, phishing simulations and SOC drills with records and evaluation data.
How we deliver
Four stages, each with defined inputs, outputs and a client sign-off.
Scope and standards
Applicable standards, assessment scope and interviewees.
Gap assessment
Document review, interviews, technical checks; gap report delivered.
System build and remediation
Policy drafting, GRC go-live, remediation tracking.
Training and audit readiness
Tiered training, exercises, internal audit and certification support.
Frequently asked questions
Notes on scope, execution and delivery standards. Contact us for anything not covered here.
MLPS evaluation is performed by a licensed evaluation body that issues the report. We provide the pre-evaluation gap assessment, remediation and documentation, and post-evaluation fixes; we do not replace the evaluation body.
Start from where you stand
Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.