Security leadership for growing companies in Japan
Audits, enterprise security questionnaires, and a security program that holds up — without hiring a full-time security manager.
Hi, I’m William Hollis.
I work full time as an information security manager at a technology company in Tokyo. ISO 27001, PrivacyMark, risk management, customer security reviews, incident response — that is my job, every week, not a subject I studied once.
I started EverydayGRC because most growing companies don’t need a large consulting firm. They need one experienced person who will take responsibility for security and see it through.
Most companies don’t call because they “need GRC”
They call because something changed.
A customer asked whether you’re ISO 27001 certified
The deal is moving, the answer is no, and nobody is sure how long certification actually takes.
Procurement sent a 200-question security review
It landed with an engineer who has other work to do, and the answers need to be consistent with what you said last time.
Leadership realised nobody actually owns security
There are policies and tools. There is no one whose job it is to decide what happens next.
An audit is coming and the evidence isn’t ready
The internal audit hasn’t been done, the risk register is out of date, and the certification body has a date booked.
Growth has outpaced the controls you set up
What worked at fifteen people doesn’t work at eighty, and the gap is starting to show up in customer questions.
How I Help
Nobody owns security at your company
I become your security lead on a fractional basis — running risk reviews, handling audits and customer questionnaires, working with your engineers, and reporting to your leadership. Ongoing responsibility, not scheduled advice.
Fractional Information Security Manager — the main way I work with companies.
Learn moreYou need to pass an ISO 27001 or PrivacyMark audit
Certification without months of documentation nobody reads. I own the evidence, the auditor communication, and the corrective actions — and build a system your team can actually keep running afterwards.
ISO 27001 and JIS Q 15001 (P-Mark) can be aligned into one management system to cut duplication.
Learn moreEnterprise customers keep sending security questionnaires
I answer them, build a reusable answer library so the same questions stop costing you a week, and pull in engineering only where a real answer requires it.
Learn moreYou need an internal audit before certification
ISO 27001 and PrivacyMark both require one, and it has to be independent. Fixed scope, fixed fee, and a findings report you can act on before the certification body arrives.
Fixed fee from ¥250,000. A straightforward way to work together once before committing to anything ongoing.
Learn more
Why EverydayGRC?
Most consultants spend their week consulting. I spend mine running a security program.
So what you get isn’t drawn from a case study or a framework I read once. It comes from problems I am working through right now, in a real company, with auditors who ask hard questions and engineers who push back when something is impractical. When I tell you an approach works, it’s because I’ve had to make it work.
It’s also where the name comes from. Governance, risk, and compliance get treated as projects — something you do before an audit and revisit once a year. Risk doesn’t work that way, and neither do customer expectations. Good governance is something a company does every day, or it isn’t governance.