Taking new engagements — Q4 hello@datadefenz.com
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutBook a 30-minute callContact

The practice

A core team, plus specialists engaged per job.

The compliance work is done by the practice. The technical work is delivered by vetted specialists brought in for the engagement that needs them — scoped, briefed and quality-controlled by the same people who wrote the assessment. You get depth without paying to keep a penetration tester on a bench.

Role

Lead auditor and practice lead

ISO/IEC 27001:2022 Lead Auditor. Owns scope, methodology and quality on every engagement, and is the person who signs the report.

Role

Security architects

Practitioners who have designed, segmented and rebuilt enterprise estates — not reviewers who have only read about them. They are why our control sets tend to be implementable: an architect signs off that the thing we wrote can actually be built on your platform, at your scale, with your constraints.

Role

Security operations specialists

People who have run security operations centres, not only assessed them. They lead SOC-CMM engagements across all five domains, design detection use cases and escalation paths, and can tell the difference between a SOC with good tooling and a SOC that actually works — which is the entire point of the model.

Role

Penetration testers

Brought in per engagement against a defined scope and rules of engagement. Findings are reviewed by the practice before they reach you, and written for two audiences at once — the engineer who has to fix it and the executive who has to fund it.

Role

DevSecOps engineers

Pipeline and secure-development work, engaged where an assessment has identified something that needs building rather than documenting.

Role

Regulatory and privacy counsel

Engaged where a determination needs a legal opinion rather than a practitioner's reading.

How an engagement runs

Four stages, and you can stop after any of them.

One

Scoping call

Thirty minutes, no charge. We establish what applies to you and whether we are the right people. Sometimes the answer is that you do not need us yet, and we say so.

Two

Written scope and fixed price

What is included, what is not, what we need from you, and what you will hold at the end. Priced before you commit.

Three

Delivery

Evidence review, interviews, testing as scoped. Findings shared as they emerge rather than saved for a reveal at the end.

Four

Report and walkthrough

The deliverable, plus a session with the people who have to act on it. Remediation support is a separate decision, not an assumed upsell.