Consulting · Cybersecurity & AI Governance

Control designed into the change, not bolted on after.

Security and AI governance fail the same way: controls that exist but cannot be evidenced, applied uniformly instead of proportionately. We assess both domains together, classify what actually carries risk, and design controls that produce their own proof.

A zero-trust architecture: a faceted shield encircled by concentric verification rings with checkpoint nodes.
Scope
Security + AI
One assessment, both domains
Frameworks
27001 · 42001
Alignment and readiness work
Local law
PDPO-aware
Brunei data-protection context
Output
Evidence-first
Controls that produce their own proof

The exposure

Four exposures that are already open.

Shadow AI 01

AI adopted faster than it is governed

Staff are already pasting operational data into public models. The exposure is real, undocumented and — until someone inventories it — unquantified.

Identity 02

Identity is the perimeter now

Most incidents we are called into begin with a valid credential used by the wrong person. Network controls alone stopped being sufficient some years ago.

Supply chain 03

Third parties inherit your trust

Integrations, contractors and managed vendors hold standing access that was granted once and reviewed never. Their compromise becomes yours.

Assurance 04

Evidence assembled in a panic

Controls may genuinely operate, but nobody can show that they did. Audits and tenders are lost on the absence of evidence, not the absence of control.

AI governance framework

Four bands, from the outside in.

Organisations usually start at the third band — writing controls — and discover later that nobody owns the use case they were controlling. The order matters.

  1. B1

    Accountability

    Who owns each AI use case, who may approve it, and who answers for an outcome. Without a named owner the remaining three bands are decoration.

  2. B2

    Risk classification

    Each use case classified by consequence and autonomy, which determines the depth of control it needs. Uniform controls over-govern trivial cases and under-govern the dangerous ones.

  3. B3

    Controls in operation

    Human-in-the-loop gates, permission inheritance, retention limits, model and prompt change control — proportionate to the classification, not applied uniformly.

  4. B4

    Evidence & review

    Traceability produced as a by-product of the work, plus a defined review cadence, so assurance is a report you run rather than a project you start.

An AI governance framework rendered as four concentric segmented bands around a solid core.
Illustrative governance framework — accountability at the core

Zero trust

Six principles, including one most frameworks have not caught up with.

The fourth is the AI-era addition, and it is the one we most often find missing: an agent that can reach more than the person it acts for is a privilege-escalation path with a friendly interface.

  1. 01

    Verify explicitly

    Every request authenticated and authorised on its own merits — identity, device posture, location and sensitivity — rather than inherited from network position.

  2. 02

    Least privilege, always

    Standing access replaced with the minimum needed, time-bound where possible, and reviewed on a cadence rather than at the point of an incident.

  3. 03

    Assume breach

    Segment so a compromise stays local, and instrument so it is visible. The design question is containment, not prevention alone.

  4. 04

    Agents inherit, never exceed

    An AI agent acting for a user reaches exactly what that user could reach. It must not become a privilege-escalation route by construction.

  5. 05

    Encrypt in transit and at rest

    Including the personal data your AI features touch, with key management that survives an auditor asking who can decrypt what.

  6. 06

    Log what a reviewer will need

    Decided in advance from the questions you expect to be asked, not discovered afterwards when the logs turn out not to contain it.

Compliance

Alignment work, stated precisely.

TEKYDOCT is not currently certified to ISO/IEC 27001 or ISO/IEC 42001 — our own certification engagement is in progress. The work described here is readiness and alignment work we deliver for clients. Certification is issued only by an accredited certification body.

ISO/IEC 27001

Information security management

Gap assessment against Annex A, a Statement of Applicability, the risk register and the ISMS document set — prepared so an external auditor can follow it.

We prepare your organisation for certification. We do not issue it, and we are not your certification body.

ISO/IEC 42001

AI management system

AI policy, impact assessment method, risk classification scheme, human-oversight definitions and the model and provider governance record.

The newer of the two and increasingly asked for in enterprise and public-sector due diligence.

PDPO

Brunei data protection

Personal-data inventory, lawful-basis mapping, retention and cross-border transfer positions, and the handling path for data-subject requests.

Assessed against your own legal advice — we design the controls, your counsel confirms the interpretation.

Tender assurance

Security questionnaires

A maintained evidence pack that answers the recurring questions, so each bid stops being a fresh scramble across four departments.

Frequently the fastest commercial return on the whole engagement.

Risk assessment

Proportionate control starts with an honest rating.

Every finding is rated on consequence and likelihood, and the rating drives the depth of control. Uniform controls are how organisations spend heavily and remain exposed where it counts.

Illustrative risk ratings

Findings are rated on a five-by-five matrix of impact against likelihood, producing a residual rating of low, moderate, high or critical. The example placements shown are:

  • Shadow AI data exposure: severe impact, likely likelihood — residual rating critical.
  • Third-party standing access: major impact, possible likelihood — residual rating high.
  • Phishing to valid credential: moderate impact, almost certain likelihood — residual rating critical.
  • Unpatched edge component: minor impact, unlikely likelihood — residual rating low.

