SECURE. TRANSFORM.
GOVERN. GROW.
Technology Consulting for a More Secure, Resilient and Intelligent Future.
CISOG Consults Nigeria helps organizations strengthen cybersecurity, manage technology risk, govern artificial intelligence and transform their digital operations.
Get your maturity score immediately — no email required to see your result
Part of the CISOG Group — operating internationally since 2003 · United States · Africa · Middle East
The challenge
Technology creates opportunity.
It also creates risk.
Organizations are under pressure to secure increasingly complex environments, respond to evolving threats, meet regulatory and customer requirements, manage third-party risk, adopt AI responsibly, modernize legacy systems and improve operational resilience.
What we do
Six flagship practices
Integrated advisory and implementation across security, governance and technology.
Cybersecurity
Strategy, risk assessment, architecture, incident readiness and security program development.
Explore →vCISO
CISO-level leadership without full-time executive overhead. Strategy, governance, board reporting.
Explore →GRC & IT Governance
Governance structures, technology risk, controls, compliance and audit readiness.
Explore →AI Governance
Governance frameworks, AI risk, responsible AI, AI security and executive advisory.
Explore →Digital Transformation
Strategy, enterprise architecture, cloud, automation and digital operating models.
Explore →Technology Advisory
IT strategy, architecture, investment advisory, due diligence and operating models.
Explore →Start here
What are you trying to solve?
Enter through your problem, not our org chart.
Why CISOG
Global perspective. U.S.-focused delivery.
Global Perspective
International capability applied to U.S. market requirements and regulatory context.
Business-First Advisory
Technology decisions connected to business objectives, risk and measurable outcomes.
Security by Design
Security, privacy, resilience and governance embedded rather than retrofitted.
Strategy to Execution
We do more than produce reports. We help design, implement and sustain capability.
Solutions
Packaged programs, not billable hours
Fixed scope, defined deliverables, predictable outcomes.
An integrated cybersecurity improvement program spanning assessment, governance, controls, awareness and incident readiness.
Explore solution →Governance maturity assessment, risk and control frameworks, policies, compliance mapping and management reporting.
Explore solution →AI inventory, risk assessment, governance framework, policy, controls and lifecycle monitoring.
Explore solution →From current-state assessment through target architecture, roadmap, execution and sustaining governance.
Explore solution →Independent advisory for CEOs, CIOs, CTOs and COOs on strategy, investment and technology risk.
Explore solution →Quarterly board technology risk briefings covering cyber risk, AI risk, resilience and regulatory exposure.
Explore solution →Industries
Where technology risk is a board issue
Financial Services
Cyber risk, regulatory compliance, third-party risk, AI governance.
Government
Digital government, IT governance, cybersecurity, modernization.
Healthcare
Cybersecurity, privacy, technology governance, transformation.
SMEs & Growth
Fractional leadership, cybersecurity, cloud, IT strategy.
Assessments
How ready is your organization?
Eight assessments — cybersecurity, governance, AI, transformation, network, cloud, application security and identity. Each takes 10–15 minutes and produces a scored report.
Cybersecurity Readiness
10 domains · 10–15 min
Start →GRC Maturity
8 domains · 10–15 min
Start →AI Governance Readiness
10 domains · 10–15 min
Start →Transformation Readiness
10 domains · 10–15 min
Start →Network Security
Perimeter, monitoring, vulnerabilities
Start →Cloud Security
Posture, data protection, identity
Start →Application Security
Secure design, testing, controls
Start →Identity & Access
Provisioning, authn, privileged access
Start →Ready to secure, transform and govern your organization?
Let's discuss your technology priorities and risks.
Home / Services / AI Governance
AI Governance & Responsible AI
GOVERN AI.
ENABLE INNOVATION.
MANAGE RISK.
Artificial intelligence introduces new risks across security, privacy, bias, transparency, intellectual property and accountability. We establish the governance structures that let organizations adopt AI responsibly — without slowing it down.
The lifecycle
Six stages, continuously governed
AI governance is not a one-time framework exercise. It is a lifecycle that runs alongside every AI system in the organization.
Capabilities
What we deliver
AI Governance Framework
Roles, responsibilities, controls and decision-making processes defined at enterprise level.
AI Risk Management
Risk identification and treatment across systems, models, vendors and use cases.
AI Policy
Acceptable and responsible use, aligned to organizational risk appetite.
AI Use-Case Governance
Evaluation and approval processes applied before deployment, not after.
AI Security
Cybersecurity risk across AI systems, training data, models and integrations.
Third-Party AI Risk
Assessment of AI vendors, platforms and externally supplied models.
Cybersecurity Consulting
Build a security program that protects the business.
Cybersecurity is not an IT issue. It is a business, operational, financial and reputational risk. We help organizations build security capability that protects critical systems, information, people and operations.
The business problem
Cybersecurity is a business risk
Boards and executives are accountable for exposure they often cannot see or measure.
Threat
Ransomware, business email compromise, supply-chain intrusion and credential theft continue to target organizations of every size — increasingly through third parties.
Exposure
Cloud adoption, remote access, legacy systems and unmanaged vendor relationships expand the attack surface faster than most security programs adapt.
Impact
Operational disruption, regulatory exposure, contractual failure, customer loss and board-level scrutiny — consequences measured in business terms, not technical ones.
Capabilities
What we do
- Cybersecurity strategy and program development
- Cyber risk assessment and risk register development
- Security governance, policies and standards
- Security architecture and control design
- Vulnerability and security assessment
- Incident response readiness and tabletop exercises
- Security awareness and phishing resilience
- Third-party and supply-chain risk management
- Security metrics and executive reporting
- Audit and regulatory readiness support
How we work
Assess. Prioritize. Design. Implement. Monitor.
A risk-based sequence. We do not start with tooling.
Assess
Establish the current state against a recognized framework and your actual risk profile.
Prioritize
Rank gaps by business impact and likelihood, not by ease of remediation.
Design
Define governance, controls and architecture proportionate to the risk.
Implement
Execute alongside your team, transferring capability rather than dependency.
Monitor
Establish metrics, reporting and review cycles that sustain the improvement.
Deliverables
What you receive
- Cybersecurity assessment report with maturity scoring
- Prioritized risk register with business impact ratings
- Security roadmap sequenced over 12–24 months
- Policy and standards set aligned to your framework
- Board-ready reporting pack and metric definitions
Outcomes
What changes
Framework alignment
Aligned to what your context requires
We align to the framework your regulators, customers and contracts actually reference — not to a house methodology.
Proof
Client outcomes
Case studies publish once outcomes are verified
We publish quantified results only where the measurement methodology is documented and the client has given written permission. Until then, we would rather show you nothing than show you something we cannot stand behind.
Request references under NDAThis is the designed empty state, not a placeholder. The CaseStudyRail component renders this whenever the collection is empty — the page never looks unfinished while evidence is being gathered.
Sector context
Where this work most often starts
Common questions
Before you engage
How long does a cybersecurity assessment take?
A focused assessment typically runs four to six weeks depending on organizational complexity and the number of business units in scope. That covers document review, stakeholder interviews, technical validation, scoring and the report-out. A rapid diagnostic can be completed in two weeks where a board or customer deadline requires it.
Do you replace our existing security team or MSSP?
