Two engagements that show the same GRC discipline applied at different scales — advisory work on a regulatory deadline, and dual-track enterprise procurement under time pressure.
Advising a Critical Information Infrastructure operator on Cyber Trust Mark Level 5 readiness — representing an AI-driven CTI vendor on a regulator-convened advisory panel, and independently sustaining the client relationship through a regulatory timeline that outpaced their operational readiness.
Ran an introductory session, independently and with minimal guidance from the account director, to evaluate the client's current CTI posture against Cyber Trust Mark Level 3 requirements.
Found the client had no cyber threat intelligence feeds and no regular sector-specific threat reporting in place — a critical gap against the Level 3 bar.
Presented Protos AI-as-a-Service to the panel and client, mapping contextualised monthly reports and on-demand RFIs directly onto the identified gap. Was designated the cyber analyst who would write and deliver those reports.
Identified that foundational IT infrastructure and asset monitoring needed to be in place before a CTI programme could sit on top of it. Rather than push a regulatory timeline the client wasn't operationally ready for, flagged the dependency directly and let it shape the engagement plan.
Continued sending the client relevant sector-specific threat intelligence on an unsolicited, no-charge basis — keeping them supported and the relationship active while their infrastructure work caught up.
The formal engagement went on hold while the client addressed its infrastructure prerequisites, and picked back up in September 2026. The goodwill reporting kept the relationship — and the client's line of sight to the Level 3 deadline — intact through the pause, rather than letting it go cold.
Running two concurrent, high-stakes vendor risk assessments — for a public sector agency and a multinational FMCG company — as the gatekeeping step standing between Protos Labs and procurement sign-off.
Read both questionnaires closely before drafting a single answer. The public agency's questions leaned toward data sovereignty, access governance, and formal control attestation; the FMCG's leaned toward international data flows and third-party/AI vendor risk standards common in large multinational procurement. Treated them as two separate engagements running in parallel, not one template reused twice.
Mapped Protos Labs' ISO/IEC 27001 Annex A controls, plus the AI platform's specific guardrails — model access boundaries, data handling and retention limits, logging and monitoring — directly onto each client's own risk categories, rather than sending a generic control list and leaving them to translate it themselves.
Where a question went beyond documented policy — architecture specifics on the AI platform, security design decisions — coordinated directly with engineering and security to get accurate, defensible answers rather than approximating.
Delivered the public agency response in the formal, attestation-heavy register that public sector procurement expects, and the FMCG response in the enterprise vendor-risk format their security team was used to reviewing — same underlying evidence, framed for how each reviewer would actually read it.
Owned both assessments end to end on overlapping timelines without either slipping — prioritising and sequencing the work so neither client's procurement process stalled waiting on Protos Labs.
Delivered accurate, well-evidenced responses that passed security review for a public sector agency and a multinational FMCG company at the same time, on two different sets of expectations. Demonstrated that GRC could operate as a single flexible point of contact across sharply different institutional contexts — public sector formality and enterprise MNC vendor-risk process — without becoming a bottleneck to revenue.