Featured Engagements

Two engagements that show the same GRC discipline applied at different scales — advisory work on a regulatory deadline, and dual-track enterprise procurement under time pressure.

Cyber Trust Mark Advisory

Energy (CII)

Advising a Critical Information Infrastructure operator on Cyber Trust Mark Level 5 readiness — representing an AI-driven CTI vendor on a regulator-convened advisory panel, and independently sustaining the client relationship through a regulatory timeline that outpaced their operational readiness.

Role
GRC Lead, Customer Success & Security Operations
Sector
Energy (Critical Infrastructure)
Regulatory driver
CSA Cyber Trust Mark, Level 5 by end-2027
Status
Resumed Sept 2026
1

Assessment

Ran an introductory session, independently and with minimal guidance from the account director, to evaluate the client's current CTI posture against Cyber Trust Mark Level 3 requirements.

2

Gap analysis

Found the client had no cyber threat intelligence feeds and no regular sector-specific threat reporting in place — a critical gap against the Level 3 bar.

3

Solution matching

Presented Protos AI-as-a-Service to the panel and client, mapping contextualised monthly reports and on-demand RFIs directly onto the identified gap. Was designated the cyber analyst who would write and deliver those reports.

4

Sequencing & prioritisation

Identified that foundational IT infrastructure and asset monitoring needed to be in place before a CTI programme could sit on top of it. Rather than push a regulatory timeline the client wasn't operationally ready for, flagged the dependency directly and let it shape the engagement plan.

5

Sustained client support

Continued sending the client relevant sector-specific threat intelligence on an unsolicited, no-charge basis — keeping them supported and the relationship active while their infrastructure work caught up.

Engagement paused pending client infrastructure readiness · resumed September 2026

The formal engagement went on hold while the client addressed its infrastructure prerequisites, and picked back up in September 2026. The goodwill reporting kept the relationship — and the client's line of sight to the Level 3 deadline — intact through the pause, rather than letting it go cold.

Independent delivery under regulatory pressure Technical-to-business translation Client-first sequencing over deadline-first pressure Proactive relationship management External-advisor + audit-requirement fluency

Vendor Compliance Questionnaires

Public Sector & FMCG · Enterprise Procurement

Running two concurrent, high-stakes vendor risk assessments — for a public sector agency and a multinational FMCG company — as the gatekeeping step standing between Protos Labs and procurement sign-off.

Role
GRC Lead, Customer Success & Security Operations
Clients
A public sector agency · A multinational FMCG company
Driver
Client-side vendor risk & security due diligence, gating procurement
Status
Both cleared
1

Scoping two very different risk lenses

Read both questionnaires closely before drafting a single answer. The public agency's questions leaned toward data sovereignty, access governance, and formal control attestation; the FMCG's leaned toward international data flows and third-party/AI vendor risk standards common in large multinational procurement. Treated them as two separate engagements running in parallel, not one template reused twice.

2

Mapping controls to each question set

Mapped Protos Labs' ISO/IEC 27001 Annex A controls, plus the AI platform's specific guardrails — model access boundaries, data handling and retention limits, logging and monitoring — directly onto each client's own risk categories, rather than sending a generic control list and leaving them to translate it themselves.

3

Pulling in the right technical depth

Where a question went beyond documented policy — architecture specifics on the AI platform, security design decisions — coordinated directly with engineering and security to get accurate, defensible answers rather than approximating.

4

Matching tone to institution

Delivered the public agency response in the formal, attestation-heavy register that public sector procurement expects, and the FMCG response in the enterprise vendor-risk format their security team was used to reviewing — same underlying evidence, framed for how each reviewer would actually read it.

5

Running both to deadline, in parallel

Owned both assessments end to end on overlapping timelines without either slipping — prioritising and sequencing the work so neither client's procurement process stalled waiting on Protos Labs.

Both vendor risk assessments cleared — procurement unblocked for both clients

Delivered accurate, well-evidenced responses that passed security review for a public sector agency and a multinational FMCG company at the same time, on two different sets of expectations. Demonstrated that GRC could operate as a single flexible point of contact across sharply different institutional contexts — public sector formality and enterprise MNC vendor-risk process — without becoming a bottleneck to revenue.

Enterprise vendor-risk fluency AI platform & security architecture translation Dual-track delivery under deadline pressure Public sector & MNC stakeholder range Procurement-critical GRC support