CUSTOMER PATHWAY
Governance and customer requirements
Customers ask for security evidence.

THE LOGIC
Address the cause.
Then build the capability.
Qualify the framework, organise evidence and separate preparation from certification.
A POSSIBLE SEQUENCE
Select the steps
that fit your situation.
The starting point, sequence and scope depend on existing controls and evidence. Services remain separately scoped.
01 / GRC-01
EBIOS Risk Manager risk assessment
A structured method linking business objectives to cyber-risk scenarios and a treatment plan decided by the organisation.
02 / GRC-03
ISO/IEC 27001 and ISMS implementation support
Establishing an information security management system: responsibilities, risks, controls, evidence and continual improvement, with optional certification preparation.
03 / GRC-06
Fractional CISO and cybersecurity governance
Recurring executive support to manage security risks, priorities, projects and decisions without immediately hiring a full-time CISO.
04 / GRC-07
Security policies, procedures and project governance
Defining understandable, enforceable rules for access, usage, operations and security decisions within projects.
05 / AUD-01
Cybersecurity maturity assessment
A review of practices, tools and responsibilities to decide what to secure first, rather than starting with a product purchase.
START A CONVERSATION
Let’s scope your route.
Bring the business objective, your current environment and the constraints. We will help define the next useful step.
