Skip to content
CyberSmithSECURE
Under Attack

Services

Governance, Risk & Compliance

Twenty services, one consistent way of thinking about assurance: understand the requirement, understand the risk, implement the control, and prove that it works.

01 / 13

ISO 27001

Building an ISMS that functions as an operating system for information security, rather than as a folder of documents produced for an audit.

Everything in this service

Gap assessment, ISMS implementation, ISO 27002:2022 control alignment, internal audit and readiness, certification support and annual maintenance — entered at whichever stage matches your maturity.

  • Business-aligned ISMS scoped around objectives, assets and real operating practice

  • Risk-led control design rather than a one-size-fits-all checklist

  • Audit-ready evidence organised to demonstrate operation, not just intent

  • Governance cadence and management visibility that outlast the certificate

02 / 13

ISO 27701

Privacy Information Management System implementation and privacy governance.

Everything in this service

Discover data, identify processing, assess privacy risk, map controls, implement, validate, improve — extending an existing ISO/IEC 27001 ISMS rather than standing a second management system beside it.

  • Personal data inventory and data processing mapping before any control is chosen

  • Privacy governance framework, roles, policies and procedures

  • Processor and controller governance, and privacy control implementation

  • Privacy Management Framework and a privacy readiness assessment report

03 / 13

ISO 42001

AI Management System and AI governance implementation.

Everything in this service

Identify AI, classify use cases, assess risk, define controls, implement governance, validate, monitor. Delivered against the ISO/IEC 42001 AI Governance Control Framework.

  • AI system inventory and use-case classification before any control is chosen

  • AI risk assessment, policies, and roles and responsibilities

  • Lifecycle, vendor and incident governance, with human oversight defined rather than assumed

  • AI Management and Governance Framework, plus a readiness report

04 / 13

GDPR

CyberSmithSECURE helps organisations assess and establish governance aligned with GDPR requirements.

Everything in this service

Discover, map data, identify obligations, assess gaps, implement controls, validate evidence — using the CSS Privacy Toolkit and a Privacy Impact Assessment methodology aligned to ISO/IEC 27701.

  • Personal data inventory, data flow mapping and records of processing activities

  • Data subject rights, consent, retention and deletion governance

  • Data protection by design, processor management and cross-border transfer governance

  • GDPR compliance gap assessment report and a compliance roadmap

05 / 13

DPDPA

Practical governance for personal-data processing under India's Digital Personal Data Protection Act.

Everything in this service

Identify data, map flows, identify processing, determine obligations, assess gaps, implement, validate, monitor — across data governance, consent governance, data principal rights, organisational governance, and risk and assurance.

  • Consent governed as a lifecycle: collection, records, withdrawal, notices and the consent manager

  • Data principal rights workflows for access, correction, erasure and grievances

  • Data fiduciary and processor governance, cross-border transfers and breach governance

  • DPDPA compliance gap assessment report and a compliance roadmap

06 / 13

NIST CSF

Assessment and improvement of cybersecurity governance using the NIST CSF lifecycle.

Everything in this service

Identify, Protect, Detect, Respond, Recover — assessed against the framework's own functions, with current state and target state defined separately so the gap between them is the deliverable.

  • Current-state assessment and target-state definition, kept distinct

  • Cybersecurity function assessment with control and practice mapping

  • Gap identification and risk prioritisation rather than a maturity score alone

  • NIST CSF assessment report and a cybersecurity improvement roadmap

07 / 13

NIST SP 800-53

Control assessment and security governance aligned with NIST SP 800-53.

Everything in this service

Scope, map controls, assess, validate, gaps, remediate — against the control baseline that actually applies, established during scoping rather than assumed.

  • Control applicability settled first, because 800-53 is a catalog and not a checklist

  • Control implementation review kept separate from control effectiveness

  • Evidence review against each assessed control

  • Control assessment report and a control gap / remediation matrix

08 / 13

SOC 2

SOC 2 readiness and control assessment against applicable Trust Services Criteria.

Everything in this service

Scope, TSC mapping, assess, validate, gaps, readiness. Readiness and control assurance — the report itself is issued by a licensed CPA firm.