No. We are an advisory firm. We assess, design and help implement — then hand the program to your team or your service provider to run. Where you have an MSSP, we frequently act as the client-side capability that holds them to a defined standard, which is a different function from the one they perform.
Which framework should we adopt?
The one your obligations already point to. If you sell to U.S. enterprises, SOC 2 is usually the commercial driver. If you operate internationally, ISO/IEC 27001 travels better. NIST CSF is the strongest general-purpose structure for organizing a program and maps cleanly to both. We recommend based on your contracts and regulators, not on what we prefer to deliver.
We are a small organization. Is this proportionate?
Scope scales. A 60-person company does not need the control set of a bank, and applying one to the other produces a program nobody follows. For smaller organizations the more common route is a readiness assessment followed by fractional leadership through our vCISO service, rather than a full program build.
Can you help after an incident?
We support post-incident review, root-cause analysis, control remediation and board reporting. We are not a digital forensics and incident response retainer — if you are in an active incident, engage a DFIR firm first. We can help you select one and can take over the improvement program once containment is complete.
Start with an honest view of where you are
Ten domains, ten minutes, immediate score — then we can talk about what it means.
Services
What we do
Nine practices across security, governance and technology. Most engagements begin in one and extend into two.
Cybersecurity
Strategy, risk assessment, architecture, incident readiness and security program development.
Explore →vCISO
CISO-level leadership without full-time executive overhead. Three engagement tiers.
Explore →GRC & Compliance
Governance structures, controls, compliance mapping and audit readiness.
Explore →IT Governance & Technology Risk
Decision rights, risk registers, governance committees and IT performance reporting.
Explore →AI Governance
Frameworks, AI risk, responsible AI, AI security and executive advisory.
Explore →Digital Transformation
Strategy, enterprise architecture, cloud, automation and operating models.
Explore →Technology Advisory
IT strategy, investment advisory, due diligence and technology roadmaps.
Explore →Cloud & Infrastructure
Cloud readiness, migration advisory, resilience and disaster recovery.
Explore →Software & Applications
Custom software, integration, workflow automation and application modernization.
Explore →Prototype note — all service cards route to the Cybersecurity page, which is the master template the other eight inherit.
Not sure where to start?
Take an assessment and let the result point you.
Financial Services
Technology risk is examination risk.
Banks, credit unions, insurers and fintech organizations operate under examination, contractual and customer scrutiny simultaneously. We help you build security and governance capability that holds up to all three.
Industry challenges
What we are asked about most
Examination readiness
Evidence that controls operate as documented — produced on demand rather than assembled under pressure the week before.
Third-party concentration
Core processors, cloud providers and fintech partners create dependency that regulators increasingly treat as systemic.
Operational resilience
Recovery objectives that reflect what the business actually needs, tested against realistic disruption scenarios.
AI in credit and service
Model governance, explainability and fair-lending exposure as AI moves into decisioning and customer contact.
Legacy core constraints
Modernization sequencing where the core system cannot be replaced on the timeline the strategy assumes.
Board fluency
Directors who are accountable for technology risk without a technology background — and reporting that closes the gap.
Risk landscape
Where exposure concentrates
Identity & access
Privileged access to core systems and payment rails remains the highest-value target.
Vendor chain
Fourth-party exposure through providers your contracts do not reach.
Data protection
Customer financial data across increasingly distributed environments.
Business continuity
Recovery capability measured against contractual and regulatory tolerance.
Priority services
Where we typically start
Cybersecurity
Assessment, governance, architecture and incident readiness.
Explore →GRC & Compliance
Control frameworks, compliance mapping and examination support.
Explore →Third-Party Risk
Vendor assessment, concentration analysis and ongoing monitoring.
Explore →AI Governance
Model inventory, risk assessment and decisioning oversight.
Explore →vCISO
Fractional security leadership and board reporting.
Explore →Digital Transformation
Core modernization sequencing and cloud strategy.
Explore →Regulatory context
Obligations we work against
Applicability depends on charter, size and activity. We map obligations before we design controls.
Discuss financial services technology risk
A first conversation is a scoping conversation, not a pitch.
Government & Public Sector
Technology and cybersecurity for the public sector.
CISOG Consults Nigeria supports federal, state, local and education organizations with cybersecurity, IT governance, AI governance and technology modernization.
Core competencies
Capability matrix
Contracting information
Registration & identifiers
Procurement officers need these before a conversation is useful. Every field is a nullable CMS entry — the page is complete without them.
Differentiators
Why public-sector buyers engage us
Executive fluency
We brief agency leadership and elected officials, not only technical staff.
Framework literacy
Work grounded in NIST SP 800-53, CSF and CIS rather than proprietary methodology.
AI governance depth
A structured practice at a point when public-sector AI policy is still forming.
Implementation capability
Access to the wider CISOG technology ecosystem beyond advisory alone.
Partnering
Prime contractors & system integrators
We work as a subcontractor and specialist partner on cybersecurity, governance and AI governance scopes. Teaming agreements, past-performance references and capability documentation available on request.
Past performance
Selected experience publishes once contract references and permission to cite are confirmed. We do not list engagements we cannot substantiate to a contracting officer.
Download the capability statement
Company overview, core competencies, differentiators and contact information in a single PDF.
Solutions
Practical solutions for complex technology challenges.
CISOG combines advisory expertise and practical delivery into focused solutions designed around common organizational challenges.
CyberSecure 360
A structured cybersecurity improvement program covering assessment, risk, governance, controls, awareness and resilience.
vCISO
Flexible cybersecurity leadership for organizations that need experienced security direction without building a full-time executive structure.
GRC 360
An integrated governance, risk and compliance improvement program.
AI Governance 360
A structured approach to governing AI adoption, risk and responsible use.
Digital Transformation 360
A strategy-to-execution framework for technology and operating-model transformation.
Executive Technology Advisory
Independent technology guidance for senior executives and boards.
Board Cybersecurity & AI Advisory
Executive-level briefings and advisory support addressing cyber, AI and technology risk.
Which solution fits your situation?
Ten minutes of assessment usually answers this faster than a meeting.
Cybersecurity Consulting
Build a security program that protects the business.
Cybersecurity is no longer only an IT issue. A cyber incident can affect operations, finances, customers, reputation and organizational resilience.
CISOG helps organizations understand their cybersecurity risk, strengthen security capabilities and develop practical programs aligned with business priorities.
Cybersecurity Services
Cybersecurity Strategy
Develop a practical cybersecurity strategy aligned with organizational objectives and risk.
Cyber Risk Assessment
Identify critical assets, threats, vulnerabilities and business-impacting risks.
Security Governance
Establish policies, accountability, decision rights and management structures.
Security Architecture
Design security capabilities aligned with business and technology requirements.
Vulnerability & Security Assessment
Identify weaknesses that could expose systems, applications or information.
Incident Response Readiness
Prepare the organization to detect, respond to and recover from cybersecurity incidents.
Security Awareness
Strengthen the human layer of cybersecurity through education, awareness and behavior-focused programs.
Third-Party Cyber Risk
Identify and manage cybersecurity risks associated with vendors, suppliers and technology partners.
Our Cybersecurity Methodology
Assess
Prioritize
Design
Implement
Monitor
Framework-Aligned Advisory
Depending on client requirements, engagements may be aligned with recognized frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, ISO/IEC 27001 and COBIT. Framework selection should always be based on the client’s business, regulatory and risk environment.
