Your deal is stuck behind a security review

I build and run your security programme, and I face your customer's security team while it happens.

Took over a stalled ISO 27001 and closed it in 18 days. SOC 2 Type II, unqualified opinion, all five trust services categories.

Send me the questionnaire and get the scope back.

A read within a day. Fixed scope and a written quote after a 30 minute call.

marius@keibisoft.com · Telegram · LinkedIn

Services

Compliance, start to certificate

ISO 27001, SOC 2 Type I and Type II, NIS2 and GDPR. Policies, risk register, evidence, and the auditor managed to final report.

The part that decides the outcome: your posture is aligned to the risk profile of the customers you are selling to, so the review comes back with no comments.

Fractional CISO or Head of Security

Whatever you call the seat: fractional CISO, Head of Security, security lead, DPO. The roadmap, the management system, vendor reviews, DPAs and board reporting. Monthly retainer, cancel anytime.

Enterprise deal unblocking

Questionnaires, vendor risk assessments and customer CISO calls. I answer them and join the call. Usually where an engagement starts.

Cloud security review and DevSecOps

AWS, GCP or Azure against a written threat model, with SAST, SCA, secret and IaC scanning wired in as required checks.

AI and LLM security governance

Model data flows, prompt injection, credential exposure and logging. Policy, controls, and the AI section of your customers' questionnaires.

Cloud cost and commitment review

Before you sign a multi-year commitment, someone checks it covers what you actually run.

Post-quantum cryptography

TLS, key exchange and data-at-rest audited for quantum exposure, with a named migration path. KeibiDrop runs on ML-KEM-1024 with X25519.

Cases

Credentials

Common questions

How long does ISO 27001 or SOC 2 take?

ISO 27001 runs 8 to 12 weeks. SOC 2 Type II takes five to six months, and most of that is the auditor's clock: scoping, an observation window of at least three months, then about a month for the report. Type I is much faster if a buyer accepts it as an interim.

Do I need a compliance programme at all?

Only when a buyer has asked. If nobody is asking, you will hear that first, before any quote.

What do you not do?

Penetration testing. I scope it, brief the testers and act on the findings, and a specialist firm runs it.

Estimate the work on your deal.

marius@keibisoft.com · Telegram · LinkedIn

Reply within 24 hours. Can start within 1 to 2 weeks. Writing on this.