CyberSafe · Fenolink Enterprises · Datasheet
Policy that matches the controls you actually run. We attest from evidence, not from a template library you will never operate.
| Workstream | Outcome |
|---|---|
| Policy & standards | A short set of policies people can follow; owners named |
| Risk register | Ranked risks tied to identity, cloud, email, and exposed services |
| Control mapping | ISO 27001 / NIST CSF language mapped to live controls — gaps labeled |
| Board / audit pack | A briefing a non-specialist can fund, plus the appendix auditors want |
Typical retainers: monthly vCISO hours plus a quarterly board pack. One-off gap analyses are scoped as assessments, not as a GRC subscription.
Not a certificate mill. Not a 200-page policy dump. If you need a platform plan for detection, buy CyberLink or Enterprise separately.
Windhoek, Namibia · +264 81 390 6697 · [email protected] · Aug 2026.