  • Which Trust Services Criteria apply is scoped, not defaulted

  • System description review and control owner mapping

  • Evidence review against each criterion, with remediation tracked to close

  • SOC 2 readiness assessment report and a control and evidence matrix

09 / 13

PCI DSS

Payment-card security governance and compliance assessment.

Everything in this service

Scope, requirements, assess, evidence, gap, remediation — worked through the CSS PCI DSS assessment checklist.

  • Scope identification first, because scope is what determines the cost of everything after it

  • Requirement assessment, control review and evidence assessment

  • Gap identification with remediation planning, not just a finding list

  • PCI DSS gap assessment report and a remediation matrix

10 / 13

HIPAA

Security and privacy compliance assessment for organisations subject to HIPAA requirements.

Everything in this service

Scope, risk assessment, safeguard assessment, evidence validation, gap identification, remediation — against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule.

  • Administrative, physical and technical safeguards assessed separately

  • Privacy governance review and risk assessment

  • Incident and breach governance, and business associate governance

  • HIPAA assessment report and a HIPAA remediation roadmap

11 / 13

Assurance & Risk

Where you actually stand against a standard, a regulation or a framework — established independently rather than self-reported.

Everything in this service

Gap assessment against a defined standard, internal audit, risk assessment, and third-party risk across vendors, suppliers and service providers. Four distinct engagements rather than one bundled review, because they answer different questions and get commissioned at different times.

  • Scope, requirement mapping, evidence collection, control assessment, gap identification, risk prioritisation

  • Internal audit run to the standard's own clauses, producing findings an external auditor will recognise

  • Third-party risk across vendors, suppliers and service providers: identify, classify, assess, validate

  • A Gap Assessment Report and a prioritised remediation roadmap, not a list of observations

12 / 13

Business Resilience

What happens when something stops working, and whether the plan for it has ever been tested.

Everything in this service

Business impact analysis to establish what disruption actually costs, continuity plans built on those findings, and mock tests that exercise them. Aligned to ISO 22301 principles.

  • Identify processes, map dependencies, assess impact, determine recovery requirements, prioritise

  • Continuity plans built from the business impact analysis rather than from a template

  • Mock tests, so resilience is exercised rather than documented

  • A Business Impact Analysis Report and a critical process and recovery requirements matrix

13 / 13

vCISO

Security leadership as a service — strategy, board engagement and programme ownership, from a team rather than a single hire.

Everything in this service

Assess, prioritise, strategise, govern, execute through teams, measure, report, improve. The vCISO provides governance and oversight of security operations, incident governance and programme management, and does not necessarily perform the underlying technical operations.

  • Cybersecurity strategy and a prioritised roadmap, not a list of tools to buy

  • Monthly executive security governance report written for a board, not a console

  • Oversight across vulnerability, incident, monitoring, endpoint, IAM, cloud, backup and awareness

  • Incident escalation, crisis coordination, post-incident review and corrective action tracking

Kits

The toolkits behind these services

The documentation sets our own consultants work from, free to download.

Free toolkit

Business Continuity Toolkit

An ISO 22301 business continuity management set following the standard's clauses 4 to 10, with the operational forms a continuity programme runs on — business impact analysis, recovery objective analysis, incident impact logs, response action logs and post-incident reports.

83 documents · ZIP · 20.5 MB

Download the toolkit

Free toolkit

ISO 27001 Toolkit

A complete ISO/IEC 27001:2022 documentation set, arranged the way the standard is: clauses 4 to 10 for the management system, then the four Annex A control families — organizational, people, physical and technological. Includes the implementation resources, policies, procedures and records an ISMS needs to reach certification.

310 documents · ZIP · 40.8 MB

Download the toolkit

Free toolkit

GDPR Compliance Toolkit

Ten structured workstreams covering a GDPR programme end to end — preparation, roles and training, personal data mapping, privacy notices, data subject rights, controller and processor obligations, DPIAs, international transfers and personal data breach management.

65 documents · ZIP · 12.1 MB

Download the toolkit