Advisory that spans compliance, risk, diplomacy and human behaviour.
We help organisations get and stay compliant against ISO/IEC 27001 and ISO/IEC 42001, with structured gap and risk assessments — complemented by advisory on cyber diplomacy and the human dimensions of security.

Compliance, risk, diplomacy and behavioural advisory
Compliance Advisory — ISO/IEC 27001
Readiness advisory for the Information Security Management System (ISMS) standard — policies, controls and documentation aligned to Annex A, through to certification support.
Discuss this serviceCompliance Advisory — ISO/IEC 42001
Readiness advisory for the AI Management System (AIMS) standard — governance, risk controls and lifecycle management for organisations building or deploying AI.
Discuss this serviceGap Assessment
A structured review of your current security or AI governance posture against the target standard, identifying gaps and prioritising remediation.
Discuss this serviceRisk Assessment & Advisory
Identification, analysis and treatment of information security and AI risk, with practical, prioritised advisory to close exposure.
Discuss this serviceCyberdiplomacy Advisory
Advisory on cyber norms, digital diplomacy and cross-border cooperation for governments, multilateral bodies and enterprises operating across jurisdictions.
Discuss this serviceCyberpsychology Advisory
Advisory on the human and behavioural dimensions of cybersecurity — insider risk, social engineering resilience and security culture design.
Discuss this serviceHow a typical engagement unfolds
Gap Assessment
Benchmark your current state against ISO/IEC 27001 or ISO/IEC 42001 requirements.
Risk Assessment
Identify, evaluate and prioritise information security and AI risk across your organisation.
Advisory & Remediation
Design the controls, policies and management-system documentation needed to close gaps.
Certification Readiness
Support through internal audit and external certification body assessment.
Advisory that starts with your people, not a template
Our consulting work runs as a conversation with the teams who will live with the controls — boards, engineers, compliance leads and, where it matters, the regulator. That is how a management system survives its first audit and its first incident.
Not sure where to start?
Book a complimentary 30-minute consultation with our advisory team.
