Cyber Resilience
Consulting

We help organizations strengthen their cyber governance and resilience capabilities through strategic assessments, compliance frameworks, and continuity plans that reduce real business risk.

8 Consulting Services
ISO -27001 - 22301 - 31000
NIST - CSF - SP800-53 - RMF
GRC Governance - Risk - Compliance

ISO 27001 GAP Assessment

Gap Assessment Against the International Information Security Standard

We assess the organization's current state against the 93 controls in Annex A of ISO 27001:2022, identifying specific gaps, classifying their criticality, and designing a prioritized roadmap to achieve certification or improve the security posture.

Applicable Standards and Frameworks

ISO 27001:2022 Assessed Framework
ISO 27002:2022 Control Guidelines
ISO 27005 Risk Management
ISO 27701 Privacy (Add-On)

Assessed Domains

  • A.5 Information Security Policies
  • A.6 Security Organization
  • A.7 Human Resources Security
  • A.8 Asset Management
  • A.9 Access Control
  • A.10 Cryptography and Encryption
  • A.11 Physical and Environmental Security
  • A.12 Operations Security

Additional Domains

  • A.13 Communications Security
  • A.14 Secure Acquisition and Development
  • A.15 Supplier and Third-Party Management
  • A.16 Incident Management
  • A.17 Business Continuity
  • A.18 Legal and Contractual Compliance
  • Clauses 4–10: Context, Leadership, and Planning
  • ISMS Process: Scope, Policy, and ISMS

Security Maturity Assessment

Objective Measurement of the Organization's Cybersecurity Maturity Level

We assess the maturity of cybersecurity programs, capabilities, and controls using recognized models such as CMMI, C2M2, and NIST CSF. The result is an objective snapshot of the current level (from 1 to 5), with gaps identified by domain and an improvement plan prioritized by impact.

Applicable Standards and Frameworks

NIST CSF 2.0 Main Framework
CIS Controls v8 Technical Controls
C2M2 Maturity Model

Assessed Maturity Domains

  • Identify: Inventory, Risk, and Governance
  • Protect: Preventive Controls and Access
  • Detect: Threat Monitoring and Detection
  • Respond: Response Plans and Capabilities
  • Recover: Continuity and Lessons Learned
  • Supply Chain and Third Parties
  • Supply Chain and Third Parties
  • Security Awareness and Culture

Business Continuity Plan (BCP)

A Plan That Ensures Business Operations During Any Significant Disruption

We design the Business Continuity Plan (BCP) in accordance with ISO 22301 by identifying critical processes, analyzing the impact of disruptions (BIA), and defining continuity strategies, activation procedures, and communication plans to ensure the organization remains operational even during a major incident.

BCP Components

  • Business Impact Analysis (BIA)
  • Identification of Critical Processes (RTO/RPO)
  • Continuity Strategies by Process
  • Activation and Escalation Plans
  • Crisis Communication Tree
  • Roles and Responsibilities (Crisis Management Team)
  • Alternate Operating Procedures
  • Testing and Simulation Exercise Plan

BIA Results

  • Recovery Time Objective (RTO) by Process
  • Recovery Point Objective (RPO) by Process
  • Maximum Tolerable Period of Disruption (MTPD)
  • Minimum Business Continuity Objective (MBCO)
  • Technology and Third-Party Dependencies
  • Financial Impact per Hour of Disruption
  • Critical vs. Important vs. Non-Critical Processes
  • Supporting Assets Required by Process

Disaster Recovery Plan (DRP)

Technology Recovery Plan to Restore Critical Systems After a Disaster

The DRP defines the technical procedures for recovering critical technology infrastructure—including servers, databases, applications, and networks—within the RTO and RPO targets established in the BCP. It includes recovery architectures, failover procedures, and periodic recovery testing.

