Fractional compliance

Security, privacy and compliance leadership for the time your company needs, without building a full-time team: chief information security officer (CISO), data protection officer (DPO) and governance, risk and compliance (GRC) coverage, made to measure. We start with what matters today and coverage grows with your organization.

You need someone accountable for security, privacy or compliance, but not full time

Your customers, your board or an auditor ask who is accountable for information security, personal data and compliance in your company.

Today those tasks are spread across people who have another job, and a full-time in-house team is more than your company needs.

Where the EU General Data Protection Regulation (GDPR) applies, it allows the data protection officer to be a staff member or to work under a service contract (art. 37(6)).

The areas we can cover, starting with what matters today

  • Information security · CISO

    The chief information security officer leads the security program: prioritizes risks, coordinates incident response and answers customers and auditors.

  • Personal data · DPO

    The data protection officer advises your company on data protection and monitors compliance, keeps the record of processing activities up to date with your team, handles requests from individuals about their data, advises on data protection impact assessments and, where the GDPR applies, is the contact point for the supervisory authority.

  • Governance, risk and compliance · GRC

    The GRC lead keeps the map of your company's obligations, tracks compliance with them and runs risk management.

What you receive

Each deliverable shows its area; you receive them according to the areas your company needs to cover.

  • Security · Monthly security committeeOne session a month with your team to review risks, incidents and progress on the plan.
  • Security · Risk and incident reportThe status of risks and incidents, ready for your board.
  • Security · Annual plan and follow-upThe priorities of the year, with owners, and their progress month by month.
  • Security · Single point of contactOne door for the customers, auditors and regulators who ask about the security of your information.
  • Personal data · Record of processing activitiesWhich personal data your company processes, for what purpose and with whom it is shared, kept up to date.
  • Personal data · Requests from individualsRequests from people about their data, answered and logged.
  • Compliance · Obligations map and follow-upWhat the laws and standards that apply to your company require, with the status of each obligation.

How it works

  1. We talk about what matters today: security, personal data or compliance.

  2. We review your situation and agree with you on the priorities of the annual plan.

  3. Whoever leads each area joins your committees and channels and becomes the contact point for customers, auditors and regulators on that topic.

  4. Every month: committee, report and plan follow-up.

  5. Coverage grows with your organization: if your company needs to cover another area, we add it.

What defines the scope

  • The areas your company needs to cover today.
  • The size of the organization and the countries where it operates.
  • How many systems, suppliers and processing activities are in scope.
  • The laws and standards that apply to your company.
  • How often your board wants committees and reports.

How to engage

It is contracted as a fixed monthly fee, matched to the coverage your company needs.

Let's talk about what matters to you today.

In 30 minutes we review where you stand and suggest where to start.

Book 30 minutes contacto@gradiente.cl Write to us and we will set up a 30-minute conversation