Cybersecurity Governance & Risk
Cybersecurity governance turns security from a set of disconnected controls into a program leadership can actually steer. I build and assess information security management systems against ISO 27001, translating technical risk into decisions business leaders can act on.
-
Governance framework design and control mapping
-
Risk register development and risk treatment planning
-
Policy and procedure development aligned to a named standard
-
Gap assessments against ISO 27001 and SOC 2 Common Criteria
-
Audit readiness and evidence coordination
ISO 27001 · SOC 2 · PCI DSS
Third-Party Risk Management
Vendors and partners extend your attack surface and your compliance obligations. I build third-party risk programs that scale from initial due diligence through ongoing monitoring, so vendor relationships get the scrutiny their risk level actually warrants.
-
Vendor risk assessment and criticality tiering
-
Due-diligence questionnaire design and evidence review
-
Ongoing vendor monitoring and reassessment cycles
-
TPRM platform configuration (including ServiceNow TPRM)
-
Fourth-party risk visibility and contractual risk clauses
ISO 27001 · SOC 2 · TPRM Lifecycle Frameworks
Privacy Governance
Privacy compliance goes stale the moment it stops reflecting how data actually moves through your organization. I build privacy management-system readiness aligned to ISO 27701, grounded in real data flows and mapped against the legislation that actually applies to you — not a generic policy template.
-
Privacy gap assessments against applicable legislation (e.g. PIPEDA, provincial health privacy law)
-
Data flow mapping and data inventory development
-
Privacy policy and procedure development
-
ISO 27701 management-system readiness
-
Regulator submission support and evidence coordination
ISO 27701 · PIPEDA · Provincial Privacy Legislation
AI Governance
AI governance is becoming a genuine compliance requirement, not just a policy checkbox. I build practical AI risk and governance readiness aligned to ISO 42001 — covering how AI systems are inventoried, assessed and controlled, not just a one-page acceptable-use policy.
-
AI system inventory and risk classification
-
AI management-system readiness aligned to ISO 42001
-
AI use policy and governance framework development
-
Third-party AI vendor risk assessment
-
Impact assessments for AI-assisted decision-making
ISO 42001 · AI Risk Management Frameworks
Assurance & Compliance Readiness
Being audit-ready means more than having policies on file — it means evidence that maps cleanly to a named framework and holds up under scrutiny. I coordinate the deliverables, documentation and evidence trail organizations need to move from policy-ready to audit-ready.
-
Framework mapping and control alignment across multiple standards
-
Evidence coordination and audit-readiness reviews
-
Compliance scoping (e.g. PCI DSS scoping statements)
-
Business continuity and disaster recovery planning
-
Independent review and quality-control checkpoints for compliance deliverables
ISO 27001 · SOC 2 · PCI DSS · ISO 27701
Advisory Services
-
Risk Assessments
-
ISO 27001 / ISMS Readiness
-
Privacy Governance / ISO 27701 Readiness
-
AI Governance / ISO 42001 Readiness
-
Third-Party Risk Management
-
SOC 2 Readiness
-
Fractional GRC Advisory
SOC 2: Readiness support only; not the audit itself.
Formal SOC 2 audits are performed by a licensed CPA firm.
Privacy: Privacy governance and management-system readiness services only.
Legal instruments such as DPAs and SCCs are referred to privacy counsel.
Security testing: All security testing described was performed in authorized environments or controlled simulations.