Frequently asked questions
What does a cybersecurity assessment include?
A cybersecurity assessment examines relevant technology, processes, governance and controls to identify material security risks and improvement priorities.
Does CISOG provide ongoing cybersecurity advisory?
Yes. Organizations can engage CISOG for project-based or ongoing advisory support, including vCISO services.
Can CISOG help develop cybersecurity policies?
Yes. We develop and improve cybersecurity policies, standards, procedures and governance documentation.
Does CISOG provide cybersecurity training?
Yes. Cybersecurity awareness and capability development can form part of a broader cybersecurity improvement program.
Start with an honest view of where you are
A cybersecurity assessment identifies what matters most, in business terms.
Virtual CISO
CISO-level leadership without full-time executive overhead.
Many organizations need experienced cybersecurity leadership but do not need—or are not ready for—a full-time CISO.
CISOG’s vCISO service provides flexible cybersecurity leadership tailored to organizational needs.
What Our vCISO Does
Your vCISO can provide:
- Cybersecurity strategy
- Security governance
- Executive and board reporting
- Cyber risk management
- Security roadmap development
- Policy and standards development
- Security metrics and KPIs
- Audit readiness
- Third-party risk management
- Incident-response preparedness
- Security awareness strategy
- Security program oversight
Who Needs a vCISO?
A vCISO can be valuable for:
- Growing organizations
- Organizations without an internal CISO
- Organizations transitioning between security leaders
- Organizations facing increasing cyber risk
- Organizations preparing for audits
- Organizations undergoing digital transformation
- Organizations implementing a formal cybersecurity program
vCISO Engagement Models
vCISO Essentials
Focused guidance for smaller organizations establishing core cybersecurity capability.
vCISO Advisory
Ongoing strategic cybersecurity leadership for growing organizations.
vCISO Enterprise
Comprehensive strategic advisory for complex organizations requiring sustained executive security support.
Scope and Pricing
Specific scope, frequency and pricing should be customized following an initial assessment.
Frequently asked questions
Is a vCISO the same as a full-time CISO?
A vCISO provides many strategic CISO functions on a fractional or advisory basis rather than as a permanent full-time executive.
How often does a vCISO engage with management?
Engagement frequency depends on organizational needs and service scope and can range from periodic advisory sessions to ongoing program leadership.
Can a vCISO report to the board?
Yes. Board and executive reporting can be included in the engagement.
Talk to a vCISO advisor
A first conversation is a scoping conversation, not a pitch.
Governance, Risk & Compliance
Governance. Risk. Compliance.
Strong governance creates accountability. Effective risk management creates resilience. Effective compliance creates trust.
CISOG helps organizations establish practical governance, risk and compliance capabilities that align technology with business objectives.
Our GRC Capabilities
IT Governance
Define decision rights, accountability, governance structures and technology oversight.
Cybersecurity Governance
Establish structures for managing security strategy, risk and accountability.
Technology Risk Management
Identify, assess, prioritize and manage technology-related risks.
Compliance Advisory
Evaluate organizational requirements against applicable regulatory, contractual and industry obligations.
Policy & Standards Development
Create practical policies, standards and procedures.
Internal Controls
Design and improve technology and cybersecurity controls.
Audit Readiness
Prepare organizations for internal, external and customer audits.
Third-Party Risk Management
Assess technology and cybersecurity risks introduced by suppliers and partners.
Our GRC Lifecycle
Assess
Design
Implement
Monitor
Improve
Frameworks
Depending on client requirements, our work may reference:
- NIST Cybersecurity Framework
- ISO/IEC 27001
- ISO/IEC 27701
- COBIT
- CIS Controls
- SOC 2
- PCI DSS
- Applicable privacy and regulatory requirements
Frequently asked questions
What is GRC?
GRC refers to governance, risk and compliance—the structures and processes organizations use to make informed decisions, manage risk and meet applicable obligations.
Does GRC include cybersecurity?
Cybersecurity governance and technology risk can form important components of an organization’s GRC program.
Can CISOG develop policies?
Yes. Policy and standards development can be included within GRC engagements.
Assess your GRC maturity
Understand where your governance, risk and compliance capability actually stands.
IT Governance
Govern technology with confidence.
Technology creates value only when it is properly governed.
CISOG helps organizations establish clear accountability, decision-making structures, controls and risk-management practices for technology.
Our IT Governance Services
- IT governance assessments
- Technology governance frameworks
- Governance committees
- Technology policies
- Technology risk registers
- IT controls
- Technology performance metrics
- Executive reporting
- Risk reporting
- IT operating models
- Technology decision rights
Technology Risk
We help organizations identify risks associated with:
- Infrastructure
- Applications
- Cloud
- Data
- Cybersecurity
- Vendors
- AI
- Digital transformation
- Business continuity
Executive Technology Governance
We help boards and senior executives obtain clearer visibility into technology performance, risk and strategic priorities.
Frequently asked questions
Why is IT governance important?
It helps organizations ensure that technology decisions support business objectives while risks and accountability are properly managed.
Does CISOG work with boards?
Yes. Executive and board-level technology risk advisory can be included in appropriate engagements.
Discuss your governance requirements
Clear accountability is the foundation of everything else.
AI Governance & Responsible AI
Govern AI. Enable innovation. Manage risk.
Artificial intelligence is changing how organizations operate, make decisions and serve customers.
It also introduces new risks involving security, privacy, transparency, accountability, intellectual property, bias and operational resilience.
CISOG helps organizations establish governance structures that enable responsible and secure AI adoption.
AI Governance Services
AI Governance Framework
Define roles, responsibilities, decision rights, controls and oversight.
AI Risk Management
Identify and manage risks associated with AI systems, models, data, vendors and use cases.
AI Policy
Establish clear organizational requirements for responsible AI use.
AI Use-Case Governance
Evaluate proposed AI applications before deployment.
AI Security
Address cybersecurity risks associated with AI systems, models, data and integrations.
AI Privacy & Data Governance
Establish appropriate governance for data used by AI systems.
Third-Party AI Risk
Evaluate AI vendors, platforms and externally supplied models.
Responsible AI
Promote transparency, accountability, safety, human oversight and responsible deployment.
Executive AI Advisory
Help executives and boards understand the strategic opportunities and risks associated with AI.
Our AI Governance Lifecycle
Discover
Assess
Govern
Control
Monitor
AI Governance Is Not About Stopping Innovation
The objective is not to prevent organizations from using AI. The objective is to create the governance, risk and accountability structures that allow AI innovation to happen responsibly and at scale.
Frequently asked questions
What is AI governance?
AI governance is the framework of policies, roles, controls, processes and oversight used to manage how an organization develops, acquires, deploys and uses AI.
Why does my organization need AI governance?
AI can create security, privacy, operational, legal, ethical and reputational risks. Governance provides a structured way to manage those risks while enabling innovation.
Does CISOG provide AI policy development?
Yes. AI policy development can form part of an AI governance engagement.
Assess your AI governance readiness
Ten domains, ten minutes, immediate score.
Digital Transformation
Turn technology investment into business performance.
Digital transformation is more than implementing new software. It requires alignment between strategy, people, processes, technology, data and governance.
CISOG helps organizations develop and execute practical transformation programs focused on measurable business outcomes.
