FOUNDED 2025 · INDEPENDENT UK PRACTICE
01Toolkit catalogue

Practitioner-led toolkits with AI-assisted workflows and attestation.

Move from obligation to evidence: map what applies, assess the gap, draft the artefacts, structure control activity and prepare for scrutiny: audit, certification, regulatory review, customer assurance and attestation. Senior practitioner judgement at the core of every output.

How access works PRIVATE PREVIEW · H1 2026

Practitioner-led toolkits, accessed through advisory engagement. Human judgement retained throughout.

ACCESS MODEL
Private preview

Not yet a self-serve product. Available through engagement with the practice during the preview window.

DELIVERY MODEL
Advisory-led

A senior practitioner scopes the work, runs the toolkit alongside your team, and is accountable for every output.

REVIEW MODEL
Human-reviewed

AI accelerates the structured tasks. Senior practitioners review, judge and sign off every output before it leaves the practice.

ROADMAP
H2 2026 GA

General availability anticipated H2 2026, informed by early-access partner feedback during the preview.

02Group one · 7 toolkits

Security Frameworks & Standards

International standards. Recognised control catalogues. Backbone toolkits.

Structured implementation kits for the international standards underpinning most certification and assurance programmes. Each kit covers the management system, the control set with implementation guidance, and the artefacts required for external audit.

T01 BACKBONE

ISO 27001 Toolkit

ISO/IEC 27001:2022 ISMS, end-to-end.

93 Annex A controls mapped, risk methodology, Statement of Applicability, internal audit programme, management review pack. The backbone toolkit, most other frameworks map directly to it.

T02 RESILIENCE

ISO 22301 Toolkit

Business continuity that auditors can verify.

BCMS scope, BIA template, business continuity plans, exercise programme, supplier dependency mapping. Configured to align with ISO 27001 for joint certification, or to run standalone.

T03 AI BACKBONE

ISO 42001 Toolkit

AI management system aligned to EU AI Act and NIST AI RMF.

AI policy, AI risk register, AI impact assessment, model and system cards, monitoring procedures, incident handling. Build once, satisfy ISO 42001, NIST AI RMF, and EU AI Act overlap.

T04 FRAMEWORK

NIST CSF 2.0 Toolkit

Six functions, operationalised for board, audit and regulator.

Govern, Identify, Protect, Detect, Respond, Recover. Tier-based maturity assessment, profile builder, sector-specific implementation guidance, executive-readable scoring. Maps to ISO 27001 and CIS Controls.

T05 AI FRAMEWORK

NIST AI RMF Toolkit

Govern, Map, Measure, Manage for the generative-AI era.

Trustworthiness assessments across the seven characteristics. Generative AI Profile (NIST AI 600-1) playbook actions baked in. Pairs with ISO 42001 for management-system depth.

T06 CONTROLS

CIS Controls v8 Toolkit

Cyber hygiene baseline, IG1 / IG2 / IG3 tiered.

18 controls, 153 safeguards, mapped to NIST CSF and ISO 27001. Implementation Group banded for scale-appropriate ramp. Includes v8.1 and recent SAT updates.

T07 UK ASSURANCE

Cyber Essentials / Plus Toolkit

Self-assessment and Plus-audit ready, with Apr 2025 updates.

Five technical control families, scope determination wizard, cloud-services scoping, MFA artefacts, 14-day patching SLA. UK government-supplier ready (DSPT, DEFCON 658, NHS scope).

03Group two · 5 toolkits

Regulations

EU and UK statutory obligations. Mapped to controls.

Translation kits that convert legal text into a working programme of control activity, governance moves and evidence artefacts sized to the organisation in question.

T08 FS REG

DORA Toolkit

ICT risk, third-party register, incident classification.

Five DORA pillars covered. ICT risk framework, third-party register schema, incident classification matrix, threat-led penetration test scoping. Aligned to the ESA RTS and ITS.

T09 EU REG

NIS 2 Toolkit

Sector-tier scoping. Supplier obligations. Incident reporting.

