Services / 02

Security Consulting

Maturity assessments, threat and risk assessments (STRA / SOAR) and compliance readiness against ISO 27001, SOC 2 and NIST CSF 2.0. Written for the people who have to act on it.

MATURITYSTRA / SOARISO 27001
Overview

What the practice does.

Most security programs do not fail for lack of controls. They fail because nobody can say, in one page, where the organization stands, what the real risks are, and what to do first.

We assess against a framework you choose, in your language, and leave you with a prioritised roadmap, a risk register your leadership will read, and the evidence an auditor will accept.

What you get

Deliverables.

Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.

01

Maturity assessment

Current state scored against NIST CSF 2.0, ISO 27001:2022 or CIS Controls, with a target state agreed with leadership and the gap between the two sequenced into a roadmap.

02

Threat and risk assessment (STRA / SOAR)

Security threat and risk assessments and statements of acceptable risk for systems, projects and vendors, in the structure public sector and healthcare organizations expect.

03

Compliance readiness

Gap analysis, control mapping and evidence planning for ISO 27001 and SOC 2, with a realistic path to the audit date rather than a template policy pack.

04

Policies and standards

Policies your teams will actually follow: short, mapped to controls, with the standards and procedures that make them operational.

05

Board and executive reporting

A one-page position, a risk register in business terms, and the budget case for what comes next.

How it runs

The four steps, applied.

The method is the same for every practice. This is what each step means here.

01 / SCOPE

Framework, systems in scope, stakeholders and the decisions the assessment needs to support, agreed before interviews begin.

02 / TEST

Document review, interviews and technical sampling. We check that controls operate, not just that they are written down.

03 / VERIFY

Every rating is backed by evidence a second consultant reviews. Disagreements are resolved before you see the draft.

04 / REPORT

Scores, gaps, risk register and roadmap, with a readout for executives and a working session for the team that owns the fixes.

When to call us

The situations this is built for.

You need to answer a framework question honestly

A customer, regulator or board has asked where you stand against ISO 27001, SOC 2 or NIST CSF 2.0, and the honest answer is that nobody has checked.

A system or project needs a signed STRA

Public sector and healthcare organizations need threat and risk assessments and statements of acceptable risk completed to a standard, on a schedule, by someone independent.

An audit date is set

Certification or attestation is on the calendar and the gap between policy and practice has not been measured.

Questions

Asked before most engagements.

Which frameworks do you work with?

ISO 27001:2022, SOC 2, NIST CSF 2.0, CIS Controls, and the public sector security standards used in British Columbia and across Canada. If you have a customer questionnaire or a contract schedule instead of a framework, we map to that.

Do you write policies?

Yes, and we keep them short. Policies are mapped to the controls they satisfy and paired with the standards and procedures that make them real.

Can you help us get certified?

We run readiness, remediation planning and the internal audit. We do not act as your certification body; independence matters to us and to your auditor.

How is this different from a fractional CISO?

Consulting delivers a defined assessment or document set. A fractional CISO runs the program over time. Many clients start with an assessment and continue with a fractional CISO who owns the roadmap.

Request a quote

Tell us what you need tested, assessed or governed.

A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.

Start on Frontier Verify