Program Add-ons

Extend your GRC program with add-ons designed to help you hit your security objectives.

Explore our add-ons below.

Designed for Outcomes

Our Program Add-ons focus on the most critical aspects of any security program, allowing you to focus on the things that matter the most.

Internal Audit

Independent, structured verification of the organisation's control environment.

Learn More →
Audit Assist

Targeted readiness and remediation support in the lead-up to a formal external audit.

Learn More →
Extended Risk & Review

Maintains ongoing hygiene across risk, user access, and vendor management.

Learn More →
Tabletop Exercise

A facilitated, scenario-based simulation designed to test incident response readiness.

Learn More →
Third-Party Risk

Structured, evidence-based assessments of key suppliers.

Learn More →
Security Responses

Handles inbound and outbound security enquiries on behalf of the client.

Learn More →
Internal Audit

Our Internal Audit service provides an independent, structured verification of your organisation's control environment as mandated by ISO 27001 and similar standards. We conduct structured stakeholder interviews to validate control operations and thoroughly review all provided evidence. You will receive a formal internal audit report documenting findings, observations, and actionable recommendations.

  • Develop a comprehensive internal audit plan and schedule
  • Conduct structured stakeholder interviews to validate controls
  • Deliver a formal internal audit report with actionable recommendations
Get Started

Our Service Guarantee:

Provide an independent verification of the control environment as required by the compliance framework.

Our Internal Audit Includes:

Audit Planning Evidence Review Audit Reporting
Audit Assist

Audit Assist provides targeted readiness and remediation support in the lead-up to your formal external audit. We identify compliance gaps through structured assessments and develop Corrective and Preventive Action (CAPA) plans to ensure your evidence set is complete. Our team will also organise audit materials and provide on-call support while the auditor is assessing your organisation.

  • Conduct a structured readiness assessment to identify gaps
  • Provide prioritised remediation guidance and CAPA development
  • Manage audit coordination and provide external audit support
Get Started

Our Service Guarantee:

Identify compliance gaps and provide targeted support to address them prior to a formal external audit.

Our Audit Assist Includes:

Readiness Assessment Remediation Support Audit Coordination
Extended Risk & Review Programme

This quarterly add-on programme maintains ongoing hygiene across three core governance areas: risk, user access, and vendor management. We facilitate periodic reviews of high-privilege account access and critically evaluate your vendor inventory status. By regularly updating your Risk Register with nominated owners, we ensure your compliance environment remains continually up-to-date.

  • Review and update the Risk Register with nominated owners
  • Facilitate periodic reviews of high-privilege user access
  • Review and update the status of the critical vendor list
Get Started

Our Service Guarantee:

Maintain ongoing hygiene of the compliance environment through quarterly governance activities across risk, access, and vendor management.

Our Programme Includes:

Quarterly Risk Review User Access Review Vendor Inventory Review
Cybersecurity Tabletop Exercise

The Cybersecurity Tabletop Exercise is a facilitated, scenario-based simulation specifically tailored to your organisation's threat profile and critical assets. We lead an interactive crisis simulation workshop using a custom scenario to effectively test your team's readiness. Following the exercise, you receive a detailed report documenting observations, identified gaps, and actionable improvement recommendations.

  • Develop a tailored Scenario Design Document and Exercise Plan
  • Facilitate an interactive crisis simulation workshop
  • Produce a detailed post-exercise report with gap analysis
Get Started

Our Service Guarantee:

Test the organisation's incident response readiness through a structured, facilitated breach simulation tailored to the organisation's threat profile.

Our Tabletop Exercise Includes:

Scenario Development Workshop Facilitation Post-Exercise Report
Third-Party Risk Management

Our Third-Party Risk Management service provides structured, evidence-based assessments to evaluate the security posture of your key suppliers. We design tailored security questionnaires and conduct direct technical interviews with vendors to review their available evidence. The assessment concludes with a comprehensive TPRM report documenting identified gaps and strategic recommendations.

  • Design tailored security questionnaires and assessment criteria
  • Conduct structured technical vendor interviews and evidence reviews
  • Produce a final TPRM report documenting security posture and gaps
Get Started

Our Service Guarantee:

Evaluate the security posture of key suppliers through structured, evidence-based assessments.

Our TPRM Service Includes:

Assessment Planning Vendor Interview TPRM Report
Managed Security Responses

Managed Security Responses handles inbound and outbound security enquiries on your behalf, effectively reducing the burden on your internal teams and keeping your sales pipeline moving. We expertly draft responses to prospect questionnaires and proactively prepare outbound evidence packages for customer-initiated audits. You also receive a quarterly summary of all questionnaire activity, outcomes, and recurring themes.

  • Draft responses to inbound customer and prospect security questionnaires
  • Prepare outbound evidence packages for customer-initiated audits
  • Deliver quarterly summaries of questionnaire activity and outcomes
Get Started

Our Service Guarantee:

Manage inbound and outbound security enquiries to protect and build external trust with customers and prospects.

Our Managed Responses Include:

Inbound Responses Outbound Issuance Quarterly Reporting
Ready to extend your program?

Tell us what you're working towards and we'll recommend the right add-ons for your situation.

Book a Free Call
  • ✓  45-minute no-pressure conversation
  • ✓  We'll scope exactly what you need
  • ✓  Straight answers, no upselling
  • ✓  We'll tell you if we're not the right fit