Expertise

Expertise, credentials and delivery standards

Our experts have worked inside large, regulated institutions, where every technology decision has to stand up to scrutiny. We bring those same standards to organisations that need the rigour without the overhead.

  • CGEIT Certified in the Governance of Enterprise IT, awarded by ISACA. An independent credential in exactly this discipline, and one a sceptical buyer can verify.
  • TOGAF The Open Group's enterprise architecture standard. It is what allows an architecture engagement to produce something your organisation can maintain after we leave.
  • CISM Certified Information Security Manager, awarded by ISACA. Security assessed as a management and accountability question, which is where most of the exposure sits.
  • AI governance Policy, use registers, risk assessment and adoption decisions, aligned to ISO/IEC 42001:2023. A specialism, not an add-on to a security offer.
  • Strategic planning Translating technology questions into decisions your leadership team can take, record and stand behind.
  • Regional network Experience and an active professional network across large, regulated, multi-stakeholder institutions in Africa.

Certifications are held by our experts and are verifiable with the awarding bodies. Standards named elsewhere on this site, including ISO/IEC 42001:2023, describe the methods our work is aligned to. Alignment to a standard is a statement of method and is not a claim to be certified against it.

Independence

Nothing sits behind the advice

What that means in practice

We sell no technology and take no commission from anyone. There is no product behind the recommendation, no reseller agreement, and no vendor relationship to protect. What we recommend is never influenced by what we would earn if you bought it.

We do implement, when you want us to. Writing the policy suite, building the portfolio register or standing up the governance structure is often the part an organisation has no capacity for. That work is quoted and agreed separately from the assessment, never bundled into it and never assumed. You are free to take the findings and have anyone else do the work, and plenty of clients should.

It also means we will tell you when the answer is to do nothing, or to fix a process rather than buy a tool. That is not a sales position; it is the whole reason for commissioning an assessment from outside. Where we have implemented something, any later re-assessment of that work says so plainly, because an assessor marking their own work is worth very little to you.

How we work

  • Written scope agreed before any work starts
  • Fixed price, never hourly billing
  • Modular. You choose the domains
  • Findings you own, in a form you can reuse
  • A clear end date on every engagement

Next step

Take the first step

Most engagements start with a short discussion about what your organisation is trying to achieve and where technology is getting in the way. From there we agree a clear scope and a fixed price before any work begins.