ISO 27001 and privacy regulations - without a security team

Meet ISO 27001 and the privacy regulations
Simply. Quickly. Accountably.

A client or a tender demanding ISO 27001? Handling medical, financial or personal data under the privacy regulations? We build you an audit-ready security program - a smart platform paired with hands-on expert guidance, with no in-house security team.

ISO 27001ISO 27799Privacy Protection Regulations
ISMS / STATUS
Policies & procedures
18/18
Risk assessment
86%
Technical controls
72%
Vendors & third parties
64%
Employee training
91%

sample view

23
average days to audit
0+
organizations certified with us
100%
passed the audit first time
93
ISO 27001 controls managed
24/7
cyber desk with a consultant

Clients & partners

ferfis
pavlovit
cyn.ai
naya notes
ferfis
pavlovit
cyn.ai
naya notes

Plans

Pick the level of support that fits

From expert guidance on top of the platform, to fully outsourcing your security program.

Guidance

Platform + support
  • One expert hour a month for ₪100.
  • 24/7 cyber desk with a consultant.
  • All the features a certified organization needs.
Learn more

Pro

Most popular
  • Full GRC platform.
  • Two expert hours a month - a biweekly meeting plus audit-day support.
  • Penetration testing (PT).
  • End-to-end ISMS, tools included.
Learn more

Build your own plan

Full outsourcing
  • Everything in the platform plan.
  • A dedicated part-time CISO.
  • Certification managed for you - at unmatched price and value.
  • Leading tools from the market.
Learn more

The threat surface

Every exposed asset is on someone's map.

Automated scanning finds new infrastructure within hours of exposure. Controls are what turn that traffic into noise instead of an incident.

Simulated data

Readiness check

How far are you from the requirements?

Five questions, under a minute. You get a readiness score and a recommended starting point.

Starting point

There is a lot to build - and that is fine. Pro or full outsourcing gives you the framework from day one, and an orderly process through to success.

0/5

Your answers are not stored by us, and the result is an initial indication of whether you need support. The score carries no legal meaning, and readiness involves many further steps. Talk to us for a precise picture once you have this first read on where you stand.

Do you have a management-approved information security policy?
Has a risk assessment been done in the last year?
Are your databases and external processors mapped?
Are your vendors mapped and covered by signed DPAs?
Has the process been externally reviewed?

Fine calculator

Privacy fine calculator

Mark the gaps in your organization and get an estimate of the administrative fine under Amendment 13. Runs in your browser - nothing is stored with us.

Estimate only - not legal advice. Currently available in Hebrew.

Open the calculator
“Reservist Business” certificate · click to enlarge
Reservist business

Our values

Contributing to the country - part of our values

GRCistant is founded and run by an active IDF reservist, and officially recognized as a “Reservist Business” by the “Mechabkim Miluimnikim” initiative. We believe those who protect the country protect their clients too - reserve service is inseparable from the way we do business.

Special benefits for reservists

Active reservists and reservist-owned businesses get 10% off the Guidance and Pro plans. Mention it in your message and we will tailor the quote.

Talk to us

We would love to hear what you need

Leave your details and we will come back with a tailored proposal.

Reply within one business day
Free first scoping call
A quote with clear pricing and timeline

We never share your details with third parties. More in our privacy policy.

Information security & compliance consulting - ISO 27001, SOC 2 and Israeli privacy law | GRCistant