IT Governance’s cyber security consultancy services are delivered by a team of experienced in-house consultants who have a deep understanding of the range of cyber risks facing organisations today, helping you implement the best possible security solutions for your budget and requirements.
Our services can be tailored for organisations of all sizes in any industry and location.
ISO 27001 consultancy
ISO 27001 is the international standard that describes best practice for an ISMS (information security management system). It is globally recognised as the most comprehensive solution to achieving an enhanced cyber security posture.
We’ve helped more than 400 organisations achieve accredited certification to the Standard, and we can provide implementation support to suit every budget or timescale, wherever you are in the world. From fixed-price packages to bespoke consultancy, we can supply everything you need to implement an ISO 27001-compliant ISMS in your organisation.
Find out more about our ISO 27001 consultancy services >>
Cyber health check
The three-phase cyber health check combines on-site consultancy and audit with remote vulnerability assessments to assess your cyber risk exposure. Our four-step approach will identify your actual cyber risks, audit the effectiveness of your responses to those risks, analyse your real risk exposure and then create a prioritised action plan for managing those risks in line with your business objectives.
Find out more about our cyber health check service >>
NCSC certified cyber security consultancy scheme
The NCSC (National Cyber Security Centre)’s CCSC (Certified Cyber Security Consultancy) scheme is primarily aimed at public-sector organisations that have to use a government-approved procurement framework to purchase or acquire security services, and at private-sector organisations that have to provide assurance that the services they provide are secure.
There are currently four CCSC categories, and we offer consultancy services related to three:
Find out more about the NCSC CCSC scheme >>
The UK government’s G-Cloud framework makes it faster and cheaper for the public sector to buy Cloud services. Suppliers are approved by the Crown Commercial Service (CCS) via the G-Cloud application process, eliminating the need for a full tender process for each buyer.
IT Governance has been approved to provide six cyber security services via the government’s Digital Marketplace for Cloud support.
Find out more about our G-Cloud consultancy services >>
SOC audits based on ISAE 3402 and SSAE 16
A Service Organization Controls (SOC) audit is often a prerequisite for service organisations to partner with or provide services to tier-one organisations in the supply chain. SSAE 16 and ISAE 3402 have replaced SAS-70 as the new global standards for assurance reporting for service organisations. Many organisations that have undergone an SAS 70 in the past will now require a SOC 2 Type II report.
IT Governance can provide assistance throughout the entire SOC preparation, remediation, testing and reporting process.
Find out more about SOC audits based on ISAE 3402 and SSAE 16 >>
Cyber incident response management
The speed at which you identify a breach, combat the spread of malware, prevent unauthorised access to data, and remediate the threat will make a significant difference in controlling risk, costs and exposure during an incident. Effective incident response processes can reduce the risk of future incidents occurring.
With an effective incident response plan, you will be able to detect incidents at an earlier stage and develop an effective defence against the attack.
IT Governance's cyber security incident response consultancy service is based on ISO 27001, ISO 27035 (the international standard for cyber incident response) and best-practice frameworks developed by CREST. It can help you develop the resilience to protect against, remediate and recover from a wide range of cyber incidents.
Find out more about cyber incident response management >>
Why choose IT Governance?
IT Governance has a wealth of experience in the cyber security and risk management field. As part of our work with hundreds of private and public organisations in all industries, we have been carrying out detailed risk assessments for more than ten years. All our consultants are qualified, experienced practitioners.