Skip to content

Cybersecurity · Governance, risk & compliance

Governance, risk & compliance. Security the board can steer.

Regulation keeps growing: NIS2 and GDPR in Europe, Ley 21.719 and the Framework Cybersecurity Law in Chile. We turn requirements into a working security programme, and give your board the reporting to steer it.

You get a clear view of your risks, a realistic roadmap to compliance and, if you want it, a senior security leader on call.

What's included. From policy to boardroom.

  • Compliance consulting

    ISO 27001, NIST, GDPR, PCI DSS, HIPAA, Ley 21.719 and Chile’s Economic Crimes Law.

  • Risk management

    Risk assessments and business impact analyses that set priorities.

  • Policies & procedures

    Security policies, procedures and codes of conduct that people actually follow.

  • Audit readiness

    Preparation and support for certification audits and regulators.

  • Data protection impact assessments

    DPIAs for new systems and new ways of processing personal data.

  • Third-party risk

    Security assessments of the vendors and suppliers you depend on.

  • Virtual CISO

    Senior security leadership on a retainer, including board reporting.

  • M&A and cyber insurance

    Cyber due diligence before an acquisition, and readiness for cyber insurance.

What you receive. Evidence, not paperwork.

Everything is written to be used: by the board to decide, by owners to act, and by auditors to verify.

  • Gap assessment

    Where you stand against the standard or regulation, in plain terms.

  • Risk register

    Every risk with an owner, a rating and a treatment.

  • Compliance roadmap

    Actions phased into 0–30, 30–90 and 90+ days.

  • Audit readiness

    An evidence pack, and support through the audit itself.

How it runs

Duration
Depends on the standard and your starting point. A gap assessment comes first, so the plan is realistic.
Team
GRC consultants and a senior lead, backed by our technical practices.
From you
Existing policies and documentation, and time with the key people for interviews.
Cadence
Steering meetings at an agreed rhythm, with progress reported against the roadmap.

Frameworks and laws

  • ISO 27001
  • NIS2
  • GDPR
  • NIST CSF
  • PCI DSS
  • DORA
  • Ley 21.719
  • Ley 21.663

Frequently asked questions

Can you get us ISO 27001 certified?

We prepare you and support you through the audit. The certificate itself is issued by an accredited certification body.

What is a virtual CISO?

A senior security leader who works for you part-time: setting strategy, reporting to the board and guiding your team, without a full-time hire.

Does NIS2 apply to us?

It depends on your sector and size. We start by confirming whether and how you are in scope, before recommending any work.

Do you cover Chilean regulation?

Yes, including Ley 21.719 on personal data and the Framework Cybersecurity Law, Ley 21.663.

Talk to a specialist

Make compliance work for you.

Tell us which standard or regulation you are facing.

Review build · draft copy
Base
Render