CISO as a Service
Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.
Service
We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.
The challenge
Regulators, auditors and customers increasingly demand evidence that your organization manages information security. Many companies respond by piling up policies nobody applies and controls nobody verifies.
Our approach is different: we design controls that work in practice and that your team can sustain, aligned with the standards that apply to you.
And because we are an offensive security team, we technically verify that those controls actually stop an attack, not just that they are documented.
What we do
We identify the controls shared across standards so your organization does not do the same work twice.
Assessment, implementation of the information security management system (ISMS) and preparation for the certification audit.
Gap analysis and adaptation plan for Peru’s information security and cybersecurity management regulation for supervised entities.
Cardholder data environment scoping, gap analysis and support during the assessment.
Inventory of personal data banks, required security measures and procedures to handle data subject rights under Peru’s data protection law.
A methodology based on ISO/IEC 27005 and NIST CSF 2.0: risk identification, assessment and treatment plans.
Independent internal audits, follow-up of nonconformities and support during external audits.
How we work
01
Interviews, document review and technical testing to understand the real state of your security.
02
We compare every applicable requirement with your current situation and prioritize by risk.
03
We define projects, owners and realistic timelines to close the gaps.
04
We draft policies and procedures and support the rollout of technical controls alongside your teams.
05
We use offensive testing to prove that key controls work as expected.
06
Internal audit, organized evidence and support during the external audit.
Deliverables
Standards and frameworks
Frequently asked questions
No. Certification is granted by an accredited certification body. We prepare your organization and support it during the audit; keeping both roles separate avoids conflicts of interest.
It depends on the scope, size and maturity of your organization. After the assessment we provide a realistic, phased timeline.
Yes. We map the controls shared by ISO/IEC 27001, SBS Resolution No. 504-2021 and PCI DSS so the same evidence serves several requirements.
Among other obligations, registering your personal data banks with the competent Peruvian authority, applying security measures and handling data subject rights. We work with your legal team for the legal analysis.
Because we technically verify that controls work. A control that passes a document review but does not stop an attack is a risk your organization is still carrying.
Other services
Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.
Consulting to design and adopt a zero trust model: identity, segmentation and continuous verification.
Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.