Our Digital Transformation Services
- Digital transformation strategy
- IT strategy
- Enterprise architecture
- Business process transformation
- Technology modernization
- Cloud transformation
- Workflow automation
- Data and analytics
- Digital operating models
- Technology roadmaps
- Change management
- Digital governance
Our Transformation Model
Strategy
Architecture
Technology
People
Process
Governance
Outcomes
Transformation Outcomes
Our objective is to help organizations:
- Improve operational efficiency
- Modernize technology
- Reduce technology complexity
- Improve customer experience
- Strengthen resilience
- Enable innovation
- Improve decision-making
- Align technology investments with strategy
Frequently asked questions
Does digital transformation require replacing all existing systems?
No. Effective transformation may combine modernization, integration, optimization and selective replacement.
Does CISOG support implementation?
Implementation support can be included depending on engagement scope and requirements.
Discuss your transformation strategy
Start with outcomes, not platforms.
Technology Advisory
Make better technology decisions.
Technology decisions can create long-term financial, operational and strategic consequences.
CISOG provides independent, business-focused technology advice to help executives make informed decisions about technology investments, architecture, modernization and transformation.
Advisory Services
IT Strategy
Align technology investments with business strategy.
Enterprise Architecture
Create a structured blueprint connecting business, information, applications and technology.
Cloud Strategy
Develop practical strategies for cloud adoption, migration and optimization.
Technology Modernization
Identify legacy technology and develop modernization roadmaps.
Technology Due Diligence
Assess technology capabilities, risks, architecture and opportunities.
Technology Investment Advisory
Evaluate investments based on strategic value, risk and expected outcomes.
IT Operating Models
Define the people, processes, governance and capabilities required to operate technology effectively.
Frequently asked questions
Who uses technology advisory services?
CEOs, boards, CIOs, CTOs, COOs, CISOs, investors and organizations making significant technology decisions.
Is CISOG vendor-neutral?
Our advisory approach is positioned around business requirements and outcomes rather than technology sales.
Request an executive technology briefing
Independent advice, framed for the people who decide.
Cloud & Infrastructure
Modernize your technology foundation.
Cloud and infrastructure decisions affect security, performance, resilience, scalability and cost.
CISOG helps organizations develop practical strategies for modernizing their technology foundations.
Cloud Services
- Cloud strategy
- Cloud readiness assessment
- Migration advisory
- Hybrid cloud strategy
- Cloud governance
- Cloud security considerations
- Cloud optimization
Infrastructure Services
- Infrastructure modernization
- Network architecture
- Storage strategy
- Resilience
- Disaster recovery
- Business continuity
- Infrastructure security
Our Approach
Assess
Architect
Roadmap
Implement
Optimize
Frequently asked questions
Does CISOG provide cloud migration services?
CISOG can provide strategy, assessment, architecture and implementation support depending on the engagement scope.
Can cloud transformation include cybersecurity?
Yes. Security and governance should be incorporated into cloud transformation from the beginning.
Discuss your infrastructure strategy
Modernization sequenced by business dependency, not architecture diagrams.
Software & Applications
Technology solutions built around your business.
Technology should adapt to the way your organization operates—not the other way around.
CISOG supports organizations that need to develop, integrate, modernize or automate technology solutions.
Application Capabilities
- Custom software solutions
- Web applications
- Enterprise applications
- Mobile applications
- Application modernization
- Systems integration
- API integration
- Workflow automation
- Software architecture
- Data and analytics solutions
From Strategy to Technology
Business Requirement
Architecture
Development
Integration
Deployment
Improvement
CISOG Technology Ecosystem
Application and software capability can be integrated with CISOG’s broader consulting, cybersecurity, infrastructure and technology advisory services.
Discuss your technology solution
Tell us what the business needs to do differently.
Industries
Technology advisory for complex industries.
Different industries face different technology risks, regulatory expectations and transformation priorities. CISOG combines cross-industry technology expertise with sector-focused advisory.
Financial Services
Financial organizations operate in a highly technology-dependent and risk-sensitive environment.
Explore →Government & Public Sector
Government organizations increasingly depend on digital systems to deliver essential services.
Explore →SMEs & Growth Companies
Growing organizations need strong technology foundations, but they do not always need large internal technology and cybersecurity
Explore →Healthcare
Healthcare organizations operate in environments where technology, sensitive information, operational continuity and patient exper
Explore →Energy & Utilities
Energy and utilities organizations operate critical, interconnected environments where operational technology, IT, data, infrastru
Explore →Manufacturing
Manufacturers increasingly depend on connected operational technology, industrial systems, enterprise applications, data and autom
Explore →Professional Services
Professional services firms compete on expertise, reputation, responsiveness and client trust.
Explore →Which sector are you in?
Every industry page has a downloadable capability statement.
Financial Services
Secure, govern and transform financial technology.
Financial organizations operate in a highly technology-dependent and risk-sensitive environment.
CISOG helps financial institutions and fintech organizations strengthen cybersecurity, technology governance and responsible innovation.
Key Challenges
- Cybersecurity threats
- Technology risk
- Third-party risk
- Regulatory expectations
- AI adoption
- Digital transformation
- Data protection
- Operational resilience
CISOG Capabilities
- Cybersecurity
- vCISO
- GRC
- Technology risk
- AI governance
- Third-party risk
- Digital transformation
- Technology advisory
Discuss Your Financial Technology Risk
A first conversation is a scoping conversation, not a pitch.
Government & Public Sector
Technology & cybersecurity for the public sector.
Government organizations increasingly depend on digital systems to deliver essential services.
That dependence creates opportunities for improved service delivery—and creates significant requirements for cybersecurity, governance, resilience and responsible technology adoption.
Key Challenges
- Cybersecurity strategy
- Cyber risk management
- IT governance
- Digital transformation
- Technology modernization
- AI governance
- Data governance
- Cybersecurity awareness
- Technology strategy
- Executive advisory
CISOG Capabilities
Digital government — assess and improve the technology, governance and operating capabilities required to deliver modern digital services
Responsible government AI — governance, accountability, risk management and human oversight for public-sector AI adoption
Download Capability Statement
A first conversation is a scoping conversation, not a pitch.
SMEs & Growth Companies
Enterprise technology expertise without enterprise overhead.
Growing organizations need strong technology foundations, but they do not always need large internal technology and cybersecurity teams.
CISOG provides flexible access to experienced technology and cybersecurity advisory capabilities.
Services for Growing Organizations
- vCISO
- Cybersecurity assessment
- Cybersecurity strategy
- GRC
- IT governance
- Cloud advisory
- Technology strategy
- AI governance
- Digital transformation
Grow Securely
We help organizations establish the technology governance and cybersecurity foundations needed to grow with confidence.
Talk to an Advisor
A first conversation is a scoping conversation, not a pitch.
Healthcare
Protect patient data. Modernize care operations.
Healthcare organizations operate in environments where technology, sensitive information, operational continuity and patient experience are tightly connected.
CISOG helps organizations address cybersecurity, privacy, technology governance, risk and digital transformation through an integrated advisory model.
Key Challenges
- Cybersecurity
- Privacy and sensitive data protection
- Technology governance
- Technology risk management
- Operational continuity
- Digital transformation
- AI governance
- Third-party risk
Who We Serve
- Hospitals and health systems
- Physician practices and medical groups
- Health plans and payers
- Home health and long-term care organizations
- Life sciences and pharmaceutical organizations
- Health technology and digital health companies
Discuss Healthcare Technology Risk
A first conversation is a scoping conversation, not a pitch.
