EverydayGRC Services

Most consultants deliver a report and leave. I'd rather stay until security is part of how your company operates.

Flagship Engagement

Fractional Information Security Manager

You get a security lead. Not a set of recommendations about hiring one.

Most companies hit a point where the security work never really stops — but it still doesn't add up to a full-time salary. This is the answer to that. I become the person whose job it is to know the state of your security, decide what happens next, and make sure it happens.

In practice that means I coordinate your audits, run your risk reviews, answer the enterprise security questionnaires, sit down with your engineers, keep documentation current, track remediation to closure, and report where things stand to your leadership. The point is that security stops being everybody's second priority.

Includes:

  • I coordinate your certification and surveillance audits, and deal with the auditors directly
  • I run risk assessments, and bring the decisions that need a human owner to your leadership
  • I answer enterprise security questionnaires and build a reusable answer library, so they stop costing a week each
  • I keep policies, records, and evidence current — instead of rebuilding them the month before an audit
  • I work with your engineers on what is actually implementable, and track remediation until it is closed
  • I report security posture to your executives in language they can act on
Discuss Your Situation
Fixed-Fee Offering

Internal Audit as a Service

A fixed-scope internal audit against ISO 27001 or PrivacyMark (JIS Q 15001) — the internal audit both standards require before certification and surveillance.

Internal audits are a mandatory part of ISO 27001 and PrivacyMark. Many teams either don't have an independent person to run one, or want a second set of eyes that mirrors the rigor of the external audit without the pressure. This is a defined, fixed-fee engagement: a structured review of your policies, processes, and controls, followed by a clear findings report you can act on before the certification body arrives.

Includes:

  • Independent internal audit against the chosen standard
  • Review of policies, processes, and control implementation
  • Nonconformity and observation findings, prioritized
  • Clear, auditor-aligned report with corrective-action guidance
  • Available in English or Japanese
Single standard (ISO 27001 or P-Mark) · under 30 employees from ¥250,000
Single standard (ISO 27001 or P-Mark) · 30–100 employees from ¥350,000

Over 100 employees, or a complex scope, we'll agree a fee before anything starts. The integrated audit covers both standards in one engagement, which is meaningfully cheaper than running them separately if you already operate an integrated management system.

Request an Internal Audit

Getting PrivacyMark Certified

If a Japanese customer has asked whether you hold PrivacyMark, this is the process that gets you there.

PrivacyMark is a common requirement for companies operating in Japan, particularly in B2B contexts involving personal information. Engagements cover the full process: understanding the standard, building the documentation, establishing internal processes, and managing the certification and ongoing compliance.

Includes:

  • P-Mark requirements review and gap analysis
  • Personal information management system design
  • Policy and procedure development
  • Internal audit planning and execution
  • Certification application and audit support
Talk About P-Mark

ISO 27001, From Start to Certification

Certification is very achievable. Most of the pain comes from doing it in the wrong order.

ISO 27001 certification is achievable without months of excessive documentation or a process that overwhelms internal teams. The focus is on building a management system that auditors accept and that the organization can actually operate and maintain.

Where relevant, ISO 27001 and JIS Q 15001 (P-Mark) can be aligned to reduce duplication and simplify ongoing operations.

Includes:

  • Gap analysis against ISO 27001 requirements
  • Implementation guidance and hands-on support
  • Policy and documentation development
  • Internal audit planning and execution
  • Certification audit management and support
Talk About ISO 27001

How Security Actually Gets Done

Many engagements stop after identifying problems. A report is delivered, and internal teams are left with a long list of findings and no clear path forward. The focus here is not just identifying problems. It's taking ownership of the outcome.

1

Understanding the Business

Architecture, stakeholders, regulatory and customer requirements.

2

Identifying Risks and Gaps

Controls, compliance gaps, operational risks.

3

Prioritizing What Matters

Business impact, likelihood, effort.

4

Driving Implementation

Solution decisions, architecture review, policy and governance leadership.

5

Owning the Outcome

Progress tracking, audit management, ongoing program leadership.

When I’m probably not the right fit

It’s cheaper for both of us to find this out now.

Look elsewhere if:

  • You want policies written and delivered, with no involvement after that. Templates are cheaper than I am and will do the same job.
  • You want the certificate but not the management system behind it. Surveillance audits happen every year, and that approach falls apart at the first one.
  • You need a team of twenty consultants on site. I’m one person — that’s the point, but it does have limits.
  • You need someone reachable at any hour on short notice. I work with a small number of clients so the ones I have get real attention.

Not sure which fits your situation?

Every company is different. The first conversation is just about understanding where you are today, what you're trying to accomplish, and whether I'm actually the right person to help. If I'm not, I'll tell you — and I'll point you at whoever is.

Discuss Your Situation