Skip to content
Client access

Service

Compliance & Risk Management

We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.

Automation
The history of Kynapt scans, findings and retests in the portal serves as documented evidence of your vulnerability management cycle.
Human validation
Our consultants prove that each control actually works, not just that it is written in a policy.

The challenge

Being compliant is not the same as being protected

Regulators, auditors and customers increasingly demand evidence that your organization manages information security. Many companies respond by piling up policies nobody applies and controls nobody verifies.

Our approach is different: we design controls that work in practice and that your team can sustain, aligned with the standards that apply to you.

And because we are an offensive security team, we technically verify that those controls actually stop an attack, not just that they are documented.

What we do

International standards and Peruvian regulation, in a single program

We identify the controls shared across standards so your organization does not do the same work twice.

ISO/IEC 27001

Assessment, implementation of the information security management system (ISMS) and preparation for the certification audit.

SBS Resolution No. 504-2021

Gap analysis and adaptation plan for Peru’s information security and cybersecurity management regulation for supervised entities.

PCI DSS

Cardholder data environment scoping, gap analysis and support during the assessment.

Law No. 29733

Inventory of personal data banks, required security measures and procedures to handle data subject rights under Peru’s data protection law.

Risk management

A methodology based on ISO/IEC 27005 and NIST CSF 2.0: risk identification, assessment and treatment plans.

Internal audit

Independent internal audits, follow-up of nonconformities and support during external audits.

How we work

From assessment to audit, with no shelfware

01

Assessment

Interviews, document review and technical testing to understand the real state of your security.

02

Gap analysis

We compare every applicable requirement with your current situation and prioritize by risk.

03

Roadmap

We define projects, owners and realistic timelines to close the gaps.

04

Implementation

We draft policies and procedures and support the rollout of technical controls alongside your teams.

05

Technical verification

We use offensive testing to prove that key controls work as expected.

06

Audit readiness

Internal audit, organized evidence and support during the external audit.

Deliverables

Organized evidence for auditors and regulators

Standards and frameworks

  • ISO/IEC 27001
  • ISO/IEC 27005
  • NIST CSF 2.0
  • PCI DSS
  • SBS 504-2021
  • Law No. 29733
  • Assessment and gap reportCompliance level per requirement, with findings and their priority.
  • Risk registerIdentified risks, their assessment and the treatment plan agreed with the owners.
  • Statement of ApplicabilityFor ISO/IEC 27001: applicable controls, justification and implementation status.
  • Policies and proceduresDocumentation tailored to your organization, written to be used, not filed away.
  • Compliance roadmapPrioritized projects with owners, deadlines and dependencies.
  • Internal audit reportResults, nonconformities and corrective actions before the external audit.

Frequently asked questions

What clients usually ask before we start

Do you issue the ISO/IEC 27001 certification?

No. Certification is granted by an accredited certification body. We prepare your organization and support it during the audit; keeping both roles separate avoids conflicts of interest.

How long does an ISO/IEC 27001 implementation take?

It depends on the scope, size and maturity of your organization. After the assessment we provide a realistic, phased timeline.

Can we comply with several standards at once?

Yes. We map the controls shared by ISO/IEC 27001, SBS Resolution No. 504-2021 and PCI DSS so the same evidence serves several requirements.

What does Law No. 29733 require from my company?

Among other obligations, registering your personal data banks with the competent Peruvian authority, applying security measures and handling data subject rights. We work with your legal team for the legal analysis.

Why an offensive security firm for compliance?

Because we technically verify that controls work. A control that passes a document review but does not stop an attack is a risk your organization is still carrying.

Other services

A comprehensive view of your security

CISO as a Service

Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.

Zero Trust

Consulting to design and adopt a zero trust model: identity, segmentation and continuous verification.

Red Team & Ethical Hacking

Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)