Energy & Utilities
Protect critical infrastructure. Sustain reliable operations.
Energy and utilities organizations operate critical, interconnected environments where operational technology, IT, data, infrastructure, reliability and regulatory expectations converge.
CISOG helps organizations strengthen cybersecurity, manage technology risk, modernize systems and transform operations while supporting resilience and sustainable growth.
Key Challenges
- Operational technology (OT) security
- Industrial control systems (ICS)
- Cyber resilience
- Infrastructure modernization
- Technology risk management
- Regulatory and reliability expectations
- Digital transformation
- Incident readiness
Who We Serve
- Electric utilities — generation, transmission and distribution
- Natural gas utilities and pipeline operators
- Oil & gas companies
- Renewable energy producers
- Water and wastewater utilities
- Power marketers and energy traders
- Energy service providers and EPC firms
Discuss Energy & Utilities Technology Risk
A first conversation is a scoping conversation, not a pitch.
Manufacturing
Secure connected operations. Modernize with confidence.
Manufacturers increasingly depend on connected operational technology, industrial systems, enterprise applications, data and automation.
CISOG helps organizations strengthen industrial cybersecurity, manage technology risk, modernize systems and adopt emerging technologies while supporting efficiency, quality, resilience and sustainable growth.
Key Challenges
- Industrial cybersecurity
- OT/IT convergence
- IoT and connected assets
- Intellectual property protection
- Enterprise systems
- Automation
- Technology risk management
- Digital transformation
Who We Serve
- Discrete manufacturers — automotive, machinery, electronics and components
- Process manufacturers — chemicals, materials and industrial products
- Food & beverage manufacturers
- Pharmaceutical and medical-device manufacturers
- Packaging and consumer-goods manufacturers
- Industrial equipment and component manufacturers
- Contract manufacturers and assemblers
Discuss Manufacturing Technology Risk
A first conversation is a scoping conversation, not a pitch.
Professional Services
Protect client trust. Scale with confidence.
Professional services firms compete on expertise, reputation, responsiveness and client trust.
Their technology environment must therefore support secure collaboration, confidential information, resilient operations, efficient workflows, responsible AI adoption and scalable growth. CISOG provides integrated technology and cybersecurity advisory designed around these priorities.
Key Challenges
- Cybersecurity and cyber resilience
- Client data confidentiality
- Secure collaboration
- GRC
- Cloud
- AI governance
- Technology strategy
- Operational resilience
Who We Serve
- Consulting, advisory and management consulting firms
- Accounting, audit and tax practices
- Law firms and legal services organizations
- Engineering, architecture and technical services firms
- Insurance, actuarial and risk advisory firms
- Real estate, property and professional advisory firms
- Marketing, media and creative professional services firms
- Specialist and knowledge-intensive service organizations
Discuss Professional Services Technology Risk
A first conversation is a scoping conversation, not a pitch.
Legal
Privacy Policy
CISOG Consults Nigeria Limited · A member of the Cisog Group of Companies · Effective 16 August 2026
Privacy Policy
CISOG Consults Nigeria Limited
Governing the use of cisoggroup.com A member of the Cisog Group of Companies
Effective Date: August 16, 2026
CISOG TECHNOLOGY CONSULTS LLC — PRIVACY POLICY
CISOG Consults Nigeria Limited
Effective Date: August 16, 2026
1. Introduction
CISOG Consults Nigeria Limited, a Delaware limited liability company and a member of the Cisog Group of Companies ("Cisog," "Company," "we," "us," or "our"), respects your privacy and is committed to protecting the personal information of visitors to our website at https://cisoggroup.com (the "Website"). This Privacy Policy explains what information we collect, how we use and share it, the choices available to you, and how you can contact us about our privacy practices.
This Privacy Policy applies to information collected through the Website. It does not apply to information collected offline, through a separate client engagement agreement, or through third-party websites that may be linked from the Website. By using the Website, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy is incorporated by reference into, and should be read together with, our Terms and Conditions.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised "Effective Date." Your continued use of the Website after changes are posted constitutes your acceptance of the updated Privacy Policy.
2. Information We Collect
We may collect the following categories of information when you visit or interact with the Website:
a. Information You Provide Directly. When you fill out a contact form, request a consultation, subscribe to
our newsletter or marketing updates, or otherwise communicate with us, we may collect information such as your name, email address, phone number, job title, company or organization name, and the content of your message or inquiry.
b. Usage and Technical Data. When you browse the Website, we and our service providers may
automatically collect certain technical information, including your IP address, browser type and version, device type and operating system, referring and exit pages, pages viewed, the date and time of your visit, and other diagnostic data, typically through server logs, cookies, and similar technologies described in Section 4 below.
c. Location Data. We may infer general geographic location (such as country, region, or city) from your IP
address or similar technical data. We do not collect precise GPS location through the Website.
d. Information from Third Parties. We may receive limited information about you from third-party analytics
or advertising platforms (such as Google Analytics or social media advertising tools) when you interact with our ads or content on those platforms.
We do not knowingly collect sensitive categories of personal information (such as government identification numbers, financial account details, or health information) through the Website, and we ask that you not submit such information through our contact forms.
CISOG TECHNOLOGY CONSULTS LLC — PRIVACY POLICY
3. How We Use Your Information
We use the information we collect for purposes including:
a. Responding to your inquiries and requests for information about our cybersecurity consulting services;
b. Providing, operating, maintaining, and improving the Website and our Services;
c. Sending you marketing communications, newsletters, or updates about our services and cybersecurity
insights, where you have opted in or as otherwise permitted by applicable law, and always with the ability to unsubscribe;
d. Analyzing usage trends and Website performance through analytics tools to improve content, design, and
functionality;
e. Detecting, investigating, and preventing fraudulent, unauthorized, or illegal activity, and protecting the
security and integrity of the Website;
f. Complying with applicable laws, regulations, legal processes, or enforceable governmental requests; and
g. For any other purpose disclosed to you at the time the information is collected, or with your consent.
4. Cookies and Tracking Technologies
The Website uses cookies, web beacons, pixels, and similar tracking technologies to recognize your browser, remember preferences, and understand how visitors interact with the Website. We use, or may use, third-party analytics and advertising tools such as Google Analytics and social media advertising pixels (for example, LinkedIn and Meta) to measure Website traffic, evaluate the effectiveness of our marketing, and improve the relevance of our content.
These technologies may collect information such as your IP address, browser and device characteristics, pages visited, time spent on the Website, and referring website. Third-party analytics and advertising providers may use this data in accordance with their own privacy policies, and in some cases may combine it with information collected from other websites or services.
Your choices. Most web browsers allow you to control cookies through their settings, including blocking or deleting cookies. You may also opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, and you may manage interest-based advertising preferences through the Digital Advertising Alliance (www.aboutads.info) or the Network Advertising Initiative (www.networkadvertising.org). Please note that disabling cookies may affect the functionality of the Website.
We do not currently respond to "Do Not Track" browser signals, as no uniform industry standard for recognizing such signals has been adopted.
