What we actually do
Anonymised real-world examples. Filter by category on the left.
Day one setup: Google Workspace from scratch in 24 hours
Within 24 hours we deployed a complete Google Workspace environment: business-domain email for all users, MFA on every account, secured Drive sharing rules, DMARC/DKIM/SPF for domain reputation protection, and role-based admin tooling.
The client walked into their first meeting with a professional business email, secure file sharing, and the confidence that their digital identity was protected.
Result: a fully functional, GDPR-ready Google Workspace — in one working day.
Migration without chaos: email and domain to Google Workspace
We planned the migration in stages: first DNS preparation and Google Workspace account creation, then gradual email history migration via IMAP, finally MX record cutover at a precisely timed moment.
The result: complete email history in the new system, users trained, DMARC and DKIM configured, and the domain switched without a single message going missing.
Result: a smooth migration with 0 minutes of downtime — users didn't notice the transition.
Working smarter: AI automation inside Google Workspace
We deployed Google Workspace AI tools combined with Apps Script automation: Gemini AI-assisted drafting in Gmail, automated workflows from Google Forms into Sheets and Drive, and a notification system routing the right information to the right person without manual intervention.
The result: staff reclaimed an average of 4 hours per week from repetitive tasks. The IT lead received automated security event summaries directly to their inbox.
Result: repetitive processes automated, Gemini AI deployed — without violating a single data privacy requirement.
Full renovation: domain, email, and security in one project
We expanded the scope together by mutual agreement. Alongside the standard migration, we ran a full Google Workspace security review: audited all admin permissions, configured Data Loss Prevention (DLP) rules, enabled Google Workspace security logs, and produced a short action plan for the road toward ISO 27001.
Result: the client left with not just a new email system, but a genuinely secure and audit-ready Google Workspace environment.
ISO 27001 gap analysis — from uncertainty to action plan in 3 weeks
We conducted a thorough gap analysis — reviewing all 93 ISO 27001:2022 controls, interviewing key personnel, and assessing existing documentation. Within three weeks, the client had a clear action plan: what is in order, what needs attention, and what needs to be built from scratch.
The client entered the certification process with a precise timeline and budget — no surprises.
Result: complete gap analysis report and prioritised action plan — delivered in 3 weeks.
GDPR audit — data mapping and contract review
We mapped all personal data flows — customers, employees, suppliers. We built a complete Record of Processing Activities (ROPA), audited all third-party contracts against GDPR requirements, and completed the missing DPAs. Also included: an updated privacy policy and a short staff training session.
Result: full GDPR compliance documented — in 4 weeks, without interrupting operations.
NIS2 readiness assessment — financial services company
We assessed NIS2 applicability, sector classification, and existing security controls. The finding: the company is an important entity under Annex II, but already has approximately 70% of the required measures in place. We produced a focused gap list and a 90-day action plan.
Result: NIS2 compliance achievable without launching full ISO 27001 certification — time and money saved.
Risk assessment per ISO 27005 — manufacturing company
We conducted a full information security risk assessment per the ISO 27005 methodology: asset inventory, threat and vulnerability identification, risk evaluation and prioritisation, risk treatment plans. The final document met certification body requirements on first submission.
Result: audit-ready risk assessment document — delivered in 2 weeks, ready as direct input for ISO 27001 certification.
Incident response procedure — 24-hour compliance
We built a complete incident handling framework: incident classification, escalation chain, reporting template for the supervisory authority, internal investigation procedure, and a learning mechanism. A post-training test showed that staff could correctly identify and escalate incidents after a 2-hour training session.
Result: NIS2-ready incident response procedure — implemented in 3 days, team trained and tested.
E-ITS compliance audit — qualifying for public procurement
We audited the company's information systems and processes against E-ITS baseline requirements. We identified 11 gaps, of which 4 required immediate technical changes. All gaps were closed within 6 weeks — precisely before the tender submission deadline.
Result: E-ITS baseline compliance evidenced — the company successfully qualified for the tender.
Supply chain security audit — assessing critical suppliers
We developed a supply chain risk assessment methodology and questionnaire. We classified all suppliers by criticality, conducted document analysis for high-risk suppliers, and produced a short assessment for each. The outcome was a complete supply chain risk register and a follow-up action plan.
Result: 23 suppliers assessed, risk register created — accepted by the certification auditor on first review.
Information security policy package — documentation from scratch
We produced a complete information security policy package: general information security policy, password management policy, remote work security guide, incident handling procedure, data classification scheme, and acceptable use policy. All documents were tailored to the company's actual way of working — not generic templates.
Result: 6 core policy documents delivered — in 2 weeks, the client immediately signed three contracts that had been on hold.
Similar challenge?
Book a free 30-minute consultation.
Book a consultation