Not the sentence "we provide data security consulting", but these eight concrete pieces of work: assessment, inspection readiness, management system build, classification rollout, and engineers on site keeping it alive.
They ask: an inspection lands next month and I cannot answer these checklist items; we finished classification two years ago and nobody has maintained it since; head office wants every branch assessed and someone has to set the basis. So we break the work into concrete deliverables, each stating when you need it, what happens, and what you receive — so you can match it against wherever you are stuck.
When you need it
Regulatory self-inspection, annual review, before a new system goes live, or when head office wants branches assessed on one basis.
What happens
Deliverables
When you need it
Against insurance data security requirements, or after a dispute in underwriting, claims or the agent channel.
What happens
Deliverables
When you need it
When an inspection notice arrives, or a self-inspection is mandated. The window is usually short.
What happens
Deliverables
When you need it
Required periodically for handlers above the regulatory threshold; when an audit is ordered by the regulator; or when investment, M&A or customer due diligence asks for an audit conclusion.
Audit scope, frequency and method are governed by the current text of the PIPL compliance audit measures and by regulator requirements.
What happens
Deliverables
When you need it
After the policies exist — the real problem is that nobody maintains them day to day.
On-site engineers run governance operations. That is not a 24/7 SOC watch, and we do not describe it as one.
What happens
Deliverables
When you need it
When a data catalogue must be filed, or governance has stalled at "we graded it and nobody uses it".
What happens
Deliverables
When you need it
Starting from nothing, or when existing policies contradict each other and never reach the desk.
What happens
Deliverables
When you need it
Before a new system goes live, after capacity or architecture changes, and on the annual assessment cycle. Level 3 systems also face routine supervisory inspection.
The assessment report itself is issued by a licensed assessment body; our role is consulting, remediation and support.
What happens
Deliverables
When you need it
Pre-launch security acceptance, the periodic testing required by MLPS and other regimes, after major releases, or after an incident.
What happens
Deliverables
When you need it
When periodic drills are required, or when something has actually happened and you need someone to take it on immediately.
What happens
Deliverables
When you need it
At vendor onboarding, before renewal, or when an audit or inspection reaches this item — and it almost always does.
What happens
Deliverables
When you need it
When development and test environments are running on production data. It is one of the most common inspection findings and one of the easiest to overlook internally.
What happens
Deliverables
When you need it
When your sector publishes its important data catalogue, or filing is required.
What happens
Deliverables
Not seeing the one you need? Describe the situation and the deadline and we will work out where to start.
Not the sentence "we provide data security consulting", but these eight concrete pieces of work: assessment, inspection readiness, management system build, classification rollout, and engineers on site keeping it alive.
Book a consultation