5. Marketing Communications
If you subscribe to our newsletter, request updates, or otherwise opt in to receive marketing communications from us, we will use your email address to send you information about our cybersecurity consulting services, training content, and related updates. You may opt out of marketing communications at any time by clicking the
CISOG TECHNOLOGY CONSULTS LLC — PRIVACY POLICY
"unsubscribe" link included in our emails or by contacting us using the information in Section 13 below. Even if you opt out of marketing communications, we may still send you transactional or administrative messages related to an inquiry or engagement you have with us.
6. How We Share Your Information
We do not sell your personal information. We may share the information we collect in the following circumstances:
a. Service Providers. With third-party vendors, consultants, and service providers who perform services on
our behalf, such as website hosting, analytics, email delivery, and customer relationship management, under confidentiality and data protection obligations consistent with this Privacy Policy;
b. Affiliates. With other members of the Cisog Group of Companies for internal business, administrative,
and service-delivery purposes;
c. Legal Compliance and Protection. When required by law, regulation, legal process, or governmental
request, or when we believe disclosure is necessary to protect our rights, property, or safety, or the rights, property, or safety of others;
d. Business Transfers. In connection with a merger, acquisition, reorganization, financing, or sale of
assets involving Cisog Group, in which personal information may be transferred as a business asset, subject to this Privacy Policy or a policy at least as protective; and
e. With Your Consent. For any other purpose disclosed to you and with your consent.
7. International Data Transfers
Cisog Group operates internationally, including in the United States, Nigeria, and the United Arab Emirates. Information you provide through the Website may be accessed, stored, or processed in countries other than your country of residence, including the United States and Nigeria, which may have data protection laws that differ from those in your jurisdiction. Where required by applicable law, we implement appropriate safeguards, such as standard contractual clauses, to protect personal information transferred internationally.
8. Data Retention
We retain personal information collected through the Website only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including responding to your inquiries, maintaining business records, and complying with our legal, accounting, or regulatory obligations. When personal information is no longer needed for these purposes, we take reasonable steps to delete, anonymize, or securely dispose of it.
9. Data Security
We implement reasonable technical and organizational measures designed to protect personal information from unauthorized access, use, alteration, or disclosure. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are
CISOG TECHNOLOGY CONSULTS LLC — PRIVACY POLICY
responsible for maintaining the confidentiality of any information you transmit to us and for using caution when submitting information through the internet.
10. Children's Privacy
The Website is intended for a business and professional audience and is not directed to, and we do not knowingly collect personal information from, children under the age of 13 (or the applicable age of consent in your jurisdiction). If we become aware that we have inadvertently collected personal information from a child without appropriate parental consent, we will take steps to delete that information as soon as reasonably possible. If you believe a child has provided us with personal information, please contact us using the details in Section 13.
11. Your Privacy Rights
California Residents (CCPA/CPRA) If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), grants you certain rights with respect to your personal information, including the right to: (a) know the categories and specific pieces of personal information we have collected about you; (b) know the categories of sources, purposes, and third parties involved in that collection and disclosure; (c) request deletion of personal information we have collected from you, subject to certain exceptions; (d) request correction of inaccurate personal information; (e) opt out of the "sale" or "sharing" of personal information (Cisog does not sell personal information, and does not knowingly "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, except potentially through the use of advertising cookies described in Section 4, over which you may exercise the opt-out choices described there); and (f) not be discriminated against for exercising these rights. To exercise your CCPA/CPRA rights, please contact us using the details in Section 13. We will verify your request using the information available to us before responding.
European Economic Area, United Kingdom, and Other Applicable Jurisdictions (GDPR) If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar data protection laws, you may have rights under the General Data Protection Regulation ("GDPR") or equivalent local law, including the right to: (a) access the personal information we hold about you; (b) request correction of inaccurate or incomplete personal information; (c) request erasure of your personal information, subject to certain exceptions; (d) restrict or object to our processing of your personal information; (e) request portability of personal information you have provided to us; and (f) withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
Where we rely on your consent to process personal information (for example, for marketing emails or certain cookies), the legal basis for processing is your consent. Where we process personal information to respond to your inquiries or pursue a prospective business relationship, the legal basis is our legitimate interest in operating and promoting our business, or the steps necessary to enter into a contract at your request. You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal information does not comply with applicable law.
CISOG TECHNOLOGY CONSULTS LLC — PRIVACY POLICY
All Users Regardless of your location, you may contact us at any time to ask about the personal information we hold about you, to request that we correct or delete it, or to ask us to stop using it for a particular purpose, and we will respond in accordance with applicable law.
12. Third-Party Links
The Website may contain links to third-party websites, including other Cisog Group affiliate sites, that are not operated by CISOG Consults Nigeria Limited. This Privacy Policy does not apply to those third-party websites. We encourage you to review the privacy policies of any third-party website you visit.
13. Contact Us
If you have questions, comments, or requests regarding this Privacy Policy or our data practices, or if you wish to exercise any of the rights described above, please contact us at:
CISOG Consults Nigeria Limited
c/o Cisog Group
Email: info@cisoggroup.com
Phone: +234 (0) 803 535 4363
Group Head Office: Flat 3 and 4, Block 505, MET Quarter, Kodesoh Street, Ikeja, Lagos, Nigeria
Website: https://cisoggroup.com
Legal
Terms and Conditions
CISOG Consults Nigeria Limited · A member of the Cisog Group of Companies · Effective 16 August 2026
Terms And Conditions
CISOG Consults Nigeria Limited
Governing the use of cisoggroup.com A member of the Cisog Group of Companies
Effective Date: August 16, 2026
CISOG TECHNOLOGY CONSULTS LLC — TERMS AND CONDITIONS
CISOG Consults Nigeria Limited
Effective Date: August 16, 2026
1. Introduction and Acceptance of Terms
These Terms and Conditions ("Terms") constitute a legally binding agreement between you ("User," "you," or "your") and CISOG Consults Nigeria Limited, a Delaware limited liability company and a member of the Cisog Group of Companies ("Cisog," "Company," "we," "us," or "our"), governing your access to and use of the website located at https://cisoggroup.com (the "Website"), together with any content, features, tools, and services made available through it (collectively, the "Services").
By accessing or using the Website, you acknowledge that you have read, understood, and agree to be bound by these Terms and by our Privacy Policy, which is incorporated herein by reference. If you do not agree to these Terms, you must not access or use the Website.
We reserve the right to update, modify, or replace any part of these Terms at our sole discretion. Any changes will be effective immediately upon posting of the revised Terms on the Website, with the "Effective Date" updated accordingly. Your continued use of the Website following the posting of changes constitutes your acceptance of those changes. We encourage you to review these Terms periodically.
2. About CISOG Consults Nigeria Limited
CISOG Consults Nigeria Limited is the United States operating entity of the Cisog Group, an international group of companies headquartered in Lagos, Nigeria, that provides business, technology, and infrastructure consulting services, including cybersecurity solutions and awareness consulting. The Website is maintained to provide information about our cybersecurity consulting practice areas, thought leadership content, and a means for prospective clients and partners to contact us regarding our services.
The Website is currently informational in nature. It does not process online payments, sell products, or offer paid subscriptions, and no user accounts are required to browse the Website. Any engagement for consulting, training, or advisory services is entered into separately, pursuant to a distinct written agreement, statement of work, or proposal between you (or your organization) and CISOG Consults Nigeria Limited, the terms of which will govern that engagement and will control over these Terms in the event of a conflict.
