InfoSecAI · Founded 2025 · Booking H1 2026 engagements now
Founded 2025 · Independent · UK-based

Information security and AI governance, made practical.

InfoSecAI helps organisations understand what needs to change, decide what matters most, and put the right governance, controls and ways of working in place to achieve their target operating model across security, regulation and AI.

Four phases. One accountable team. Assess, Align, Design, Deliver and Embed.
Aligned to what your auditors and regulators already cite

Built around the standards your business operates under, and the regulations it answers to.

Standards & frameworks
7 International · certifiable
ISO/IEC 27001:2022 ISO/IEC 42001:2023 NIST CSF 2.0 NIST AI RMF CIS Controls v8 SOC 2 Cyber Essentials
Regulations
7 Statutory · sector-specific
UK GDPR Data Protection Act 2018 DUAA 2025 EU AI Act DORA NIS2 DSPT
What we do

Four pillars.
Sixteen services.
One senior team.

Security and AI governance services for organisations that need practical decisions, stronger controls and delivery momentum. We help leadership teams understand the current state, align obligations and risk appetite, design target operating models, and move from assessment to implementation.

01

Leadership & Strategy

Senior security direction. Board-grade governance.

Fractional CISO leadership, strategy and architecture, programme management, and transactional cyber due diligence for organisations that need senior expertise without full-time headcount.

4 services
  • CISO Advisory & Virtual CISO
  • Cyber Strategy & Architecture
  • Programme Management & Transformation
  • M&A Cyber Due Diligence
02

Governance, Risk & Compliance

ISO 27001, DORA, UK GDPR and assurance readiness.

Gap-to-certification programmes, independent assurance, data protection advisory, maturity benchmarking and operational resilience. All regulator-grade.

5 services
  • Cyber GRC & Regulatory Alignment
  • Information Security Assurance
  • Data Protection & UK GDPR Advisory
  • Cyber Maturity Assessment
  • Operational Resilience & BCM
03

AI Security & Governance

EU AI Act. ISO 42001. NIST AI RMF. Production AI.

AI governance frameworks, EU AI Act compliance, ISO 42001 management systems, NIST AI RMF alignment, AI red-teaming and model security testing. Built for organisations deploying AI at scale.

3 services
  • AI Security & Governance
  • ISO 42001 & NIST AI RMF Alignment
  • AI Red-teaming & Model Security Testing
04

Security Operations & Engineering

Hands-on security across the live estate.

Incident response and security operations, cloud security posture management, security architecture review, and third-party and supply chain risk. Practical security work for live operating environments.

4 services
  • Incident Response & SecOps
  • Cloud Security Posture Management
  • Security Architecture Review
  • Third-Party & Supply Chain Risk
By the numbers

Built on practitioner depth, not headcount.

Services
0

Core consultancy services across four pillars, all delivered by senior practitioners.

Practitioner experience
0+ yrs

Hands-on CISO, Head of Security and Director-level practice in regulated industries.

Frameworks covered
0+

ISO 27001, NIST CSF, CIS, DORA, NIS 2, EU AI Act, ISO 42001, UK GDPR, Cyber Essentials, SOC 2.

Toolkits in private preview
0

AI-enabled compliance toolkits across frameworks, regulations and attestations.

Our AI-Enabled Toolkits

AI-enabled toolkits for standards, regulations and attestation.

Use a toolkit when
You need structure, repeatable workflows, and clearer ownership.

Our toolkits help organisations map obligations, assess gaps, draft governance artefacts, structure control activity, and prepare for audit, certification, regulatory review, customer assurance, and attestation activity.

Engage InfoSecAI when
The scope is messy, multi-framework, time-sensitive, or board-facing.

InfoSecAI combines AI-enabled workflow support with practitioner review, so outputs remain grounded in context, risk appetite, implementation reality, and accountable decision-making.

G01 7 toolkits

Security Frameworks & Standards

ISO 27001 · ISO 22301 · ISO 42001 · NIST CSF · NIST AI RMF · CIS Controls · Cyber Essentials.

