Governance, Risk & Compliance

Compliance & Audit

Compliance frameworks deliver the most value when they form the foundation of a well-architected security program, not a checklist. Our team holds ISO/IEC 27001 Lead Auditor certification and critical-infrastructure audit experience, so we know what auditors look for and how to build programs that hold up in practice.

How We Help

ISO/IEC 27001

ITSG-33 Security Assessment

ISO/IEC 27001

Gap assessments, ISMS design, internal audits and certification readiness.

NERC CIP

ITSG-33 Security Assessment

ISO/IEC 27001

Readiness assessments, program development and evidence practices for the CIP standards.

ITSG-33 Security Assessment

ITSG-33 Security Assessment

Threat, Risk & Privacy Assessments

Security control assessments and security assessment and authorization (SA&A) support aligned with Government of Canada guidance.

Threat, Risk & Privacy Assessments

Threat, Risk & Privacy Assessments

Threat, Risk & Privacy Assessments

TRAs, harmonized TRAs and privacy impact assessments aligned with PIPEDA and PHIPA that turn risks into prioritized, defensible decisions.

PCI-DSS & Cloud Controls

Threat, Risk & Privacy Assessments

Policies & Third-Party Risk

PCI-DSS readiness and cloud control reviews based on the CSA Cloud Controls Matrix.

Policies & Third-Party Risk

Threat, Risk & Privacy Assessments

Policies & Third-Party Risk

Security policies and standards people can actually follow, plus vendor assessments and security requirements for procurement and RFPs.

Ready to strengthen your compliance program?

Tell us about your audit, assessment or certification goals.