3. Eligibility
The Website is intended for business and professional audiences and is not directed at children. By using the Website, you represent that you are at least 18 years of age, or that you are accessing the Website under the supervision of a parent or legal guardian who agrees to be bound by these Terms on your behalf. If you are using the Website on behalf of a company, organization, or other legal entity, you represent that you have the authority to bind that entity to these Terms, in which case "you" refers to that entity.
4. Permitted Use of the Website
CISOG TECHNOLOGY CONSULTS LLC — TERMS AND CONDITIONS
Subject to your compliance with these Terms, Cisog grants you a limited, non-exclusive, non-transferable, revocable license to access and make personal, non-commercial use of the Website. You agree not to:
a. Use the Website for any unlawful purpose or in violation of any applicable local, state, national, or
international law or regulation;
b. Attempt to gain unauthorized access to any portion of the Website, related systems or networks, or any
Cisog server, database, or account;
c. Interfere with, disrupt, or place an undue burden on the Website or the networks or services connected to
the Website, including through the introduction of viruses, malware, or other harmful code;
d. Use any automated means, including robots, spiders, scrapers, or other data-gathering or extraction
tools, to access, monitor, or copy any portion of the Website without our prior written consent;
e. Reproduce, duplicate, copy, sell, resell, or otherwise exploit any portion of the Website or its content for
any commercial purpose without our express written permission;
f. Impersonate any person or entity, or misrepresent your affiliation with any person or entity, in connection
with your use of the Website;
g. Submit false, misleading, or fraudulent information through any contact, inquiry, or communication form
on the Website; or
h. Engage in any conduct that, in our sole discretion, restricts or inhibits any other person from using or
enjoying the Website.
We reserve the right, but assume no obligation, to monitor use of the Website to ensure compliance with these Terms.
5. Intellectual Property Rights
All content on the Website, including but not limited to text, graphics, logos, images, videos, training materials, course content, audio clips, data compilations, software, and the design, selection, and arrangement thereof (collectively, "Content"), is the property of CISOG Consults Nigeria Limited, the broader Cisog Group, or our licensors, and is protected by United States and international copyright, trademark, patent, trade secret, and other intellectual property or proprietary rights laws.
The names "Cisog," "Cisog Group," "Cisog Technology Consults," and all related logos, product and service names, designs, and slogans are trademarks of Cisog Group and its affiliates. You may not use such marks without our prior written permission.
Except as expressly permitted in these Terms, no part of the Website or its Content may be reproduced, distributed, modified, publicly displayed, publicly performed, republished, downloaded, stored, or transmitted in any form or by any means without our prior written consent. You may view, download, and print portions of the Website solely for your own informational, non-commercial use, provided you retain all copyright and other proprietary notices contained in the original Content.
6. User Submissions and Communications
CISOG TECHNOLOGY CONSULTS LLC — TERMS AND CONDITIONS
If you submit any inquiry, message, feedback, testimonial, or other information to us through a contact form, email, or other communication channel on the Website ("Submissions"), you grant Cisog a non-exclusive, royalty-free, worldwide, perpetual license to use, reproduce, and respond to such Submissions for the purpose of addressing your inquiry, improving our Services, and other legitimate business purposes, subject to our Privacy Policy. You agree not to submit any Submission that is unlawful, defamatory, infringing, or otherwise objectionable.
We are under no obligation to review, respond to, retain, or return any Submission, and we may remove or refuse to post any Submission at our sole discretion.
7. Third-Party Links and Content
The Website may contain links to third-party websites, resources, or services that are not owned or controlled by Cisog, including links to Cisog Group affiliate sites. We do not endorse and are not responsible for the content, products, services, privacy practices, or availability of any third-party sites. Your use of any third-party website is at your own risk and subject to the terms and policies of that third party. We encourage you to review the terms and privacy policies of any third-party site you visit.
8. No Professional Advice; Informational Purposes Only
The Content on the Website, including any articles, blog posts, whitepapers, training descriptions, or general cybersecurity information, is provided for general informational purposes only and does not constitute professional, technical, legal, or security advice specific to your organization's circumstances. No attorney-client, consultant-client, or similar professional relationship is formed by your use of the Website or by viewing its Content.
Cybersecurity risks and best practices evolve continuously, and Content on the Website may not reflect the most current threats, regulatory requirements, or technical standards applicable to your organization. You should not act or refrain from acting on the basis of any Content on the Website without seeking specific, qualified professional advice tailored to your situation, which we would be pleased to provide through a formal client engagement.
9. Disclaimer of Warranties
THE WEBSITE AND ALL CONTENT ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, WITHOUT LIMITATION, IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. CISOG DOES NOT WARRANT THAT THE WEBSITE WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE, THAT DEFECTS WILL BE CORRECTED, OR THAT THE WEBSITE OR THE SERVERS THAT MAKE IT AVAILABLE ARE FREE OF VIRUSES OR OTHER
Harmful Components.
NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED BY YOU FROM CISOG OR THROUGH THE WEBSITE SHALL CREATE ANY WARRANTY NOT EXPRESSLY STATED IN THESE TERMS. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES, SO
CISOG TECHNOLOGY CONSULTS LLC — TERMS AND CONDITIONS
Some Of The Above Exclusions May Not Apply To You.
10. Limitation of Liability
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL CISOG TECHNOLOGY CONSULTS LLC, ITS AFFILIATES (INCLUDING THE WIDER CISOG GROUP), OR THEIR RESPECTIVE OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR RELATED TO YOUR ACCESS TO OR USE OF, OR INABILITY TO ACCESS OR USE, THE WEBSITE, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), STATUTE, OR ANY OTHER LEGAL THEORY, AND WHETHER OR NOT CISOG HAS BEEN ADVISED OF THE POSSIBILITY OF
Such Damages.
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, CISOG'S TOTAL CUMULATIVE LIABILITY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATING TO YOUR USE OF THE WEBSITE SHALL NOT EXCEED ONE HUNDRED U.S. DOLLARS (USD $100). THIS LIMITATION APPLIES REGARDLESS OF WHETHER SUCH CLAIMS ARE BASED IN CONTRACT, TORT, STRICT LIABILITY, OR ANY OTHER LEGAL THEORY. THIS SECTION DOES NOT LIMIT LIABILITY FOR A SEPARATE, SIGNED CLIENT
Engagement Agreement, Which Shall Be Governed By Its Own Terms.
SOME JURISDICTIONS DO NOT ALLOW THE LIMITATION OR EXCLUSION OF LIABILITY FOR CERTAIN
Damages, So Some Of The Above Limitations May Not Apply To You.
11. Indemnification
You agree to defend, indemnify, and hold harmless CISOG Consults Nigeria Limited, its affiliates, and their respective officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses, including reasonable attorneys' fees, arising out of or in any way connected with: (a) your access to or use of the Website; (b) your violation of these Terms; (c) your violation of any applicable law or the rights of any third party; or (d) any Submission you provide through the Website.
12. Privacy
Your use of the Website is also governed by our Privacy Policy, available at https://cisoggroup.com, which describes how we collect, use, and protect information obtained through the Website. By using the Website, you consent to the collection and use of information as described in the Privacy Policy.
