What we do
A focused practice, for organisations where the stakes are real: a matter of judgement, not process.
Assurance
Certification, kept.
The proof your customers and insurers now ask to see, built and maintained under one management system, because the overlap is where the cost and the audit findings live. The certificate itself comes from an accredited body and the attestation from an independent auditor; we build the system that passes and stay for the audits that follow. It has to be that way: the people who certify you must never be the people who built it.
Certification · ISO/IEC 27001 · ISO/IEC 42001 · Cyber Essentials
Attestation · SOC 2
Alignment · NIST frameworks
Counsel
Advice before the decision.
An independent read for the accountable owner of the risk on what is genuinely understood and controlled, written for the people charged with defending it rather than the team that produced it.
Board counsel · Risk assessment · Regulatory readiness
Response
The incident, led.
When the answer has to be quick and defensible: the preparation beforehand, leadership through the incident itself, and the review after that turns it into a stronger position.
Preparation · Incident leadership · Post-incident review
The way in
Begin with a Risk Profile Assessment.
A Risk Profile Assessment is a fixed-scope read on where your security, data and AI risk actually concentrates, what is defensible today, and what needs attention first. The fee is fixed and stated before we begin, and the findings arrive in writing. You will know what it costs before you say yes, and whether anything follows is your decision. The findings are yours to keep either way.
- Fixed scope
- Fixed fee, stated first
- Written findings
- Yours either way
The first conversation carries no charge and no assumption of commitment. It is exploratory, though not passive: you should leave it knowing something about your own position that you did not know when it began.
AdvisoryEvidence
Judge us by what you can check.
The seat
The principal has held Group CISO responsibility for security, data and regulatory risk across regulated software, financial services, healthcare, life sciences, education, gambling and e-commerce, in the UK, US and EU within a global remit.
Career record available in detail on request
The work
We build management systems to survive the audit that comes after the first one. We keep them ready between visits, and when the certification body returns each year, the same adviser is at the client’s side of the table. We do not name clients, in the same way we would not name you.
References available in confidence
The thinking
We publish our reasoning where it can be tested: positions argued against the primary documents rather than the consensus, written so a passing reader can check them. Each piece stands or falls on what it cites.
Read it at Insight · No gate, no email wall
The firm
Independent advice, carried through into implementation.
The data and systems an organisation cannot afford to lose now sit under more standards, regulation and scrutiny than most are built to carry. Alvermere sets the position you can defend and builds the programme that proves it, and the same named adviser leads both, so the answer holds together when it is tested.
Where there is a team, we lead it. Where there is no team to lead, we are the people delivering it, alongside your management, and that suits us fine. We stay: the same counterpart who built the system is beside you at the audit and helps run it day to day, year after year, renewed because it keeps being useful.
More about the firmOur position
Independent, and paid by one side only.
We are paid by our clients and by no one else, so our advice answers to one thing only: the client’s interest. No vendor pays us. No referral changes what we recommend. We work at both ends of the risk: brought in early, while a question is still a decision, and inside the incident, when the answer has to be quick. It is the second that taught us the value of the first.
The principal
Stephen Randles.
Stephen has held Group CISO responsibility for security, data and regulatory risk, most recently at group level in a global business. The firm exists to put that experience, the judgement of the seat that answers for the risk, within reach of the people who hold that accountability now, so they do not hold it alone.
More than one hundred client organisations advised · Certifications guided from small charities to global groups · Tens of incidents led with full accountability · Regulator-facing work including the ICO
Group CISO accountability · Group Data Protection Officer · Board-level reporting · Regulated environments · International scope · Incident leadership · AI management · Standards & assurance
The Principal