CAPABILITY · PRIVACY & SECURITY

Privacy and security compliance, that wins contracts.

Practitioner-led privacy and security programs for mid-market operating businesses — GDPR compliance, ISO 27001 certification, and the data-governance build that unlocks enterprise contracts and clears diligence. Led by a former Chief Privacy Officer who has stood up the programs that won large corporate deals — not an auditor selling a checklist.

01 / What we actually do

6 plays under one capability.

Privacy & Security Compliance is rarely one job. Engagements typically braid two or three sub-offers, led by the partner with the most relevant operating experience.

01

GDPR and privacy programs

A comprehensive privacy program — data mapping, consent, DSAR handling, breach response — built to satisfy regulators and the procurement teams of the customers you want.

02

ISO 27001 certification

Stand up the information-security management system and carry it through to certification. The credential that clears enterprise vendor-security reviews.

03

Data governance

Who owns what data, where it lives, who can touch it. The governance backbone that makes both privacy and analytics work instead of fighting each other.

04

Privacy-by-design for new systems

Build privacy and security into platform rollouts from day one, instead of retrofitting after an audit finds the gap.

05

Vendor and contract security review

The security and privacy diligence on your vendors — and the answers when your enterprise customers run the same review on you.

06

Deal-readiness and diligence support

Privacy and security posture is a diligence line item. Get it clean before a buyer or partner asks, so it is an asset in the data room, not a discount.

02 / Where this work shows up

Industries we apply privacy & security compliance inside.

All industries
03 / Partners who lead this

One operator, not associates.

The partner who takes your first call is the partner in the room. We don't sell what we haven't run.

05 / Common questions

FAQ.

Who leads privacy and security engagements?

Marcin Samiec, Senior Partner, Tech & AI, and a former VP of Technology and Chief Privacy Officer. He has stood up GDPR and ISO 27001 programs that helped win large corporate contracts.

Why would a finance-led firm do privacy and security work?

Because privacy and security posture is increasingly what wins enterprise contracts and what clears diligence in a sale. It is an operating and deal-value issue, and Marcin has run it from the executive seat.

Do you take us all the way to ISO 27001 certification?

Yes — from gap assessment through the management-system build to the certification audit, with the internal team owning it afterward.

Is this just for tech companies?

No — any business handling customer or employee data at scale, especially one selling into enterprise or preparing for a sale, needs a defensible privacy and security posture.

How does this connect to the rest of the work?

It is built into the digital-transformation and AI engagements — privacy-by-design rather than a separate audit — and it surfaces directly in exit-prep and diligence.

Start a conversation

Talk to the partner who leads Privacy & Security Compliance.