You have an audit, a finding, or an incident.
This is the practice we have been in longest, and the reason clients trust us with the AI work. It is well-made and current — SOC 2 and ISO 27001 readiness, second-line operating models, incident response you have actually rehearsed, and the capability programmes that build the next cohort.
The same discipline, pointed at a newer problem.
Twenty years of assessing, auditing and challenging systems is what makes the AI work credible — and the two practices share a single question. What data does this touch, where must it never go, who approves what, and how would we know if it went wrong?
If you arrived here with a supervisory finding or an incident, that is the work in front of us and we will not use it as an excuse to sell you something else. If you arrived here because AI is now in the risk register, the two conversations are the same conversation.
A defensible security story, evidenced rather than asserted.
Boards and regulators expect a risk-based strategy, governance with real teeth, controls that are evidenced, and reporting that translates technical posture into business language. Most organisations have fragments. Few have the full picture — and almost none have discovered which parts are aspirational until they were tested for real.
- Cybersecurity strategy and 18–36 month roadmaps aligned to NIST CSF 2.0, ISO 27001, MAS TRM, the Singapore Cybersecurity Act and equivalent African frameworks.
- SOC 2 Type I and Type II readiness assessments and pre-audit remediation.
- ISO 27001 ISMS design, scoping and implementation support.
- Cyber maturity assessments benchmarked against peer institutions.
- Second Line of Defence operating model design — RCSA, KRIs, issue and action tracking.
- Security governance: committee charters, RACI, escalation pathways, board reporting packs.
- Technology risk reporting frameworks for boards and regulators.
Finding out which parts were aspirational — before someone else does.
An incident response plan nobody has run is a document, not a capability. These engagements exist to find the gap between the two while it is still cheap to find.
- Cyber resilience simulations and ransomware tabletop exercises for executive teams.
- Incident response playbook design and stress-testing.
- Crisis communication protocols, including regulator and customer notification.
- Board-level crisis decision-making exercises.
- Ransomware decision frameworks — pay/don’t-pay, legal, sanctions.
- Post-incident reviews and lessons-learned facilitation.
- Resilience reviews aligned to regulators’ operational resilience expectations.
Building the next cohort, not just the current posture.
Capability programmes fail in predictable ways: curriculum written to a vendor’s certification path, a range nobody integrates into teaching, graduates the market does not hire. This work is about the architecture that avoids that.
- Cyber academy advisory — strategy, governance model, partnership architecture, sustainability planning.
- Curriculum design for cyber skills programmes at entry, intermediate and executive levels.
- Cyber range requirements specification and curriculum integration.
- Workforce capability mapping (NICE Framework, SFIA, regional equivalents).
- Executive education for boards and audit committees.
- Train-the-trainer programmes for in-country instructor development.
Typical deliverables
Strategy and posture
Cyber strategy paper · maturity heatmap · technology risk reporting framework · board reporting templates.
Audit readiness
SOC 2 readiness gap report · ISMS scope and Statement of Applicability · evidence library structure.
Second line
RCSA workbook · KRI definitions · issue and action tracking design · committee charters and RACI.
Incident readiness
Tabletop design and after-action report · refreshed incident response playbook · crisis communication templates · post-incident review.
Capability
Academy strategy paper · curriculum architecture · cyber range requirements specification · capability map.
Where this work usually starts
A supervisory finding
A regulator or auditor has raised something and the response needs to be credible, evidenced and quick.
An audit on the horizon
First SOC 2 or ISO 27001, and nobody is sure how far off ready actually is.
A function being rebuilt
A new CISO or CIO inheriting fragments, needing a defensible plan and a second line that works.
An incident just happened
You want an independent post-mortem rather than an internal one, and a playbook that reflects what actually occurred.
Never exercised under pressure
An executive team with a plan on paper and no idea how it behaves at 2am.
Building national capability
Universities, skills bodies and development partners designing programmes that have to produce hireable graduates.
Start with what’s actually in front of you.
A 30-minute call, no charge. If the answer is that you need an auditor rather than an advisor, you’ll get that too.
