All work
North Highland

Five certifications, first audit, zero critical findings

A risk and compliance program aligned to ISO 27001, HITRUST, HIPAA, GDPR, and UK Cyber Essentials that certified on the first pass and opened more than a billion dollars of revenue.

CISOCIO2014 to 2026
5
Standards certified on the first audit
0
Critical findings
$1B+
Revenue enabled

Context

Clients in healthcare, financial services, and the UK public sector were asking for certifications the firm did not hold, and the deals were large enough that "we follow best practices" was no longer an answer.

Approach

We built one control framework mapped to every target standard rather than five separate programs, so evidence collected once served each audit.

Controls were wired into the platforms people already used: identity, endpoint, ticketing, and the cloud estate. Compliance became a byproduct of operations rather than a spreadsheet exercise.

Internal audit rehearsals ran before every external audit, using the same evidence requests the assessors would make. [verify: order of certifications and rough timeline]

What I took from it

  • One control set, many certifications. The reverse is how compliance programs collapse under their own weight.

Related writing

More work

Cinch: a production collaboration platform built on evidence, not demos

Independent · 2025 to present

A multi-tenant Slack alternative in production at cinchme.app, with tenant isolation proven in the database, a browser suite run against the production image, and a release gate that refuses to promote traffic without evidence.

2,566
Unit and integration tests
92
Browser scenarios against the production image

Replacing 19 legacy systems with one enterprise core

North Highland · 2014 to 2026

A multi-year transformation that retired 19 systems in favor of an integrated ERP, HRIS, PSA, finance, and CRM platform for a global consultancy.

19
Legacy systems retired
5
Countries on one standard