Vendor Directory
Explore application security and software supply chain vendors.

LRQA
Certifying compliance, securing your peace of mind
LRQA is a global assurance, certification, inspection and training organisation focused on risk management and compliance. The record states LRQA supports SOC 2 preparation and audit readiness, offers Virtual CISO (vCISO) services, and delivers certification and cyber services. It references LRQA's EiQ supply chain intelligence software and offers guidance, inspections and system assessments across standards and supply chains. LRQA promotes ISO-related transition support (ISO 42001 Early Adopter Pack) and provides expert-led cyber security and tailored safety programs. The organisation positions itself as providing assurance, certification, inspection and training to help organisations manage risk, strengthen resilience and maintain audit readiness.

RAYN Secure Pte Ltd
Guarding Your Future with Tailored Security Solutions
RAYN Secure provides security and compliance services including CISO as a Service (CISOaaS) and DPO as-a-service. The firm offers tailored solutions to assess vulnerabilities and build governance via its RAPS approach: Readiness, Awareness, Processes, and Security. RAYN supports certification and compliance activities (including ISO 27001 among listed requirements) and delivers staff training and asset security management. StaySecure is described as a unified approach combining strategic oversight (CISOaaS, DPOaaS), incident response alignment, and CSA & PDPA compliant education that fosters security behaviour. The company positions itself to help organisations prepare for threats, achieve compliance certifications, and maintain consistent security configurations across hardware and software.

RightCue
Navigate Compliance, Safeguard Your Future
RightCue positions itself as a cyber security compliance consultancy. The site describes "vCISO services & Data Protection Officer" and offers ISO 27001 consulting services for ISMS implementation. RightCue's homepage labels the team "The Cyber Security Compliance Experts" and states they provide "a range of tailored Cyber security compliance services and cyber security consultancy" delivered by "qualified professionals." Messaging also promises to "help you deal with the complexities of new legislation, secure your business against the cyber threat and build trust with your stakeholders." The homepage includes cookie consent language but the core offering presented is advisory and managed compliance support including vCISO and ISO 27001 implementation services.

TSC Security
Tailored security solutions for your business goals
TSC Security offers expert cybersecurity services including a tailored virtual CISO (vCISO) program, SOC 2 readiness assessments, and ISO 27001 implementation. The firm says it helps customers pass audits, respond to security questionnaires, and build a resilient, scalable security program. TSC Security also provides compliance support for GDPR and HIPAA and offers proactive vulnerability management solutions. Their virtual CISOs work with internal teams to define security strategy, manage risk, and align programs with business goals, positioning the service as expert guidance without full-time overhead. The site emphasizes preparing for SOC 2 audits and achieving ISO 27001 certification through their consulting and managed security services.

PCG DACH
Transforming Your Cloud Security Landscape
Public Cloud Group (PCG) is a cloud and security services provider and certified partner of leading hyperscalers (AWS, Azure, Google Cloud). PCG offers cloud transformation, managed cloud operations, and AWS Managed Services alongside Compliance-as-a-Service and ISMS implementation. The company supports standards such as ISO 27001, TISAX, SOC2 and BSI C5 and guides clients "from gap analysis to audit." PCG also provides virtual CISO services, red team tests, Business Continuity services, Microsoft 365 security and cloud operations for Azure and Google Cloud. Services described include consulting, ISMS software implementation, and AI-powered continuous optimization and managed cloud operations.

CyAdviso
Cybersecurity Leadership Tailored for Fintech Success
CyAdviso provides virtual CISO (vCISO) services and cybersecurity consulting focused on fintech. Their vCISO offering delivers outsourced cybersecurity leadership, ongoing support, and strategic guidance while integrating with client IT teams. Services include initial gap assessments (noted for ISO 27001), policy development, implementation of security controls such as access management, threat detection and incident response, and continuous compliance monitoring. The team cites experience across frameworks including ISO 27001, PCI-DSS, SOC2 and GDPR. Typical delivery notes an initial assessment and strategy phase taking about 4 to 8 weeks followed by ongoing services. The site references pricing (e.g., "1499/ month") and invites prospects to book a free consultation.

