An evidence-based review of your controls, ending in a prioritised roadmap.
- Banks & SACCOs
- Fintechs
- NGOs
- Public sector
- Education
- Timeline
- 2–6 weeks
- Delivery
- On-site or remote
- Access
- Read-only
What we review
- Governance & policy
- Identity & access
- Network & perimeter
- Endpoints & patching
- Cloud & SaaS
- Data protection
- Backup & continuity
- Incident readiness
How it works
- 01
Scope
Objectives, framework and systems agreed. NDA signed.
- 02
Review
Policies, registers and prior reports checked against the framework.
- 03
Verify
Interviews and read-only checks confirm controls actually work.
- 04
Report
Risk-rated findings and a roadmap, walked through with your team.
What you get
- Executive summary with domain maturity ratings
- Findings register with evidence and owners
- Control gap analysis against your framework
- Prioritised 30/60/90-day roadmap
Aligned to
- ISO/IEC 27001:2022
- NIST CSF 2.0
- CIS Controls v8
- Uganda DPPA 2019
For reference only; no certification implied. Timelines are confirmed in your quote.
Get a fixed quote
Free scoping call. We reply within one business day.