01Risk and control operations
Maintain the risk register, control map, ownership, exceptions, and treatment decisions as the organisation changes.
02Compliance readiness
Operate the evidence, policies, and action plans that support frameworks such as ISO 27001, SOC 2, and GDPR obligations.
03Cloud and identity security
Review access, configuration, data boundaries, logging, and critical cloud changes across the agreed environment.
04Vulnerability management
Triage exposure, focus teams on material issues, and follow remediation through to evidence-backed closure.
05Incident readiness
Keep response roles, escalation paths, playbooks, and exercises current before an incident tests them.
06Leadership assurance
Translate technical and compliance work into concise reporting on exposure, decisions, progress, and unresolved risk.