Taking new engagements — Q4 hello@datadefenz.com
ServicesProductsResourcesPracticeAboutTalk to us

Shielding Your Data.

Compliance and technical security, from one team.

Most organisations buy security from two places that never speak to each other: a consultant who writes the policies, and a firm that does the testing. The findings never reconcile, and the client sits in the gap. We do both halves, and they answer to the same control set.

6 service categories 16 fixed-scope engagements 93 Annex A controls assessed 5 regimes compared
ISO/IEC 27001:2022 · Annex A93 controls

Every certification, every gap assessment, every customer questionnaire eventually resolves to this grid. On the GRC page it is clickable.

Why this exists

The gap between the two halves is where breaches live.

A policy nobody can implement is a finding waiting to happen. A penetration test nobody maps to an obligation is a PDF. The value is in the join — which is why we refuse to sell only one side of it.

Written by an auditor

Assessments that survive contact with a real audit

The practice is led by an ISO/IEC 27001:2022 Lead Auditor. Findings are written the way an auditor will read them, because eventually one will.

Delivered by specialists

Technical work by vetted practitioners

Penetration testers, SOC analysts and DevSecOps engineers brought in per engagement, scoped and quality-controlled by the practice rather than subcontracted and forgotten.

Priced before you commit

Fixed scope, fixed price, no discovery theatre

Most of what we do is packaged. You can read the scope, see a sample of the deliverable, and know the price before a sales process starts.

Start with the question everyone actually has

Does any of this apply to me?

Five questions. No email required, nothing leaves your browser. It will not settle the question for a regulator, but it will tell you whether you need to take it seriously.

Tool · Am I in scope?5 questions · nothing stored, nothing sent
Illustrative starting point based on the answers you gave. It is not a legal determination of scope. Confirm applicability with qualified counsel before acting on it.

Proof, not adjectives

Read the actual deliverable before you buy it.

We publish full sample reports — the real document structure, real finding language, real remediation sequencing, with client detail removed. Nothing proves competence like the work product.

Browse sample reports

Start here

Tell us which regulation is keeping you up.

A first conversation is 30 minutes and costs nothing. You leave with a view on what applies to you, whether or not you work with us.

Book a conversation