Security leadership for growing companies in Japan

Audits, enterprise security questionnaires, and a security program that holds up — without hiring a full-time security manager.

Hi, I’m William Hollis.

I work full time as an information security manager at a technology company in Tokyo. ISO 27001, PrivacyMark, risk management, customer security reviews, incident response — that is my job, every week, not a subject I studied once.

I started EverydayGRC because most growing companies don’t need a large consulting firm. They need one experienced person who will take responsibility for security and see it through.

Most companies don’t call because they “need GRC”

They call because something changed.

1

A customer asked whether you’re ISO 27001 certified

The deal is moving, the answer is no, and nobody is sure how long certification actually takes.

2

Procurement sent a 200-question security review

It landed with an engineer who has other work to do, and the answers need to be consistent with what you said last time.

3

Leadership realised nobody actually owns security

There are policies and tools. There is no one whose job it is to decide what happens next.

4

An audit is coming and the evidence isn’t ready

The internal audit hasn’t been done, the risk register is out of date, and the certification body has a date booked.

5

Growth has outpaced the controls you set up

What worked at fifteen people doesn’t work at eighty, and the gap is starting to show up in customer questions.

How I Help

Nobody owns security at your company

I become your security lead on a fractional basis — running risk reviews, handling audits and customer questionnaires, working with your engineers, and reporting to your leadership. Ongoing responsibility, not scheduled advice.

Fractional Information Security Manager — the main way I work with companies.

Learn more

You need to pass an ISO 27001 or PrivacyMark audit

Certification without months of documentation nobody reads. I own the evidence, the auditor communication, and the corrective actions — and build a system your team can actually keep running afterwards.

ISO 27001 and JIS Q 15001 (P-Mark) can be aligned into one management system to cut duplication.

Learn more

Enterprise customers keep sending security questionnaires

I answer them, build a reusable answer library so the same questions stop costing you a week, and pull in engineering only where a real answer requires it.

Learn more

You need an internal audit before certification

ISO 27001 and PrivacyMark both require one, and it has to be independent. Fixed scope, fixed fee, and a findings report you can act on before the certification body arrives.

Fixed fee from ¥250,000. A straightforward way to work together once before committing to anything ongoing.

Learn more
Understanding the Business
Identifying Risks & Gaps
Prioritizing What Matters
Driving Implementation
Owning the Outcome
EverydayGRC Logo

How Security Actually Gets Done

A lot of engagements end with a report. You get a list of findings, a bill, and no clear idea what happens Monday.

I’d rather stay involved. If we find a problem, I’ll help you decide whether it’s worth fixing now, work it through with the people who have to implement it, and keep track of it until it’s closed.

Security only creates value when the improvements actually happen. Everything else is paperwork.

See How I Work

Why EverydayGRC?

Most consultants spend their week consulting. I spend mine running a security program.

So what you get isn’t drawn from a case study or a framework I read once. It comes from problems I am working through right now, in a real company, with auditors who ask hard questions and engineers who push back when something is impractical. When I tell you an approach works, it’s because I’ve had to make it work.

It’s also where the name comes from. Governance, risk, and compliance get treated as projects — something you do before an audit and revisit once a year. Risk doesn’t work that way, and neither do customer expectations. Good governance is something a company does every day, or it isn’t governance.

Not sure whether this is a fit?

The first conversation is informal. We’ll talk about where you are now, what you’re trying to achieve, and whether I’m the right person to help.

If I’m not, I’ll tell you.

Discuss Your Situation