Skip to content
Service · Audit-ready · NEW

Audit-ready people, not just audit-ready systems.

Most SOC 2 and ISO 27001 failures aren't technology failures — they're human ones. We run structured, scenario-based awareness programmes mapped directly to the Trust Services Criteria your auditor will assess. Audit-ready evidence, signed registers, completion certificates, and 30 days of post-training support included.

Shield with a SOC 2 audit checklist, training module grid, and certificate of completion in cyan
What's included

Offerings under this practice.

SOC 2 awareness training

Five modules — Introduction to SOC 2, Access Control & Passwords, Data Handling & Confidentiality, Incident Reporting & Response, Change Management & Vendor Risk. Each with a knowledge-check quiz. Certificates per attendee. ~4–5 hours total, in-person or virtual.

ISO 27001 readiness

Gap assessment against ISO 27001:2022 Annex A, staff awareness sessions tuned to your sector, and a prioritised remediation plan that your QMS lead can run with. Built for SMEs, not boardroom theatre.

Security policy & compliance consulting

Tailored cybersecurity policies, incident response playbooks, data protection guidelines, vendor risk frameworks, and Kenya Data Protection Act / ODPC registration support — built for your specific business and team.

Ongoing security assessments

Phishing simulations, access control reviews, configuration audits, and quarterly security health checks. Keeps your organisation audit-ready year-round, not just in the month before the SOC 2 auditor lands.

Audit-ready deliverables

Signed attendance registers, individual completion certificates, quiz results, training-completion report, and a digital reference pack. Everything your auditor asks for — already in their format.

Tell us the 50-times-a-day decision your business keeps making.

We'll tell you in 20 minutes whether a system can make it for you — and if it can't, we'll say so.

Chat with us on WhatsApp