Your own matrix is populated from your own findings during the assessment.

Residual rating LowModerateHighCritical Illustrative placements · your matrix is populated from your own findings
A security operations centre with a curved wall of displays showing topology graphs and severity grids.
Illustrative operations view — detection designed against the questions you expect

Security architecture

Five layers, and the AI boundary is now one of them.

The fourth layer did not exist in most architecture documents three years ago. It is where the majority of new exposure now sits.

  1. 01

    Identity & access

    Single sign-on, conditional access, privileged access management and joiner–mover–leaver flows that actually revoke.

  2. 02

    Network & segmentation

    Segmented zones, controlled egress, secured remote access — designed so a compromise cannot move laterally at will.

  3. 03

    Endpoint & workload

    Hardening baselines, patch cadence, endpoint detection, and a defensible position on unsupported components.

  4. 04

    Data & AI boundary

    Classification, encryption, retention, and an explicit statement of what may leave your environment for a model to see.

  5. 05

    Detect & respond

    Logging designed against the questions a reviewer will ask, alerting routed to a named owner, and a rehearsed response runbook.

Roadmap

Assess, classify, remediate, assure.

Indicative durations for a single-entity assessment. Group structures extend assessment, not remediation sequencing.

  1. 01

    Weeks 1–3

    Assess

    Posture assessment across identity, network, endpoint, data and AI usage. Inventory the shadow AI already in use before restricting anything.

  2. 02

    Weeks 3–5

    Classify

    Risk-classify AI use cases and information assets, and agree which controls are proportionate to which class.

  3. 03

    Weeks 5–12

    Remediate

    Close the findings that carry immediate exposure, in priority order, with the fix evidenced as it lands.

  4. 04

    Ongoing

    Assure

    Establish the review cadence, the evidence pack and the change control that keep the posture from decaying quietly.

A compliance posture dashboard with a grid of control-status squares, a completion ring and stacked evidence documents.
Illustrative posture dashboard — control status and the evidence behind it

Business benefits

Security that also wins work.

The evidence pack tends to pay for itself commercially before the remediation programme finishes — enterprise and public-sector buyers ask the same questions repeatedly.

Reduced security risk

Findings prioritised by exposure, remediated in order, and evidenced as closed.

Improved compliance posture

Alignment work mapped to 27001, 42001 and PDPO with the artefacts an auditor expects.

Faster tender responses

A maintained evidence pack replaces the scramble across four departments per bid.

Secure AI deployment

AI features shipped with permission inheritance, human oversight and traceability from day one.

Clearer accountability

Named owners per control and per AI use case, so decisions have somewhere to sit.

Defensible decisions

When something goes wrong, you can show what was decided, by whom, and on what basis.

Industries

Regulated sectors set the bar.

Public-sector security classification and financial-sector supervision impose the tightest constraints, and shape the control design for everyone else we work with.

FAQ

What risk owners ask first.

Is TEKYDOCT itself ISO 27001 or 42001 certified?

No — and we will not imply otherwise. Our own certification engagement is in progress. What we bring is the practitioner work of getting an organisation ready: gap assessment, Statement of Applicability, risk register, ISMS and AIMS documentation, and the evidence discipline that survives an external audit. Certification is issued by an accredited body, never by a consultant.

Can you help us if we have no security team?

Yes, and that is common. The assessment establishes the posture and the priority order, and we can either hand the remediation plan to your provider or run it ourselves under IT Managed Services. What we will not do is leave you with a findings report and no route to closing it.

Do we need to stop staff using public AI tools?

Usually the wrong first move. Prohibition without an alternative drives the usage underground and destroys your visibility. We inventory what is actually in use, classify the exposure, then provide a sanctioned path for the legitimate cases and block the genuinely unacceptable ones. Restriction with a substitute holds; restriction alone does not.

How does AI governance differ from information security?

Security asks whether data is protected. AI governance additionally asks whether an automated decision was appropriate, explainable and overseen by a person with the authority to overrule it. The controls overlap heavily, which is why we assess both in one engagement rather than selling two.

Where does data residency fit?

It is a design constraint, not an afterthought. Where residency or sovereignty requires it, we design for private, self-hosted models and on-premises or hybrid hosting, and we document exactly what crosses which boundary so the position is defensible later.

What does the engagement actually produce?

A posture assessment with prioritised findings, an AI use-case risk classification, a control set proportionate to that classification, the framework-mapped document artefacts, and a remediation roadmap with owners. Plus the evidence pack, which is the artefact clients tend to value most within the first quarter.

Get started

Start where the exposure actually is.

The posture assessment stands alone: a rated findings list, an AI use-case classification and a prioritised remediation plan — whether or not you appoint us to close it.