For boutique consulting firms

Meet tougher client demands without slowing the work they hired you to do.

Tier 1 gives specialist consultancies one senior lead across GRC, cybersecurity and AI governance. Protect sensitive delivery, make assurance answers defensible and give the team an approved route to use AI without building three internal functions.

Start with the next tender, client request or AI rollout. Michael will help define the smallest responsible scope.

Scroll to explore
02Start with the client pressure

Start with the client pressure

The pressure usually arrives through the client.

Bring the request or delivery concern already creating work. Tier 1 follows where it touches contracts, people, cloud systems, suppliers and AI tools, then sets one priority order.

A tender or questionnaire wants evidence

The security questionnaire landed mid-tender, with a deadline and audit rights in the draft contract. The answers have to be true and provable, not hopeful.

A new client raises the standard

An enterprise or government client is pushing its security schedule down the chain, and the firm must meet obligations written for organisations many times its size.

AI is entering client work

Consultants are moving client material through AI tools to hit deadlines. Contract clauses and client trust both assume that is controlled. Right now it is not.

A provider or platform changed the boundary

Recheck where client information, access and responsibility sit before an assumption becomes a control gap.

03Tier 1

Section 03

Why advisory firms are useful targets

An attacker who cannot reach an enterprise directly can often reach its adviser. The firm holds other companies' most sensitive material, with a fraction of their security function around it.

Email compromise

A compromised partner inbox can expose client work, support impersonation and redirect invoices.

Client data theft

Investigations, financials, deal material and strategy can be damaging if disclosed.

AI leakage

Unapproved tools can move client information outside the systems and terms the firm has assessed.

04Tier 1

Section 04

One control model that supports client delivery

Tier 1 connects privacy and contractual requirements, cyber controls, client assurance, safe AI use and incident preparation. Leadership sees one priority view instead of separate compliance, IT and AI projects.

You work directly with Michael, backed by more than 14 years in IT consulting and managed security and Lead Auditor credentials spanning information security, privacy and AI management systems.

05Tier 1

Section 05

Govern AI across client delivery

AI can help a small advisory team move faster, but client intellectual property, investigations and commercial advice need a clear approval path. Tier 1 maps the uses, checks contractual and supplier boundaries, and defines the review required before AI output enters client work.

Approve the use case

Record the business purpose, client context, information involved, owner and consequence of a poor result.

Protect client material

Apply client and contract restrictions before information enters a tool, including embedded AI inside existing platforms.

Review before delivery

Set qualified human review and recordkeeping for output that informs advice, analysis or client decisions.

06Tier 1

Section 06

Start with the client journey and the accounts around it

A useful first review follows information and authority from proposal through delivery, invoicing and project close. It shows where client material is copied, who can act as the firm and whether access ends when the work does.

Client information flow

Map where briefs, working files, investigations and deliverables are received, stored, shared and archived.

Identity and access

Check partner, staff, contractor and client-issued accounts, including privileged access and timely removal.

Invoices and bank changes

Put independent verification and clear escalation around changed payment details and unusual requests.

Client assurance

Organise contracts, controls and evidence so questionnaire answers are accurate and reusable rather than rebuilt under deadline.

07Questions

Straight answers

Common questions

Will stronger security slow down client delivery?

It should not. The aim is to protect the points where client work, access and payments can fail while keeping the rest of the operating model simple. Controls are designed around how your team already delivers work, then adjusted where the risk justifies a change.

We work inside client systems. Can that be included?

Yes. The review can cover client-issued accounts, remote access, file exchange, collaboration platforms and the way access is removed when a project or contractor finishes. Contractual duties and client security questionnaires can be mapped to the same control plan.

Can you work with our existing IT provider?

Yes. Tier 1 sets the priorities, checks that important controls are operating and keeps leadership decisions visible. Your IT provider can continue to operate the systems and implement agreed technical changes.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call