EverydayGRC Services
Most consultants deliver a report and leave. I'd rather stay until security is part of how your company operates.
Fractional Information Security Manager
You get a security lead. Not a set of recommendations about hiring one.
Most companies hit a point where the security work never really stops — but it still doesn't add up to a full-time salary. This is the answer to that. I become the person whose job it is to know the state of your security, decide what happens next, and make sure it happens.
In practice that means I coordinate your audits, run your risk reviews, answer the enterprise security questionnaires, sit down with your engineers, keep documentation current, track remediation to closure, and report where things stand to your leadership. The point is that security stops being everybody's second priority.
Includes:
- I coordinate your certification and surveillance audits, and deal with the auditors directly
- I run risk assessments, and bring the decisions that need a human owner to your leadership
- I answer enterprise security questionnaires and build a reusable answer library, so they stop costing a week each
- I keep policies, records, and evidence current — instead of rebuilding them the month before an audit
- I work with your engineers on what is actually implementable, and track remediation until it is closed
- I report security posture to your executives in language they can act on
Internal Audit as a Service
A fixed-scope internal audit against ISO 27001 or PrivacyMark (JIS Q 15001) — the internal audit both standards require before certification and surveillance.
Internal audits are a mandatory part of ISO 27001 and PrivacyMark. Many teams either don't have an independent person to run one, or want a second set of eyes that mirrors the rigor of the external audit without the pressure. This is a defined, fixed-fee engagement: a structured review of your policies, processes, and controls, followed by a clear findings report you can act on before the certification body arrives.
Includes:
- Independent internal audit against the chosen standard
- Review of policies, processes, and control implementation
- Nonconformity and observation findings, prioritized
- Clear, auditor-aligned report with corrective-action guidance
- Available in English or Japanese
Over 100 employees, or a complex scope, we'll agree a fee before anything starts. The integrated audit covers both standards in one engagement, which is meaningfully cheaper than running them separately if you already operate an integrated management system.
Getting PrivacyMark Certified
If a Japanese customer has asked whether you hold PrivacyMark, this is the process that gets you there.
PrivacyMark is a common requirement for companies operating in Japan, particularly in B2B contexts involving personal information. Engagements cover the full process: understanding the standard, building the documentation, establishing internal processes, and managing the certification and ongoing compliance.
Includes:
- P-Mark requirements review and gap analysis
- Personal information management system design
- Policy and procedure development
- Internal audit planning and execution
- Certification application and audit support
ISO 27001, From Start to Certification
Certification is very achievable. Most of the pain comes from doing it in the wrong order.
ISO 27001 certification is achievable without months of excessive documentation or a process that overwhelms internal teams. The focus is on building a management system that auditors accept and that the organization can actually operate and maintain.
Where relevant, ISO 27001 and JIS Q 15001 (P-Mark) can be aligned to reduce duplication and simplify ongoing operations.
Includes:
- Gap analysis against ISO 27001 requirements
- Implementation guidance and hands-on support
- Policy and documentation development
- Internal audit planning and execution
- Certification audit management and support
How Security Actually Gets Done
Many engagements stop after identifying problems. A report is delivered, and internal teams are left with a long list of findings and no clear path forward. The focus here is not just identifying problems. It's taking ownership of the outcome.
Understanding the Business
Architecture, stakeholders, regulatory and customer requirements.
Identifying Risks and Gaps
Controls, compliance gaps, operational risks.
Prioritizing What Matters
Business impact, likelihood, effort.
Driving Implementation
Solution decisions, architecture review, policy and governance leadership.
Owning the Outcome
Progress tracking, audit management, ongoing program leadership.
When I’m probably not the right fit
It’s cheaper for both of us to find this out now.
Look elsewhere if:
- You want policies written and delivered, with no involvement after that. Templates are cheaper than I am and will do the same job.
- You want the certificate but not the management system behind it. Surveillance audits happen every year, and that approach falls apart at the first one.
- You need a team of twenty consultants on site. I’m one person — that’s the point, but it does have limits.
- You need someone reachable at any hour on short notice. I work with a small number of clients so the ones I have get real attention.