top of page
Cybersecurity Governance & Risk

Cybersecurity governance turns security from a set of disconnected controls into a program leadership can actually steer. I build and assess information security management systems against ISO 27001, translating technical risk into decisions business leaders can act on.

  • Governance framework design and control mapping

  • Risk register development and risk treatment planning

  • Policy and procedure development aligned to a named standard

  • Gap assessments against ISO 27001 and SOC 2 Common Criteria

  • Audit readiness and evidence coordination

ISO 27001 · SOC 2 · PCI DSS

Third-Party Risk Management

Vendors and partners extend your attack surface and your compliance obligations. I build third-party risk programs that scale from initial due diligence through ongoing monitoring, so vendor relationships get the scrutiny their risk level actually warrants.

  • Vendor risk assessment and criticality tiering

  • Due-diligence questionnaire design and evidence review

  • Ongoing vendor monitoring and reassessment cycles

  • TPRM platform configuration (including ServiceNow TPRM)

  • Fourth-party risk visibility and contractual risk clauses

ISO 27001 · SOC 2 · TPRM Lifecycle Frameworks

Privacy Governance

Privacy compliance goes stale the moment it stops reflecting how data actually moves through your organization. I build privacy management-system readiness aligned to ISO 27701, grounded in real data flows and mapped against the legislation that actually applies to you — not a generic policy template.

  • Privacy gap assessments against applicable legislation (e.g. PIPEDA, provincial health privacy law)

  • Data flow mapping and data inventory development

  • Privacy policy and procedure development

  • ISO 27701 management-system readiness

  • Regulator submission support and evidence coordination

ISO 27701 · PIPEDA · Provincial Privacy Legislation

AI Governance

AI governance is becoming a genuine compliance requirement, not just a policy checkbox. I build practical AI risk and governance readiness aligned to ISO 42001 — covering how AI systems are inventoried, assessed and controlled, not just a one-page acceptable-use policy.

  • AI system inventory and risk classification

  • AI management-system readiness aligned to ISO 42001

  • AI use policy and governance framework development

  • Third-party AI vendor risk assessment

  • Impact assessments for AI-assisted decision-making

ISO 42001 · AI Risk Management Frameworks

Assurance & Compliance Readiness

Being audit-ready means more than having policies on file — it means evidence that maps cleanly to a named framework and holds up under scrutiny. I coordinate the deliverables, documentation and evidence trail organizations need to move from policy-ready to audit-ready.

  • Framework mapping and control alignment across multiple standards

  • Evidence coordination and audit-readiness reviews

  • Compliance scoping (e.g. PCI DSS scoping statements)

  • Business continuity and disaster recovery planning

  • Independent review and quality-control checkpoints for compliance deliverables

ISO 27001 · SOC 2 · PCI DSS · ISO 27701

Advisory Services

  • Risk Assessments

  • ISO 27001 / ISMS Readiness

  • Privacy Governance / ISO 27701 Readiness

  • AI Governance / ISO 42001 Readiness

  • Third-Party Risk Management

  • SOC 2 Readiness

  • Fractional GRC Advisory

SOC 2: Readiness support only; not the audit itself.

Formal SOC 2 audits are performed by a licensed CPA firm.

Privacy: Privacy governance and management-system readiness services only.

Legal instruments such as DPAs and SCCs are referred to privacy counsel.

Security testing: All security testing described was performed in authorized environments or controlled simulations.

Services
bottom of page