Services / Governance, Risk & Compliance

Governance, Risk & Compliance

Our fastest-growing practice — 12+ modules across compliance, risk, audit and resilience. Buy one, or let a vCISO orchestrate them all.

5.1

Compliance & Certifications

ISO/IEC 27001:2022

  • Gap assessment
  • Documentation & Annex A control implementation
  • Internal audit & certification-audit support

SOC 2 (Type I / Type II)

  • Trust Services Criteria mapping
  • Readiness assessment
  • Support through the third-party audit

GDPR / HIPAA

  • Readiness assessments for personal and health data
  • Control design & evidence

UK Cyber Essentials

  • Baseline certification for UK operations or UK clients
Our own posture, stated plainly: ROUNDBOX is actively preparing for ISO 27001:2022, SOC 2 Type II, HIPAA and UK Cyber Essentials. We describe our services as aligned with these frameworks — never as “certified” — until certification is achieved.
5.2

Risk & Governance

vCISO / CISO as a Service

Recurring executive security leadership without the executive payroll. Board reporting included.

Risk Assessment & Management

Risk register, matrix, treatment plans and quarterly review cadence.

Policies & Governance Frameworks

Information-security policy suite built for your regulator, not a template.

Third-Party / Vendor Risk

Supplier risk assessment and monitoring. Orbis Shield TPRM — Partner Preview

5.3

Audit & Continuous Monitoring

  • Internal compliance audits (pre-certification)
  • Continuous controls monitoring
  • Periodic compliance reporting for boards and regulators
5.4

Continuity, Resilience & People

  • Business continuity & disaster recovery plans (BCP/DR)
  • Security awareness training
  • Phishing simulations and human-risk maturity measurement