Cybersecurity and Infrastructure

Governance, Risk and Compliance

The written rules that decide who may do what, and the evidence that proves it happened.

How We Work, Step by Step
  1. 1Scope and assets
  2. 2Assess risk
  3. 3Write policy
  4. 4Apply controls
  5. 5Evidence and review

What We Do for You

  • Build your risk register and rate each risk with you.
  • Write the policy set in language your staff can follow.
  • Inventory assets and map where regulated data travels.
  • Run the control gap assessment and produce the board summary.
  • Review supplier contracts for security and breach-notice terms.

How this is bought: Bought as an assessment first, then a project priced from what the assessment finds. Build an estimate for your case.

Our Approaches Explained

Risk register

A living list of what could go wrong, how likely it is, what it would cost, and who owns the fix.

Information security policy set

Acceptable use, access control, change control, incident response, supplier security, and data retention, written so staff can actually follow them.

Asset inventory and data mapping

A record of every system, device and data store, and where personal or regulated data travels.

Control framework alignment

Mapping controls to a recognised structure so gaps become visible instead of assumed.

Third-party and supplier review

Checking what your vendors can reach, what they store, and what they must tell you when something goes wrong.

Evidence and audit trail

Logs, approvals and records kept so a reviewer can verify a control worked, not just that it was written down.

The Standards We Work To

NIST Cybersecurity Framework (CSF) 2.0ISO/IEC 27001 and 27002CIS Critical Security Controls v8SOC 2 Trust Services CriteriaCOBIT

We follow the structure and controls these standards describe. We do not claim to be certified against them - where you need a formal certificate, we prepare the evidence and an accredited body performs the audit.

What You Get

  • Risk register and treatment plan
  • Policy set written for your team
  • Asset and data inventory
  • Control gap assessment
  • Board-level summary
Where We Usually Focus
Assets inventoried95%
Policies written to staff level88%
Gaps documented with owners91%

These are the areas clients most often ask us to improve. Your project sets its own targets, measured and agreed with you.

Ask AI what ARRIX does for Governance, Risk and Compliance - ARRIX

Opens your assistant with the question ready. Gemini has no pre-filled link, so we copy the question to your clipboard first.