Assurance

Cybersecurity and resilience

Governance, secure-by-design, software compliance, risk assessment, privacy and operational continuity.

The question that orders the work

What an auditor has to be able to re-check a year from now. That changes the order of things: first establish which evidence must exist and where it lives, then put in the controls that produce it, and only at the end write the documentation, which by then describes something that exists instead of promising something that will.

On resilience

The measure is not the plan, it is the rehearsal: how long recovery actually takes, who can do it without reading the manual, and when it was last tried. An untested plan is a document.

What the client is left holding

The list of evidence with where it lives and who produces it, the controls in place, and the record of what was tested and with what result. Not a certificate: the material an auditor works from.

How it can be checked

An outside auditor walks the path without asking us for anything: they start from the list of evidence, open the control that produces it, and find in the register the date of the last test and its outcome. A step that exists only because we say so is not evidence.

This is one of the areas of Consulting.

Start a conversation