Skip to main content
Steel FYI

Steel FYI

Practical security solutions for every budget

Visit Website

About

Steel FYI offers fractional information security and cyber security consultancy focused on small businesses, startups, and charities. Services include fractional CISO support, a transparent retainer to operate infosec tasks, and pragmatic ISMS design, implementation and operation to prepare organisations for ISO 27001 certification. The firm offers impartial audits of ISMS in line with requirement 9.2, help to understand GDPR compliance, and a 3-phased approach with typical timelines of around 3-6 months to build an evidence base for external audit. Steel FYI promotes a free 30 minute consultation and states a mission to provide affordable, practical security advice while funding pro bono advisory services for charities.

Related Vendors

Omni Group Consulting
Omni Group Consulting
Navigating Your Path to Certification Success

Omni Group Consulting, LLC offers consulting and advisory services for certification readiness and ongoing compliance. The firm provides gap assessments and internal audits (ISO 27001) executed to ISO 19011 and delivers a team of Information Security executives who serve clients in oversight and advisory roles, including virtual CISO (vCISO) engagements. Their services emphasize developing and implementing an information security program, managing company compliance requirements, producing audit artifacts and reporting metrics, and delivering employee awareness training and compliance audit observations. Omni positions itself to guide clients through certification journeys and to align security roadmaps with organizational strategy, culture, and resources.

View Profile ›
SECURESULT
SECURESULT
Your security strategy, expertly crafted and executed

Securesult provides information security consulting and managed CISO services. They offer a "CISO as a Service" model that assigns an experienced CISO to develop and implement information security strategy, policies and processes and act as the central contact for incidents. Engagements are preceded by a Security Assessment covering people, process and technology, with involvement of a privacy specialist and technical specialist. Services described include guidance on ISO27001, NEN 7510, BIO, NIS2 and DORA; preparation and guidance for incident response; development of business continuity and recovery plans; training and awareness programmes; and access to security engineers and ethical hackers. Offerings are described as scalable from a few hours per week to full strategy projects.

View Profile ›
RightCue
RightCue
Navigate Compliance, Safeguard Your Future

RightCue positions itself as a cyber security compliance consultancy. The site describes "vCISO services & Data Protection Officer" and offers ISO 27001 consulting services for ISMS implementation. RightCue's homepage labels the team "The Cyber Security Compliance Experts" and states they provide "a range of tailored Cyber security compliance services and cyber security consultancy" delivered by "qualified professionals." Messaging also promises to "help you deal with the complexities of new legislation, secure your business against the cyber threat and build trust with your stakeholders." The homepage includes cookie consent language but the core offering presented is advisory and managed compliance support including vCISO and ISO 27001 implementation services.

View Profile ›