S05 · Specialist module or project
Cyber Governance and Assurance
Cyber risks, control ownership, evidence, provider responsibilities, incident readiness and board reporting are governed without product-sales conflict.
When to use this service
Buying triggers
- Cyber activity exists but evidence, ownership or executive reporting is weak.
- Provider claims need independent governance challenge.
- The board needs decision-ready cyber risk reporting.
What the customer receives
Core deliverables
- 01Cyber governance profile
- 02Control-evidence map
- 03Board cyber report
- 04Prioritised improvement actions
- 05Exercise record where scoped
Professional boundary
Clear scope. Clear accountability.
No penetration testing, technical certification or product resale unless separately contracted.
Framework, technical-provider interfaces and evidence scope are agreed before work begins.
Prices, service levels, responsibilities, dependencies and any remedies apply only when approved in an executed agreement and Order Form.
Start a governance discussion