SERVICE 02 — CYBERSECURITY

Controls with evidence, not promises.

Security that leaves no evidence does not exist for an auditor. We implement and operate controls under ISO/IEC 27001 and related frameworks, with a file per control: what it protects, how it was tested and who approved it.

SCOPE

  • 01 Gap assessment against ISO/IEC 27001 and applicable regulation
  • 02 Risk analysis with a prioritized remediation matrix
  • 03 Hardening of servers, networks and applications
  • 04 Vulnerability management with verification cycles
  • 05 Incident-response playbooks and initial forensics

WHO IT IS FOR

SMBs that must demonstrate their security posture to corporate clients, banks or insurers to win and keep contracts.