About William

I’m William Hollis, an information security manager based in Tokyo.

During the week I lead information security for a technology company here — ISO 27001 and PrivacyMark governance, risk management, customer security reviews, incident response, vendor assessments, and the executive reporting that goes with all of it.

I started EverydayGRC because I kept running into the same problem from the other side of the table. Growing companies were being asked to meet enterprise security expectations by their customers, but couldn’t justify a full-time security manager and couldn’t afford a large consulting firm. So the work fell to whoever had capacity that week, which usually meant it didn’t get done properly.

That’s the gap this exists to fill.

What I do day to day

The point of saying this isn’t the job title. It’s that the problems you’re bringing me are problems I’m also working on this month:

  • ISO 27001 and PrivacyMark governance, including running the two as a single integrated management system
  • Risk assessment, risk acceptance, and getting executives to actually make the decision
  • Internal audits, management reviews, and certification audits
  • Enterprise customer security questionnaires and vendor reviews
  • Incident response process and vulnerability management
  • Policy architecture, document control, and security awareness training

None of that is theoretical for me, which is the main thing I’d want you to take from this page.

How I think about this work

I don’t think security exists to produce paperwork. It exists to help a company earn trust, reduce the risks that would actually hurt it, and keep growing without tripping over itself. Compliance is one useful outcome of a well-run security program. It isn’t the goal.

In practice that means preferring things that work in your environment over things that look correct in a framework, and preferring a control your team will follow over a stricter one they’ll quietly ignore. An auditor can’t tell the difference on paper. Everyone else can.

Why work with me

  • I own outcomes. I don’t hand over a report and disappear. I help move things from “identified” to “implemented,” which is the part that usually stalls.
  • Advice grounded in current practice. I’m running a security program right now, so what I recommend is shaped by what auditors and enterprise customers are asking for this year.
  • Japan and international, both. I work with Japanese and international stakeholders regularly and can run an engagement in either English or Japanese — documentation, audits, and the conversations in between.
  • Small enough to care. You get me. Not a partner who sold the work and an analyst who delivers it.
William Hollis, EverydayGRC
William Hollis
EverydayGRC

“The best security programs aren’t the ones with the most documentation. They’re the ones people actually follow.”

Company Profile

Business Details

Business name
EVERYDAYGRC
Representative
William Hollis
Established
2025
Structure
Sole proprietorship (個人事業主), registered in Japan
Location
Saitama Prefecture, Japan
Coverage
Engagements are primarily remote. On-site visits available in the greater Tokyo area.
Services
Fractional information security management, ISO 27001 and PrivacyMark (JIS Q 15001) support, internal audit, enterprise security questionnaire response
Languages
English / Japanese
Qualified Invoice Issuer Registration No.
T4810003803981

Want to know if this is a fit?

The first conversation is informal — where you are now, what you’re trying to achieve, and whether I’m the right person to help. If I’m not, I’ll tell you.

Discuss Your Situation