30 days
Posture and priorities
Initial risks, gaps and decisions become visible and organized.

12-month program · Assess · Implement · Operate
A yearly structure to understand posture, execute a roadmap and sustain controls, owners and evidence for customers, auditors and insurers.
Duration
12 months
Stages
Assess · Implement · Operate
Entry point
GAP, PenTest, readiness or concrete pressure
The core offer
The sequence adapts to context and team capacity while keeping one objective: every assessment should lead to execution and every control should leave evidence.
Understand context, assets, risks, controls, owners and available evidence.
Outputs: GAP report, risk register, control matrix, evidence map and roadmap.
Formalize processes, close priority gaps and integrate governance with operations.
Outputs: Policies, procedures, RACI, runbooks, evidence, metrics and an updated backlog.
Verify controls, review risk, sustain evidence and prepare the next cycle.
Outputs: Executive reviews, health checks, metrics, Fractional CISO support and next annual plan.
Visible outcomes
30 days
Initial risks, gaps and decisions become visible and organized.
90 days
The first improvements have owners, evidence and follow-up.
6 months
The roadmap has produced processes, documentation and verifiable closure.
12 months
The company can review posture, demonstrate progress and prepare the next cycle.
Fit
Outputs
Risk map, priorities, accepted risks and investment criteria.
Roadmap, backlog, owners, milestones and coordination with teams and vendors.
Control matrix, documentation and reusable third-party evidence.
Executive dashboard, metrics, reviews and next-cycle plan.
How the offers relate
Connected assessment, implementation and operations over 12 months.
This pageRecurring senior direction when executive security leadership is missing.
View Fractional CISOMonthly operation of controls, evidence, backlog and reviews.
View Continuous ManagementPublic case
Talsoft provided six months of support to formalize an ISO 27001-aligned management system, live risk register, incident response, centralized monitoring and external PenTest.
“Leandro and the team did a great job enhancing and formalising our existing security structure. The engagement was well-organised, consistently documented, and delivered to a high standard.”
Maturity framework
Reactive
Organized
Managed
Measured
Integrated
Evolving
Talsoft does not replace the internal owner or guarantee certification, audit approval or absolute security. Scope, priorities and pace are agreed according to context and execution capacity.
Startups, SMBs and growing teams that need to organize risk, evidence and execution.
Risk map, prioritized 30-60-90 roadmap, main gaps and required evidence to move forward.
No. It helps prepare posture, controls and evidence, but does not guarantee certifications or audit outcomes.
No. Many relationships start with PenTest, readiness, a security questionnaire, Mini Assessment or a specific risk. The program works as the framework for continuity when it makes sense.
When structural evolution is appropriate, ISMS Implementation is followed by Continuous Security Management. A PenTest or specific readiness engagement may also be next depending on risk.
Yes. The initial call helps understand context, external pressure and whether the GAP makes sense for your company.
We review external pressure, current posture, team and execution capacity before proposing scope, sequence and terms.