AI adopted faster than it is governed
Staff are already pasting operational data into public models. The exposure is real, undocumented and — until someone inventories it — unquantified.
↑↓ move · ⏎ open · esc close
Consulting · Cybersecurity & AI Governance
Security and AI governance fail the same way: controls that exist but cannot be evidenced, applied uniformly instead of proportionately. We assess both domains together, classify what actually carries risk, and design controls that produce their own proof.
The exposure
Staff are already pasting operational data into public models. The exposure is real, undocumented and — until someone inventories it — unquantified.
Most incidents we are called into begin with a valid credential used by the wrong person. Network controls alone stopped being sufficient some years ago.
Integrations, contractors and managed vendors hold standing access that was granted once and reviewed never. Their compromise becomes yours.
Controls may genuinely operate, but nobody can show that they did. Audits and tenders are lost on the absence of evidence, not the absence of control.
AI governance framework
Organisations usually start at the third band — writing controls — and discover later that nobody owns the use case they were controlling. The order matters.
Accountability
Who owns each AI use case, who may approve it, and who answers for an outcome. Without a named owner the remaining three bands are decoration.
Risk classification
Each use case classified by consequence and autonomy, which determines the depth of control it needs. Uniform controls over-govern trivial cases and under-govern the dangerous ones.
Controls in operation
Human-in-the-loop gates, permission inheritance, retention limits, model and prompt change control — proportionate to the classification, not applied uniformly.
Evidence & review
Traceability produced as a by-product of the work, plus a defined review cadence, so assurance is a report you run rather than a project you start.
Zero trust
The fourth is the AI-era addition, and it is the one we most often find missing: an agent that can reach more than the person it acts for is a privilege-escalation path with a friendly interface.
Every request authenticated and authorised on its own merits — identity, device posture, location and sensitivity — rather than inherited from network position.
Standing access replaced with the minimum needed, time-bound where possible, and reviewed on a cadence rather than at the point of an incident.
Segment so a compromise stays local, and instrument so it is visible. The design question is containment, not prevention alone.
An AI agent acting for a user reaches exactly what that user could reach. It must not become a privilege-escalation route by construction.
Including the personal data your AI features touch, with key management that survives an auditor asking who can decrypt what.
Decided in advance from the questions you expect to be asked, not discovered afterwards when the logs turn out not to contain it.
Compliance
TEKYDOCT is not currently certified to ISO/IEC 27001 or ISO/IEC 42001 — our own certification engagement is in progress. The work described here is readiness and alignment work we deliver for clients. Certification is issued only by an accredited certification body.
ISO/IEC 27001
Gap assessment against Annex A, a Statement of Applicability, the risk register and the ISMS document set — prepared so an external auditor can follow it.
We prepare your organisation for certification. We do not issue it, and we are not your certification body.
ISO/IEC 42001
AI policy, impact assessment method, risk classification scheme, human-oversight definitions and the model and provider governance record.
The newer of the two and increasingly asked for in enterprise and public-sector due diligence.
PDPO
Personal-data inventory, lawful-basis mapping, retention and cross-border transfer positions, and the handling path for data-subject requests.
Assessed against your own legal advice — we design the controls, your counsel confirms the interpretation.
Tender assurance
A maintained evidence pack that answers the recurring questions, so each bid stops being a fresh scramble across four departments.
Frequently the fastest commercial return on the whole engagement.
Risk assessment
Every finding is rated on consequence and likelihood, and the rating drives the depth of control. Uniform controls are how organisations spend heavily and remain exposed where it counts.
Findings are rated on a five-by-five matrix of impact against likelihood, producing a residual rating of low, moderate, high or critical. The example placements shown are:
Your own matrix is populated from your own findings during the assessment.
Security architecture
The fourth layer did not exist in most architecture documents three years ago. It is where the majority of new exposure now sits.
Identity & access
Single sign-on, conditional access, privileged access management and joiner–mover–leaver flows that actually revoke.
Network & segmentation
Segmented zones, controlled egress, secured remote access — designed so a compromise cannot move laterally at will.
Endpoint & workload
Hardening baselines, patch cadence, endpoint detection, and a defensible position on unsupported components.
Data & AI boundary
Classification, encryption, retention, and an explicit statement of what may leave your environment for a model to see.
Detect & respond
Logging designed against the questions a reviewer will ask, alerting routed to a named owner, and a rehearsed response runbook.
Roadmap
Indicative durations for a single-entity assessment. Group structures extend assessment, not remediation sequencing.
Weeks 1–3
Posture assessment across identity, network, endpoint, data and AI usage. Inventory the shadow AI already in use before restricting anything.
Weeks 3–5
Risk-classify AI use cases and information assets, and agree which controls are proportionate to which class.
Weeks 5–12
Close the findings that carry immediate exposure, in priority order, with the fix evidenced as it lands.
Ongoing
Establish the review cadence, the evidence pack and the change control that keep the posture from decaying quietly.
Business benefits
The evidence pack tends to pay for itself commercially before the remediation programme finishes — enterprise and public-sector buyers ask the same questions repeatedly.
Findings prioritised by exposure, remediated in order, and evidenced as closed.
Alignment work mapped to 27001, 42001 and PDPO with the artefacts an auditor expects.
A maintained evidence pack replaces the scramble across four departments per bid.
AI features shipped with permission inheritance, human oversight and traceability from day one.
Named owners per control and per AI use case, so decisions have somewhere to sit.
When something goes wrong, you can show what was decided, by whom, and on what basis.
Industries
Public-sector security classification and financial-sector supervision impose the tightest constraints, and shape the control design for everyone else we work with.
FAQ
No — and we will not imply otherwise. Our own certification engagement is in progress. What we bring is the practitioner work of getting an organisation ready: gap assessment, Statement of Applicability, risk register, ISMS and AIMS documentation, and the evidence discipline that survives an external audit. Certification is issued by an accredited body, never by a consultant.
Yes, and that is common. The assessment establishes the posture and the priority order, and we can either hand the remediation plan to your provider or run it ourselves under IT Managed Services. What we will not do is leave you with a findings report and no route to closing it.
Usually the wrong first move. Prohibition without an alternative drives the usage underground and destroys your visibility. We inventory what is actually in use, classify the exposure, then provide a sanctioned path for the legitimate cases and block the genuinely unacceptable ones. Restriction with a substitute holds; restriction alone does not.
Security asks whether data is protected. AI governance additionally asks whether an automated decision was appropriate, explainable and overseen by a person with the authority to overrule it. The controls overlap heavily, which is why we assess both in one engagement rather than selling two.
It is a design constraint, not an afterthought. Where residency or sovereignty requires it, we design for private, self-hosted models and on-premises or hybrid hosting, and we document exactly what crosses which boundary so the position is defensible later.
A posture assessment with prioritised findings, an AI use-case risk classification, a control set proportionate to that classification, the framework-mapped document artefacts, and a remediation roadmap with owners. Plus the evidence pack, which is the artefact clients tend to value most within the first quarter.
Get started
The posture assessment stands alone: a rated findings list, an AI use-case classification and a prioritised remediation plan — whether or not you appoint us to close it.
Chat with us on WhatsApp
Pick the team you need — we'll open the chat.
Ask Teky Bot
AI-assisted · replies may contain mistakes
Please don't share passwords or personal data. AI processes your messages. See our Privacy Policy.
We set no cookies of our own and run no trackers — just two on-device preferences (theme, this notice). The Google Map on our Contact page can set Google's. Details in our Cookie Policy and Privacy Policy.