Technical DRP Components

  • Inventory of Critical Systems and Dependencies
  • Recovery Architectures: Warm, Cold, and Hot Standby
  • Failover and Failback Procedures
  • Data Replication and Backup Strategies
  • Recovery Runbooks by System and Application
  • Recovery Testing: Tabletop, Partial, and Full
  • Integration with Cloud Providers (Azure, AWS)
  • Documented and Measurable Recovery SLAs

Covered Scenarios

  • Primary Data Center Failure (Fire, Flooding)
  • Ransomware and Large-Scale Data Encryption
  • Critical Infrastructure Failure (SAN, Network, Power)
  • Loss of WAN or Internet Connectivity
  • Active Directory (AD) Compromise
  • Critical Cloud or SaaS Provider Failure
  • Production Database Corruption
  • DDoS Attack That Disrupts Digital Services

Cyber Risk Assessment

Identification, Analysis, and Prioritization of Cyber Risks to Business Assets

We conduct a comprehensive cyber risk assessment using recognized methodologies such as ISO 27005 and NIST RMF. We identify threats, vulnerabilities, and the potential impact on critical business assets, delivering a prioritized risk register with treatment options and residual risk metrics.

Assessment Process

  • Inventory and Classification of Critical Assets
  • Threat Identification
  • Assessment of Existing Vulnerabilities
  • Determination of Inherent Risk Level
  • Assessment of Existing Controls

Risk Treatment Options

  • Mitigate: Implement Additional Controls
  • Transfer: Obtain Cyber Insurance or Outsource
  • Avoid: Discontinue the Activity That Creates the Risk
  • Action Plan for Each Risk with Owner and Due Date
  • Periodic Review of the Risk Register

Governance & Compliance

Cybersecurity Governance Structure and Regulatory Compliance

We design and implement the organization's cybersecurity governance framework, including organizational structure, roles and responsibilities, committees, performance indicators (KPIs), and compliance with local and international regulatory frameworks applicable to the sector.

Governance Structure

  • Definition of the Cybersecurity Governance Model
  • Roles: CISO and Security Committee
  • Terms of Reference and Responsibilities
  • Metrics and Performance Indicators (KPIs/KRIs)
  • Periodic Reports for the Board and Executive Management
  • Security Exception Approval Process

Compliance Frameworks

  • Law 1581 of 2012 — Data Protection in Colombia
  • SFC: Circular 007 — Colombian Financial Sector
  • PCI DSS — Payment Cards and Payment Processing
  • HIPAA — Healthcare Sector (Projects with the United States)
  • SOC 2 Type II — Cloud and SaaS Services
  • NIST Cybersecurity Framework (CSF) 2.0
  • CIS Controls v8 — Technical Controls
  • GDPR — European Data Protection

Security Roadmap

Business-Aligned Cybersecurity Strategic Roadmap Prioritized by Risk

We design the organization's Security Roadmap: a 12-, 24-, and 36-month plan that prioritizes security initiatives based on their impact on real risk reduction, implementation cost, and alignment with strategic business objectives. Each initiative includes its rationale, KPIs, and accountable owner.

Roadmap Components

  • Current Maturity Baseline (As-Is)
  • Target Security Architecture (To-Be)
  • Initiatives Prioritized by Risk and Impact
  • Quick Wins: High-Impact Improvements in 90 Days
  • Strategic Initiatives over 12/24/36 Months
  • Investment Estimate by Initiative
  • Success KPIs and Acceptance Criteria
  • Dependencies Among Initiatives and Projects

Prioritization Criteria

  • Residual Risk Reduction (Risk Impact)
  • Implementation Cost vs. Benefit
  • Regulatory Compliance Enabled
  • Technical and Organizational Complexity
  • Dependencies on Other Ongoing Initiatives
  • Risk Appetite and Available Budget
  • Team Readiness to Adopt the Solution
  • Estimated Time to Implement (TTI)

Policy & Procedure Development

Development of Internal Cybersecurity Policies, Procedures, and Standards

We develop the organization's internal cybersecurity framework, including master policies, operating procedures, and technical guidelines aligned with ISO 27001, NIST, and applicable regulations. Every document is reviewed, approved, and communicated to the relevant teams.

Documents Developed

  • Master Information Security Policy
  • Access Control and Identity Management Policy
  • Acceptable Use of IT Resources Policy
  • Data Classification and Handling Policy
  • Security Incident Management Policy
  • Vulnerability and Patch Management Policy
  • Secure Software Development Policy
  • Third-Party and Supplier Management Policy

Procedures and Guidelines

  • Incident Management Procedure (IRP)
  • User Onboarding and Offboarding Procedure
  • Privileged Access Review Procedure
  • Secure Endpoint Configuration Guide
  • Server and Service Hardening Guide
  • Backup and Recovery Procedure
  • Secure Use of Cloud Services Guide
  • IT Change Management Procedure

Discover the True Security Status of Your Infrastructure

Request a Consultation