I will write your information security policies and risk assessment
vCISO and Cybersecurity Consultant, ISO 27001, SOC 2 and GRC Expert
About this Gig
Every information security program needs written policies and a documented risk assessment for governance, customer due diligence, and audits. As Head of Information Security at a multi-country fintech, I write policies and risk documentation that regulators and auditors actually accept, not generic templates.
What you get, by tier:
Basic: One targeted policy document, written to your context.
Standard: A core set of 5-8 essential policies plus a risk register aligned to your operations.
Premium: A full 15+ policy suite plus an enterprise risk assessment report, ready for audit and board review.
Certified: CISM | ISO/IEC 27001 Lead Implementer & Lead Auditor | ISO/IEC 27701 Lead Auditor | CEH | CC (ISC2).
Message me before ordering so I can confirm which policies you need and your regulatory context.
My Portfolio
FAQ
Which policies do I actually need?
It depends on your regulatory scope and any frameworks you're targeting (ISO 27001, SOC 2, GDPR, etc.). Message me your industry and jurisdiction and I'll recommend a set before you order.

