Fractional compliance
Security, privacy and compliance leadership for the time your company needs, without building a full-time team: chief information security officer (CISO), data protection officer (DPO) and governance, risk and compliance (GRC) coverage, made to measure. We start with what matters today and coverage grows with your organization.
You need someone accountable for security, privacy or compliance, but not full time
Your customers, your board or an auditor ask who is accountable for information security, personal data and compliance in your company.
Today those tasks are spread across people who have another job, and a full-time in-house team is more than your company needs.
Where the EU General Data Protection Regulation (GDPR) applies, it allows the data protection officer to be a staff member or to work under a service contract (art. 37(6)).
The areas we can cover, starting with what matters today
-
Information security · CISO
The chief information security officer leads the security program: prioritizes risks, coordinates incident response and answers customers and auditors.
-
Personal data · DPO
The data protection officer advises your company on data protection and monitors compliance, keeps the record of processing activities up to date with your team, handles requests from individuals about their data, advises on data protection impact assessments and, where the GDPR applies, is the contact point for the supervisory authority.
-
Governance, risk and compliance · GRC
The GRC lead keeps the map of your company's obligations, tracks compliance with them and runs risk management.
What you receive
Each deliverable shows its area; you receive them according to the areas your company needs to cover.
- Security · Monthly security committeeOne session a month with your team to review risks, incidents and progress on the plan.
- Security · Risk and incident reportThe status of risks and incidents, ready for your board.
- Security · Annual plan and follow-upThe priorities of the year, with owners, and their progress month by month.
- Security · Single point of contactOne door for the customers, auditors and regulators who ask about the security of your information.
- Personal data · Record of processing activitiesWhich personal data your company processes, for what purpose and with whom it is shared, kept up to date.
- Personal data · Requests from individualsRequests from people about their data, answered and logged.
- Compliance · Obligations map and follow-upWhat the laws and standards that apply to your company require, with the status of each obligation.
How it works
-
We talk about what matters today: security, personal data or compliance.
-
We review your situation and agree with you on the priorities of the annual plan.
-
Whoever leads each area joins your committees and channels and becomes the contact point for customers, auditors and regulators on that topic.
-
Every month: committee, report and plan follow-up.
-
Coverage grows with your organization: if your company needs to cover another area, we add it.
What defines the scope
- The areas your company needs to cover today.
- The size of the organization and the countries where it operates.
- How many systems, suppliers and processing activities are in scope.
- The laws and standards that apply to your company.
- How often your board wants committees and reports.
How to engage
It is contracted as a fixed monthly fee, matched to the coverage your company needs.
References
- ISO/IEC 27001:2022
- GDPR · Regulation (EU) 2016/679 · arts. 37 to 39
Related services
Governance, risk and compliance
What data your company has, who is accountable for each data set and how its quality is measured.
Data governance for AI
Governance, risk and compliance
Ready for your customers' resilience clauses and availability requests, with recovery tests and their evidence.
Resilience & availability readiness
Governance, risk and compliance
ISO/IEC 27001, ISO/IEC 42001 and ISO 22301: from zero to prepared for certification with an accredited body.
ISO readiness
Let's talk about what matters to you today.
In 30 minutes we review where you stand and suggest where to start.