Build it. Operate it. Verify it. Advise on it.
Our work is organised around the ISMS lifecycle. Four pillars, four propositions, four entry points. Pick the one that matches the decision you're trying to make — or read across.
Most clients enter at one pillar and grow into the next. There's no required order — only the one that makes sense for where you are right now.
PILLAR 01 BUILD
Build it
A working ISMS, in the environment you already run.
Start here when
You're heading into a first ISO 27001 audit, or your current ISMS is held together with shared spreadsheets.
PILLAR 02 OPERATE
Operate it
Run the ISMS with us, not for us, not without us.
Start here when
You're certified, but the ISMS is a part-time job for someone whose actual job is something else.
PILLAR 03 VERIFY
Verify it
Independent assurance the controls actually work.
Start here when
Your board, a regulator, or a major customer is asking for evidence — and you need it from someone who isn't the team that built the controls.
PILLAR 04 ADVISE
Advise it
Trusted counsel for the decisions that move budget.
Start here when
A decision is sitting on the board agenda and the room doesn't have the right voice in it.
PILLAR 01
Build it.
A productised path to ISO 27001 / 42001 certification, delivered inside the Microsoft environment you already pay for.
Microsoft-centric organisations (typically 20–200 staff) pursuing first-time certification, or replacing a manual ISMS that has quietly stopped working.
→
SharePoint ISMS platform
Built by lead auditors, designed around what auditors actually want to see.
→
Three implementation tiers
DIY, guided, or full-build. The same destination at three speeds.
→
Video training library
On-demand, role-based. So your people don't read a policy once and forget it.
→
Certification readiness review
A fixed-scope sweep before you book the auditor.
Engagement Implementation project
Typical length 8–16 weeks
What you take away A certifiable ISMS and the platform it runs on.
What it isn't
Not a custom build. Not consulting by the hour. The point is repeatability — a known path with known timelines.
PILLAR 02
Operate it.
We run the ISMS alongside your team. Specialist capacity and continuity that's hard to keep on staff, paired with a client who stays accountable.
Certified organisations — ours or otherwise — with a nominated internal ISMS owner who needs expert support, not a full-replacement contractor.
→
Operational cadence
Quarterly or half-yearly — control reviews, risk register updates, evidence curation.
→
Management review
Prepared and facilitated, not just attended.
→
Audit preparation
Surveillance and recertification, with the auditor's eye already in the room.
→
Supplier assessment
Triaged, scored, escalated only when the answer matters.
→
Policy cycles
Reviewed and updated on the cadence regulators expect.
→
Awareness training
Delivered, not just licensed.
→
Incident response coordination
When the page goes off, we pick up.
→
ISMS coaching
For your nominated owner — because the audit will ask them, not us.
Engagement Recurring retainer
Typical commitment 12–36 months
What you take away An ISMS that stays current — without the cost of a full in-house team.
What it isn't
Not outsourcing. Outsourcing makes the ISMS invisible to the business and collapses the day the contract ends. Co-sourced keeps you accountable while we do the heavy lifting.
PILLAR 03
Verify it.
Independent verification that controls are designed well, operating effectively, and meeting the obligations that matter to your board, regulators, and customers.
Mid-market and above. Regulated industries. Organisations with board-level reporting requirements.
→
Internal audit
ISO 27001, 9001, 42001, integrated.
→
Gap assessments
Pre-certification or pre-acquisition.
→
Essential 8 maturity reviews
Pragmatic, not aspirational.
→
ISO readiness reviews
Stage 1 dry runs, with findings written for the room they'll be read in.
→
Third-party risk assessments
On suppliers that genuinely move the needle.
→
Penetration testing
Partner-delivered. We manage scope, triage, and the report your board reads.
Engagement Defined-scope project, or multi-year audit programme
Typical length 2–8 weeks per cycle
What you take away A report you can put in front of your board, your regulator, or a customer.
What it isn't
Not strategic interpretation of findings — that belongs in Advise. Verify is independent assessment against defined criteria, and stays there to protect the independence claim.
PILLAR 04
Advise it.
Trusted advisor to executives and boards on cyber, AI, and information governance posture. Strategy, not seat-warming.
Boards. Audit and risk committees. CEOs, CIOs, CISOs. The people whose decisions actually move budget.
→
Board posture assessments
Using our proprietary maturity index.
→
Virtual / fractional CISO
An ex-CISO in your senior leadership rhythm.
→
AI governance advisory
ISO 42001 strategic positioning, board AI literacy.
→
Regulatory readiness
APRA CPS 234, SOCI Act, Privacy Act reforms, EU AI Act exposure.
→
M&A due diligence
Cyber and AI, on the deal clock.
→
Strategy facilitation
Security strategy, AI strategy, GRC operating model.
Engagement Retainer, fractional appointment, or fixed-scope advisory
Typical length Single session through to multi-year
What you take away Decisions made, not options mapped.
What it isn't
Not operational delivery (that's Operate). Not control verification (that's Verify). Strategic advisory without that discipline becomes anything-we-feel-like-doing — and we'd rather be useful than busy.
A NOTE ON
Co-sourced
Outsourcing makes the ISMS invisible to the business and collapses the day the contract ends.
Co-sourced keeps you accountable while we provide the heavy lifting, specialist judgement, and continuity. It's also a more honest description of how ISO management systems must work — the client must demonstrate ownership to auditors. We can't do that for you, and wouldn't pretend to.
On Verify engagements: different team members deliver Operate vs. any independent verification work for the same client. Documented separation of duties.
If you're not sure which pillar you're in, start with the question you're trying to answer.
"We need to be certified."
Pillar 01 · Build
Productised ISO 27001 / 42001 implementation, in your Microsoft tenant.
"We're certified, but it's a part-time job for someone overloaded."
Pillar 02 · Operate
Co-sourced operation. We run the cadence with your nominated owner.
"Our board / regulator / largest customer wants independent assurance."
Pillar 03 · Verify
Internal audit, gap assessment, or pen-test programme. Defined scope, independent voice.
"There's a decision sitting on the board agenda we can't resolve."
Pillar 04 · Advise
Board posture review, vCISO retainer, or strategic facilitation. Senior-only delivery.
Tell us where you are. We'll tell you the smallest piece of work that moves you forward — and which pillar it lives in.