Cybersecurity · Governance, risk & compliance
Governance, risk & compliance. Security the board can steer.
Regulation keeps growing: NIS2 and GDPR in Europe, Ley 21.719 and the Framework Cybersecurity Law in Chile. We turn requirements into a working security programme, and give your board the reporting to steer it.
You get a clear view of your risks, a realistic roadmap to compliance and, if you want it, a senior security leader on call.
What's included. From policy to boardroom.
Compliance consulting
ISO 27001, NIST, GDPR, PCI DSS, HIPAA, Ley 21.719 and Chile’s Economic Crimes Law.
Risk management
Risk assessments and business impact analyses that set priorities.
Policies & procedures
Security policies, procedures and codes of conduct that people actually follow.
Audit readiness
Preparation and support for certification audits and regulators.
Data protection impact assessments
DPIAs for new systems and new ways of processing personal data.
Third-party risk
Security assessments of the vendors and suppliers you depend on.
Virtual CISO
Senior security leadership on a retainer, including board reporting.
M&A and cyber insurance
Cyber due diligence before an acquisition, and readiness for cyber insurance.
What you receive. Evidence, not paperwork.
Everything is written to be used: by the board to decide, by owners to act, and by auditors to verify.
Gap assessment
Where you stand against the standard or regulation, in plain terms.
Risk register
Every risk with an owner, a rating and a treatment.
Compliance roadmap
Actions phased into 0–30, 30–90 and 90+ days.
Audit readiness
An evidence pack, and support through the audit itself.
How it runs
- Duration
- Depends on the standard and your starting point. A gap assessment comes first, so the plan is realistic.
- Team
- GRC consultants and a senior lead, backed by our technical practices.
- From you
- Existing policies and documentation, and time with the key people for interviews.
- Cadence
- Steering meetings at an agreed rhythm, with progress reported against the roadmap.
Frameworks and laws
- ISO 27001
- NIS2
- GDPR
- NIST CSF
- PCI DSS
- DORA
- Ley 21.719
- Ley 21.663
Frequently asked questions
Can you get us ISO 27001 certified?
We prepare you and support you through the audit. The certificate itself is issued by an accredited certification body.
What is a virtual CISO?
A senior security leader who works for you part-time: setting strategy, reporting to the board and guiding your team, without a full-time hire.
Does NIS2 apply to us?
It depends on your sector and size. We start by confirming whether and how you are in scope, before recommending any work.
Do you cover Chilean regulation?
Yes, including Ley 21.719 on personal data and the Framework Cybersecurity Law, Ley 21.663.
Talk to a specialist
Make compliance work for you.
Tell us which standard or regulation you are facing.