From the first gap assessment through certification, day-to-day operations and crisis response - one team accountable for the entire programme.
Every engagement starts with an honest, prioritised view of your current posture. No 200-page slide decks - just a clear plan with owners, dates and dollar values.
DPIAs, TIAs and PIAs for new products, vendors and cross-border data flows - built around your engineering reality.
Discuss thisExternal attack-surface and configuration scans, cookie & tracker audits, SSL/TLS reviews and dark-web monitoring.
Discuss thisHonest readiness reviews against GDPR, CCPA, ISO 27001, SOC 2, PCI DSS or your framework of choice.
Discuss thisA privacy or security programme isn't a project - it has a heartbeat. We design it, hand-hold it through certification, and stay on board to keep it healthy.
Lawful-basis mapping, RoPA, DPIAs, DSAR workflows, transfer mechanisms (SCCs/IDTAs/TIAs), DPO support and ICO engagement.
Consumer-rights pipelines, “Do Not Sell or Share” signals, sensitive-PI handling, service-provider agreements, CPPA readiness.
ISMS & PIMS design, Statement of Applicability, Annex A controls, internal audit, certification body liaison.
Trust Services Criteria mapping, control design and operating-effectiveness evidence, auditor-ready dataroom.
Scoping, SAQ / RoC support, ASV-scan readiness, segmentation reviews, customised-approach guidance.
ODPC registration, DPIAs, data-subject-rights, operator agreements and cross-border safeguards for Kenyan and pan-African operations.
Senior privacy and security leadership on retainer - fractional support that scales with your stage.
Our 24×7 incident-response retainer gives you a privacy lawyer, an analyst and a communications lead on a single call - with regulator-notification templates ready to file.
Embed privacy controls into product, data and engineering before they ship.
Plain-English privacy notices, internal policies and standards your teams will actually read.
A living RoPA that doesn’t need an annual panic to keep up to date.
One vendor inventory, one DPA template set, one renewal calendar.
Role-based training that moves the needle on behaviour - and stays evidenced.
Retainers, runbooks, regulator drafts and crisis-comms support.
Named officers for as long as you need them.
Tenancy hardening, IAM reviews, M365 & Google Workspace baselines.
Continuous visibility into your external posture and shadow assets.
Don't see your question? Ask us directly - usually a same-day reply.
For a mid-sized SaaS business we typically reach certification readiness in 12-16 weeks for ISO 27001 and 8-12 weeks for GDPR. We hit early wins inside the first month so the business feels progress straight away.
Yes - and we recommend it. We map GDPR, CCPA, ISO 27001, ISO 27701, SOC 2 and Kenya DPA onto a single control set so you don't pay for the same control five times.
Absolutely. Our virtual DPO and vCISO retainers give you a named officer, board reporting, regulator engagement and day-to-day decision support - at a fraction of the cost of a full-time hire.
Fixed-fee for defined programmes (assessment, certification readiness, incident response) and monthly retainers for ongoing operations. We share a clear scope and pricing in our first proposal - no surprises later.
Yes - the majority of our work is international, with clients across the EU, UK, US, Middle East and Asia-Pacific. We have local language and regulatory know-how across each major region.
30 minutes, no obligation. We will share a high-level plan you can take to your board the same week.