RISK & ASSURANCE

Turn uncertainty into a decision.Turn obligations into evidence.

We help organisations understand security risk, prepare for assurance requirements and create evidence that stands up to scrutiny — without turning governance into paperwork for its own sake.

WHAT DO YOU NEED TO KNOW?

Start with the decision, not the framework.

Some organisations need a formal risk view. Others need to prepare for an assessment, a customer request, a board decision or a procurement gate.

01

What could go wrong, and how significant is it?

Build a defensible view of security risk and the controls that matter most.

02

Are we ready for ISO 27001 or PCI DSS expectations?

Understand where you stand, what evidence exists and what needs to be strengthened.

03

How do NZISM or PSR expectations apply to us?

Translate government security requirements into practical controls, ownership and evidence.

04

Can we rely on a supplier or third party?

Focus due diligence on the risks that matter instead of treating every vendor the same.

DEEP-DIVE OFFER · SECURITY RISK ASSESSMENT

“What could go wrong, how significant is it, and what should we do about it?”

A structured assessment that connects assets, threats, vulnerabilities, controls and business impact — then turns that analysis into practical treatment decisions.

01Understand context

Scope the system, service, business process and decision the assessment needs to support.

02Identify risk

Examine threats, weaknesses, dependencies and plausible impact to the organisation.

03Assess controls

Review what is already in place, how it operates and where evidence supports the claim.

04Prioritise treatment

Document residual risk, practical remediation and the decisions that need an owner.

WHAT YOU GET

A risk view that supports a decision.

  • Defined scope and assessment context
  • Risk statements and rationale
  • Control observations and evidence gaps
  • Prioritised remediation actions
  • Residual-risk and treatment view
  • Executive-ready summary

COMPLIANCE & ASSURANCE READINESS

One offer. Different assurance pathways.

The framework changes, but the underlying job is similar: understand the requirement, identify the evidence, close material gaps and prepare the organisation to demonstrate what it does.

01

ISO 27001 Readiness

Gaps, ISMS structure, policy and control readiness, evidence expectations, internal-audit preparation and remediation planning.

Techno-Fizz provides readiness and advisory support. Certification is performed by an accredited certification body.
02

PCI DSS Readiness

Scope, control gaps, evidence preparation, remediation planning and support for merchants or service providers preparing for assessment.

Techno-Fizz does not issue a ROC or AOC unless it becomes an appropriately approved QSA company.
03

NZISM / PSR Alignment

Translate the New Zealand Information Security Manual and Protective Security Requirements into practical controls, evidence and remediation priorities.

Designed for organisations that need a practical view of government-aligned security expectations.
04

Third-Party Risk Review

Assess supplier security, access, data handling, dependencies and contractual assurance using a risk-based approach.

The depth of review is matched to the service, information and access being entrusted.

FROM CLAIM TO EVIDENCE

“We have a control” is not the same as “we can demonstrate it.”

Assurance work becomes valuable when policies, technical configuration, operational practice and evidence tell the same story.

ASSURANCE WITH CLEAR BOUNDARIES

Credibility depends on knowing when independence matters.

Techno-Fizz can help organisations prepare, improve controls and review risk. Where genuine independent assurance is required, we keep that role separate.

01

Readiness before certification

We can help prepare an organisation for ISO 27001 certification, but the certification decision belongs to an accredited certification body.

02

PCI readiness, not QSA sign-off

We can support PCI DSS readiness and remediation without presenting Techno-Fizz as a QSA company or issuing QSA-only assessment outputs.

03

Advisory is not independent re-assessment

If we materially help design or implement a control, we do not present our later review of that same work as independent assurance.

WHEN THE QUESTION CHANGES

Need security posture or Secure BI instead?

LET’S START A CONVERSATION

Tell us what you’re trying to understand.

Your security posture, a compliance requirement, a specific risk, or who can see your data. We’ll tell you honestly whether we can help.