Steel FYI
Practical security solutions for every budget
Steel FYI offers fractional information security and cyber security consultancy focused on small businesses, startups, and charities. Services include fractional CISO support, a transparent retainer to operate infosec tasks, and pragmatic ISMS design, implementation and operation to prepare organisations for ISO 27001 certification. The firm offers impartial audits of ISMS in line with requirement 9.2, help to understand GDPR compliance, and a 3-phased approach with typical timelines of around 3-6 months to build an evidence base for external audit. Steel FYI promotes a free 30 minute consultation and states a mission to provide affordable, practical security advice while funding pro bono advisory services for charities.

Delta Protect
Defending Your Digital Frontier, Simplified
Delta Protect presents itself as a managed cybersecurity and compliance services provider for companies in Mexico and LATAM. The site highlights CISO as a Service / Virtual CISO offerings and lists Penetration and Ethical Hacking Tests, Security Operations Center, Managed Security Services, Compliance and Certifications, and dCloud Managed Cloud Services. Marketing text and metadata state the company focuses on simplifying and automating cybersecurity and compliance and references ISO 27001, SOC 2 and PCI DSS compliance. Service-focused language and the listed offerings indicate a consulting and managed-service firm delivering security testing, advisory and managed operations to enterprise customers in the region.

Omni Group Consulting
Navigating Your Path to Certification Success
Omni Group Consulting, LLC offers consulting and advisory services for certification readiness and ongoing compliance. The firm provides gap assessments and internal audits (ISO 27001) executed to ISO 19011 and delivers a team of Information Security executives who serve clients in oversight and advisory roles, including virtual CISO (vCISO) engagements. Their services emphasize developing and implementing an information security program, managing company compliance requirements, producing audit artifacts and reporting metrics, and delivering employee awareness training and compliance audit observations. Omni positions itself to guide clients through certification journeys and to align security roadmaps with organizational strategy, culture, and resources.

SECURESULT
Your security strategy, expertly crafted and executed
Securesult provides information security consulting and managed CISO services. They offer a "CISO as a Service" model that assigns an experienced CISO to develop and implement information security strategy, policies and processes and act as the central contact for incidents. Engagements are preceded by a Security Assessment covering people, process and technology, with involvement of a privacy specialist and technical specialist. Services described include guidance on ISO27001, NEN 7510, BIO, NIS2 and DORA; preparation and guidance for incident response; development of business continuity and recovery plans; training and awareness programmes; and access to security engineers and ethical hackers. Offerings are described as scalable from a few hours per week to full strategy projects.

Input Output, LLC
Navigating Compliance with Precision and Insight
Input Output (iO) offers information security and compliance services including fractional/vCISO engagements, information security policies and procedures, audits, penetration testing, DMARC management, and security awareness training. The firm provides ISO 27001 consulting, ISMS setup and management, gap assessments, and managed support for certification audits. Input Output describes ethical hacking and penetration testing that prioritizes fixes and supports compliance, and references work on HIPAA programs and remediation. Services are positioned for businesses seeking executive-level security and compliance leadership, risk management, and hands-on implementation of controls and processes. The site invites requests for scope and quotes and highlights customer testimonials about audits, testing, and ISO 27001 work.

Logic Weave
Securing Your Future with Strategic Leadership
Logic Weave is a Melbourne-based cybersecurity company offering fractional CISO leadership and cybersecurity advisory services for small and mid-sized Australian businesses. The firm highlights ISO 27001 readiness, Essential Eight maturity, governance and risk management, incident response and resilience planning, managed security, and cloud security. The site states they help clients "win contracts by achieving ISO 27001 readiness and Essential Eight maturity" and prepare for audits and compliance with privacy laws such as the Australian Privacy Act and GDPR. Services are described as tailored to startups, small, and mid-sized businesses and positioned as pure cybersecurity advisors providing leadership, frameworks, and expertise rather than generic IT providers.