International and recognised standards. ISO management systems, NIST frameworks, and recognised control catalogues, structured into practical governance workflows.

View toolkits
G02 5 toolkits

Regulations

DORA · NIS 2 · EU AI Act · GDPR · UK GDPR.

EU and UK regulatory obligations, mapped to controls. Turn legal text into operational work without doubling activity where ISO 27001 and NIST CSF already overlap.

View toolkits
G03 2 toolkits

Attestations

SOC 1 · SOC 2.

Trust Services Criteria and ICFR control sets mapped to ISO 27001 controls, so SOC readiness and ISO surveillance activity can be planned side by side.

View toolkits

14 AI-enabled toolkits across 3 groups. Private preview through H1 2026. Early-access partners shape the roadmap.

Browse all toolkits
Sector expertise

Adapted to your sector, obligations and operating model.

Security and AI governance expectations differ by sector, regulator, customer base and operating model. We shape the work around the obligations, control expectations and delivery realities that apply to your environment.

Financial Services

FCA-regulated firms, banks, fintechs and payment providers.

Regulatory anchor
DORA · in force Jan 2025

Healthcare

NHS trusts, ICBs, health-tech, life sciences and clinical research.

Regulatory anchor
DSPT · annual

Government & Public

Central government, local authorities, ALBs, defence and CNI operators.

Regulatory anchor
GovAssure · annual

Technology

SaaS, platforms, AI/ML organisations and cloud providers.

Regulatory anchor
EU AI Act high-risk · Aug 2026

Telecommunications

Telecoms operators, ISPs, MNOs, MVNOs and network providers.

Regulatory anchor
TSA Tier 1/2 · annual

Manufacturing

Industrial manufacturers, OT environments and product engineering.

Regulatory anchor
NIS2 · transposed

Retail & e-commerce

Multichannel retailers, e-commerce platforms and payment-handling brands.

Regulatory anchor
PCI DSS 4.0.1 · in force

Professional Services

Law firms, accountants, consultancies and advisors with their own client-data sensitivity.

Regulatory anchor
Client & SRA audits · year-round
Partner

MSSP advisory

Product strategy and advisory for managed security service providers building or evolving their portfolio.

Engagement type
Advisory · ongoing or project
PJ FOUNDER Paul Jolliffe Senior CISO & AI Governance Practitioner
Paul Jolliffe
Founder · MBA · CISSP · ISO 27001:2022 LA / LI / IA · PRINCE2
About InfoSecAI

Information security and AI governance, made practical.

InfoSecAI is an independent UK consultancy helping organisations turn security, regulatory, resilience and AI governance requirements into practical operating models, stronger controls and robust delivery.

We work across strategy, governance, risk, compliance, AI security, assurance, operations and engineering. Our services help leadership teams assess their current position, align to standards and regulation, define the target operating model, and deliver the governance, controls, artefacts and ways of working needed to move from intent to implementation.

Our toolkit capability accelerates structured work across ISO 27001, ISO 22301, ISO 42001, NIST CSF, NIST AI RMF, CIS Controls, Cyber Essentials, DORA, NIS 2, the EU AI Act, GDPR, UK GDPR, SOC 1 and SOC 2. The approach combines AI-enabled workflow support with senior practitioner judgement, so outputs remain proportionate, usable and connected to the way the organisation actually operates.

InfoSecAI was founded in 2025 by Paul Jolliffe. The company is built for organisations that need clarity, senior leadership and hands-on delivery across information security and AI governance, without adding unnecessary complexity or treating compliance as a paperwork exercise.

Get started

Tell us what needs to change.
We will help shape the next move.

Use the first conversation to clarify the outcome, and next steps.

Book via Outlook Email us
PJ
Founder
Paul Jolliffe
Founder · Senior CISO and AI Governance Practitioner

20+ years in information security, the last decade at CISO and Head of Security level. Most recent senior roles span UK financial services, professional services and enterprise technology.

Credentials
  • · MBA
  • · CISSP
  • · ISO 27001:2022 LA / LI / IA
  • · PRINCE2 Practitioner
Book a 30-min consultation