Services · Information security

Governance, compliance and resilience of your IT environment

We deliver these services together with a contracted external partner and are happy to walk you through them in detail — an independent review of processes, controls and risks for management teams that need a clear picture of their information environment.

End-to-end information security governance — IT audit, GDPR, ISO 27001, ISO 22301, risk management and compliance

IT audit

We work with you to meet your audit objectives. These engagements can focus on different parts of your IT environment and the processes connected to it.

Business continuity management system

We help you identify the threats that affect your business, deliver your business continuity objectives, design a business continuity plan and disaster recovery procedures, and run continuity tests. We can also prepare you for compliance with ISO 22301.

Data protection – GDPR

To help you comply with the General Data Protection Regulation (GDPR) and other local legislation, we map the personal data lifecycle and carry out risk analysis and data protection impact assessments (DPIA).

IT risk management

We help you assess and manage IT risks so that you can concentrate on meeting your business objectives. Our services include reviews, maturity assessments and the creation of IT risk registers.

Diagnostic reviews

Our diagnostic analyses help you understand control weaknesses in your IT environment and improve your overall technology risk framework — from cyber security and data privacy to business continuity and data quality.

Legal and regulatory compliance

We advise and guide you on IT-related regulatory compliance, prioritising the identification and resolution of issues before they can cause harm.

Independent project assurance

We give management and project boards independent support in rolling out new systems and projects effectively, spotting deviations and reducing risks before they materialise.

IT due diligence

In mergers and acquisitions we provide in-depth analysis of the technology environment, helping boards and investors make well-informed decisions.

Reporting on controls at service organizations

We provide independent assurance over controls operated by service organizations, in line with standards such as AICPA SSAE18 or ISAE 3402/3000 (type 1 and type 2 reports).

Information security management system

We identify the threats and vulnerabilities in your physical and digital environment so that you can achieve compliance with ISO/IEC 27001 or lay solid foundations for information security.

Interested in any of these areas?

We would be glad to discuss your needs

Contact us