Know exactly where you stand
A gap assessment against the audit your customers are asking for, with gaps ranked by effort and risk. No guessing.
A big customer wants proof you take security seriously, like an audit report or a certification, and suddenly a deal depends on something nobody on the team has done before. I’ve taken an IT department through two major security certifications at the same time, and wrote the policies both audits required. I’ll tell you what matters for a team your size, build controls that fit how you really work, and get you to audit day with confidence.
A gap assessment against the audit your customers are asking for, with gaps ranked by effort and risk. No guessing.
What’s in scope and a realistic plan, so you can tell a prospect when to expect your report.
Right-sized policies and the technical controls behind them: access reviews, MFA, device management, logging, backups, and vendor risk.
Evidence collection, auditor walkthroughs, and a straight answer when the auditor asks the hard questions.
I get you ready. The audit itself is done by an independent firm. My job is to make sure you pass, and that everything keeps working after the auditor leaves.
Usually whichever your customers ask for. In the US that’s most often SOC 2; in Europe and with global enterprises, ISO 27001 is common. They overlap a lot, so doing one makes the next much easier.
Most small teams need a few months to get ready. Some audits also check how your controls run over a period of time, often three to twelve months. The gap assessment gives you a realistic timeline.
Not always, but for most small teams a tool like Vanta or Drata saves real time collecting evidence. I’ll help you decide, and set it up properly if you go that route.
Yes, and it often should. Many controls — access reviews, device management, backups — are exactly what fractional IT management keeps running month to month.
A free 30-minute call. Tell me what’s keeping you up at night, and you’ll leave with a clear next step, whether or not we work together.