Essential vs important entity classification, NIS 2 Article 21 control mapping, member-state transposition tracking (different deadlines across IE, NL, DE), board accountability mapping.

T10 AI REG

EU AI Act Toolkit

Risk-tier classification. Conformity assessment. FRIA. Post-market monitoring.

Provider, deployer, importer, distributor role determination. Annex III high-risk classification. Technical documentation packs. FRIA templates. Post-market monitoring procedures.

T11 EU REG

GDPR Toolkit

EU GDPR for organisations with European data subjects.

Lawful basis register, ROPA, DPIA template, controller-processor agreements, international transfer mechanisms (SCCs, BCRs, adequacy). EDPB-aligned guidance and recent CJEU case-law baked in.

T12 UK REG

UK GDPR Toolkit

UK GDPR, DPA 2018, DUAA 2025 changes baked in.

Lawful basis, Article 22 automated decision-making, ICO AI audit framework, DUAA 2025 legitimate-interests changes, international transfers (IDTA, Addendum, UK extension to the EU-US DPF).

04Group three · 2 toolkits

Attestations

AICPA Trust Services Criteria. ICFR for service organisations.

Attestation kits aligned to the AICPA Trust Services Criteria and ICFR control objectives. Each kit maps onto ISO 27001 controls to avoid duplicate evidence collection across overlapping reporting cycles.

T13 ATTEST

SOC 1 Toolkit

ICFR control set under AT-C 320 for service organisations.

Type 1 readiness through Type 2 examination. Control objectives, complementary user entity controls, subservice organisation handling (carve-out vs inclusive). Different scoping from SOC 2, calibrated to financial-reporting impact.

T14 ATTEST

SOC 2 Toolkit

Trust Services Criteria, all five categories, mapped to ISO 27001.

Common Criteria CC1 to CC9, optional categories (Availability, Confidentiality, Processing Integrity, Privacy), system description, management assertion. Run alongside an ISO 27001 programme without duplicating evidence collection.

05What each toolkit produces

Standard outputs across every toolkit. Sized to the organisation.

Every toolkit produces the same shape of evidence. Structured, scoped to the standard or regulation, and ready to be picked up by an internal team, a board sub-committee or an external auditor.

01 · SCOPE
Scope & applicability
Scope determination, in-scope systems, exclusions and rationale.
02 · GAP
Gap assessment
Current vs target state across every control, scored and prioritised.
03 · MAP
Control map
Crosswalk to adjacent frameworks. Build once, reuse everywhere.
04 · EVIDENCE
Evidence pack
Walkthroughs, artefacts, screenshots and sign-offs in an auditor-ready bundle.
05 · RACI
RACI & accountability
Named owners, reviewers, approvers; aligned to your management system.
06 · ROADMAP
Remediation roadmap
Sequenced uplift plan with effort, dependencies and a board narrative.
07 · SUMMARY
Board summary
Four-page pack written in language your board and audit committee will accept.
08 · REGISTER
Risk register entries
Linked back to your enterprise risk register with appetite, owner and KRI.
05How a toolkit works

Structured delivery, accelerated by intelligent workflows.

Each toolkit combines AI-enabled workflows with senior practitioner review, so outputs remain grounded in context, risk appetite, implementation reality and accountable decision-making.

Engage InfoSecAI when the scope is complex, multi-framework, time-sensitive or board-facing. The toolkit accelerates the structured tasks; senior practitioners ensure the judgement stays human.

Construction

Each kit contains the management system architecture, the control catalogue with implementation guidance, evidence templates, RACI definitions and a maturity self-assessment.

Acceleration

AI-assisted drafting, mapping and gap analysis under senior practitioner review. The judgement remains with the human reviewer and the senior accountable owner of the work product.

Access

Toolkits are accessed through advisory engagement during the private preview. General availability is anticipated in H2 2026 following partner feedback.

06Early access

Inform the development roadmap. Request advisory-led toolkit access.

The toolkits are currently available through advisory-led private preview, with direct senior practitioner support. Early-access engagements inform the development roadmap. Limited capacity each quarter; general availability anticipated H2 2026.