Services
Governance, Risk & Compliance
Twenty services, one consistent way of thinking about assurance: understand the requirement, understand the risk, implement the control, and prove that it works.
ISO 27001
Building an ISMS that functions as an operating system for information security, rather than as a folder of documents produced for an audit.
- Gap Assessment
- Policy & Documentation
- ISMS Implementation
- Control Alignment
- Certification Support
- Annual Maintenance
Gap assessment, ISMS implementation, ISO 27002:2022 control alignment, internal audit and readiness, certification support and annual maintenance — entered at whichever stage matches your maturity.
Business-aligned ISMS scoped around objectives, assets and real operating practice
Risk-led control design rather than a one-size-fits-all checklist
Audit-ready evidence organised to demonstrate operation, not just intent
Governance cadence and management visibility that outlast the certificate
ISO 27701
Privacy Information Management System implementation and privacy governance.
Everything in this serviceDiscover data, identify processing, assess privacy risk, map controls, implement, validate, improve — extending an existing ISO/IEC 27001 ISMS rather than standing a second management system beside it.
Personal data inventory and data processing mapping before any control is chosen
Privacy governance framework, roles, policies and procedures
Processor and controller governance, and privacy control implementation
Privacy Management Framework and a privacy readiness assessment report
Identify AI, classify use cases, assess risk, define controls, implement governance, validate, monitor. Delivered against the ISO/IEC 42001 AI Governance Control Framework.
AI system inventory and use-case classification before any control is chosen
AI risk assessment, policies, and roles and responsibilities
Lifecycle, vendor and incident governance, with human oversight defined rather than assumed
AI Management and Governance Framework, plus a readiness report
GDPR
CyberSmithSECURE helps organisations assess and establish governance aligned with GDPR requirements.
Everything in this serviceDiscover, map data, identify obligations, assess gaps, implement controls, validate evidence — using the CSS Privacy Toolkit and a Privacy Impact Assessment methodology aligned to ISO/IEC 27701.
Personal data inventory, data flow mapping and records of processing activities
Data subject rights, consent, retention and deletion governance
Data protection by design, processor management and cross-border transfer governance
GDPR compliance gap assessment report and a compliance roadmap
DPDPA
Practical governance for personal-data processing under India's Digital Personal Data Protection Act.
Everything in this serviceIdentify data, map flows, identify processing, determine obligations, assess gaps, implement, validate, monitor — across data governance, consent governance, data principal rights, organisational governance, and risk and assurance.
Consent governed as a lifecycle: collection, records, withdrawal, notices and the consent manager
Data principal rights workflows for access, correction, erasure and grievances
Data fiduciary and processor governance, cross-border transfers and breach governance
DPDPA compliance gap assessment report and a compliance roadmap
NIST CSF
Assessment and improvement of cybersecurity governance using the NIST CSF lifecycle.
Everything in this serviceIdentify, Protect, Detect, Respond, Recover — assessed against the framework's own functions, with current state and target state defined separately so the gap between them is the deliverable.
Current-state assessment and target-state definition, kept distinct
Cybersecurity function assessment with control and practice mapping
Gap identification and risk prioritisation rather than a maturity score alone
NIST CSF assessment report and a cybersecurity improvement roadmap
NIST SP 800-53
Control assessment and security governance aligned with NIST SP 800-53.
Everything in this serviceScope, map controls, assess, validate, gaps, remediate — against the control baseline that actually applies, established during scoping rather than assumed.
Control applicability settled first, because 800-53 is a catalog and not a checklist
Control implementation review kept separate from control effectiveness
Evidence review against each assessed control
Control assessment report and a control gap / remediation matrix
SOC 2
SOC 2 readiness and control assessment against applicable Trust Services Criteria.
Everything in this serviceScope, TSC mapping, assess, validate, gaps, readiness. Readiness and control assurance — the report itself is issued by a licensed CPA firm.
Which Trust Services Criteria apply is scoped, not defaulted
System description review and control owner mapping
Evidence review against each criterion, with remediation tracked to close
SOC 2 readiness assessment report and a control and evidence matrix
Scope, requirements, assess, evidence, gap, remediation — worked through the CSS PCI DSS assessment checklist.
Scope identification first, because scope is what determines the cost of everything after it
Requirement assessment, control review and evidence assessment
Gap identification with remediation planning, not just a finding list
PCI DSS gap assessment report and a remediation matrix
HIPAA
Security and privacy compliance assessment for organisations subject to HIPAA requirements.
Everything in this serviceScope, risk assessment, safeguard assessment, evidence validation, gap identification, remediation — against the HIPAA Privacy Rule, Security Rule and Breach Notification Rule.
Administrative, physical and technical safeguards assessed separately
Privacy governance review and risk assessment
Incident and breach governance, and business associate governance
HIPAA assessment report and a HIPAA remediation roadmap
Assurance & Risk
Where you actually stand against a standard, a regulation or a framework — established independently rather than self-reported.
Everything in this serviceGap assessment against a defined standard, internal audit, risk assessment, and third-party risk across vendors, suppliers and service providers. Four distinct engagements rather than one bundled review, because they answer different questions and get commissioned at different times.
Scope, requirement mapping, evidence collection, control assessment, gap identification, risk prioritisation
Internal audit run to the standard's own clauses, producing findings an external auditor will recognise
Third-party risk across vendors, suppliers and service providers: identify, classify, assess, validate
A Gap Assessment Report and a prioritised remediation roadmap, not a list of observations
Business Resilience
What happens when something stops working, and whether the plan for it has ever been tested.
Everything in this serviceBusiness impact analysis to establish what disruption actually costs, continuity plans built on those findings, and mock tests that exercise them. Aligned to ISO 22301 principles.
Identify processes, map dependencies, assess impact, determine recovery requirements, prioritise
Continuity plans built from the business impact analysis rather than from a template
Mock tests, so resilience is exercised rather than documented
A Business Impact Analysis Report and a critical process and recovery requirements matrix
vCISO
Security leadership as a service — strategy, board engagement and programme ownership, from a team rather than a single hire.
Everything in this serviceAssess, prioritise, strategise, govern, execute through teams, measure, report, improve. The vCISO provides governance and oversight of security operations, incident governance and programme management, and does not necessarily perform the underlying technical operations.
Cybersecurity strategy and a prioritised roadmap, not a list of tools to buy
Monthly executive security governance report written for a board, not a console
Oversight across vulnerability, incident, monitoring, endpoint, IAM, cloud, backup and awareness
Incident escalation, crisis coordination, post-incident review and corrective action tracking
Kits
The toolkits behind these services
The documentation sets our own consultants work from, free to download.
Free toolkit
Business Continuity Toolkit
An ISO 22301 business continuity management set following the standard's clauses 4 to 10, with the operational forms a continuity programme runs on — business impact analysis, recovery objective analysis, incident impact logs, response action logs and post-incident reports.
83 documents · ZIP · 20.5 MB
Download the toolkitFree toolkit
ISO 27001 Toolkit
A complete ISO/IEC 27001:2022 documentation set, arranged the way the standard is: clauses 4 to 10 for the management system, then the four Annex A control families — organizational, people, physical and technological. Includes the implementation resources, policies, procedures and records an ISMS needs to reach certification.
310 documents · ZIP · 40.8 MB
Download the toolkitFree toolkit
GDPR Compliance Toolkit
Ten structured workstreams covering a GDPR programme end to end — preparation, roles and training, personal data mapping, privacy notices, data subject rights, controller and processor obligations, DPIAs, international transfers and personal data breach management.
65 documents · ZIP · 12.1 MB
Download the toolkit