13. Termination and Restriction of Access
We reserve the right, in our sole discretion and without notice or liability, to restrict, suspend, or terminate your access to all or part of the Website at any time, for any reason, including if we believe you have violated these Terms. Provisions of these Terms that by their nature should survive termination, including but not limited to intellectual property rights, disclaimers, indemnification, and limitations of liability, shall survive any termination
CISOG TECHNOLOGY CONSULTS LLC — TERMS AND CONDITIONS
of your access to the Website.
14. Governing Law
These Terms and any dispute arising out of or related to them or the Website shall be governed by and construed in accordance with the laws of the State of Delaware, United States of America, without regard to its conflict of laws principles.
15. Dispute Resolution and Venue
Any dispute, claim, or controversy arising out of or relating to these Terms or your use of the Website shall be resolved exclusively through the state or federal courts located in the State of Delaware, and you consent to the personal jurisdiction and venue of such courts and waive any objection to venue on the grounds of forum non conveniens or otherwise. Nothing in this Section prevents either party from seeking injunctive or other equitable relief in any court of competent jurisdiction to protect its intellectual property or confidential information.
16. International Users
The Website is controlled and operated from the United States, and the Cisog Group operates in multiple countries, including Nigeria and the United Arab Emirates. We make no representation that the Website or its Content is appropriate, accurate, or available for use in all locations. If you access the Website from outside the United States, you do so on your own initiative and are responsible for compliance with applicable local laws.
17. Severability
If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court or tribunal of competent jurisdiction, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions of these Terms shall continue in full force and effect.
18. Waiver and Entire Agreement
No failure or delay by Cisog in exercising any right, power, or privilege under these Terms shall operate as a waiver of that right, power, or privilege. These Terms, together with our Privacy Policy and any separate written agreement governing a specific client engagement, constitute the entire agreement between you and CISOG Consults Nigeria Limited with respect to your use of the Website and supersede all prior or contemporaneous agreements, communications, and proposals, whether oral or written, regarding the Website.
19. Assignment
You may not assign or transfer these Terms, by operation of law or otherwise, without our prior written consent. We may assign or transfer these Terms, at our sole discretion, without restriction, including in connection with a merger, acquisition, corporate reorganization, or sale of assets involving Cisog Group.
CISOG TECHNOLOGY CONSULTS LLC — TERMS AND CONDITIONS
20. Contact Us
If you have any questions about these Terms, please contact us at:
CISOG Consults Nigeria Limited
c/o Cisog Group
Email: info@cisoggroup.com
Phone: +234 (0) 803 535 4363
Group Head Office: Flat 3 and 4, Block 505, MET Quarter, Kodesoh Street, Ikeja, Lagos, Nigeria
Website: https://cisoggroup.com
About Us
Technology expertise. Global perspective. Practical results.
CISOG Consults Nigeria Limited is a West Africa regional-focused technology consulting and business advisory organization and part of the CISOG Group.
We help organizations address complex challenges across cybersecurity, technology governance, risk, artificial intelligence and digital transformation.
Our approach combines strategic thinking with practical execution. We work with executives, boards, technology leaders and operational teams to ensure that technology supports business performance, security, resilience and sustainable growth.
Our Purpose
To help organizations use technology securely, responsibly and strategically to create sustainable business value.
Our Vision
To become a trusted global technology advisory partner helping organizations secure, transform and govern their digital future.
Our Mission
We enable organizations to:
- Build stronger cybersecurity capabilities
- Improve technology governance and risk management
- Adopt artificial intelligence responsibly
- Modernize technology environments
- Transform business operations through technology
- Build resilient and sustainable digital organizations
Our Values
Integrity
We operate with transparency, professionalism and accountability.
Excellence
We pursue high standards in every engagement.
Innovation
We continuously explore better ways to solve complex technology and business challenges.
Client Success
Our success is measured by the value and outcomes we create for clients.
Security
We believe security and resilience should be embedded into technology and business decisions.
Responsibility
We promote responsible technology adoption.
Collaboration
We work with clients, partners and technology ecosystems to deliver better outcomes.
Leadership
Experienced leadership. Technology-driven thinking.
Technology challenges require more than technical knowledge. They require leaders who understand business strategy, risk, governance, technology and organizational change.
CISOG brings together professionals with experience across technology consulting, cybersecurity, governance, digital transformation and business advisory.
Simeon Idowu Afe
Founder / Executive Technology & Cybersecurity Advisor
Executive profile
Senior technology and cybersecurity leader with 20+ years of experience spanning cybersecurity, IT governance, digital transformation, enterprise architecture, technology strategy, programme delivery, public-sector transformation and technology consulting. Currently CEO of Cisog Consults Limited, with prior executive leadership as Director of ICT in the Federal Civil Service of Nigeria and extensive consulting and technology-sector experience with Microsoft and Accenture. Combines executive advisory capability with hands-on experience in technology strategy, enterprise architecture, IT risk, security policy, infrastructure assessment, business process transformation, project governance and technology-enabled service delivery.
Experienced in advising senior government and enterprise stakeholders, translating business objectives into technology strategy, establishing governance and controls, and leading complex technology programmes. Cybersecurity experience is supported by participation in national cybersecurity policy work, international cyber-security discussions, security-related technology programmes, and published research on machine-learning approaches to cybersecurity of cyber-physical systems against DDoS attacks. Brings a strong foundation for vCISO, cybersecurity/GRC advisory, IT governance, digital transformation and emerging AI governance engagements.
Areas of expertise
Advisory Expertise
CISOG’s advisory capability brings together strategic, technical and operational perspectives to help clients address complex technology challenges.
Engage CISOG leadership
Executive-level advisory on cybersecurity, governance and technology strategy.
Why CISOG
Why organizations choose CISOG.
Technology consulting should create more than recommendations. It should create confidence, capability and measurable progress.
Global Perspective
CISOG combines international experience with a U.S.-focused consulting proposition.
Business-First Advisory
We begin with business objectives, risk and outcomes—not technology for technology’s sake.
Security by Design
Security, privacy, resilience and governance are considered throughout the technology lifecycle.
Strategy to Execution
We can help clients move from assessment and strategy through implementation and continuous improvement.
Emerging Technology Expertise
We help organizations navigate emerging technologies, including artificial intelligence, while managing associated risks.
Integrated Capability
Where an engagement requires broader implementation or technology capability, CISOG can draw on the wider group ecosystem.
Discuss your challenge with CISOG
A first conversation is a scoping conversation, not a pitch.
Our Approach
From challenge to outcome.
Every organization is different. Our approach therefore combines structured methodology with practical flexibility.
Understand
We understand your business strategy, operating environment, technology landscape, stakeholders and priorities.
Output: Shared understanding of the business challenge.
Assess
We evaluate current capabilities, risks, gaps and opportunities.
Output: Evidence-based assessment and priority findings.
Strategize
We translate findings into a practical strategy, target state and implementation roadmap.
Output: Actionable roadmap.
Transform
We support implementation, organizational change, technology adoption and capability development.
Output: Improved capabilities and measurable progress.
Sustain
We establish governance, metrics, monitoring and continuous-improvement mechanisms.
Output: Sustainable capability.
Resources
We provide knowledge that helps you make better technology decisions.
Explore practical resources designed for executives, technology leaders and organizations seeking to improve cybersecurity, governance and digital capability.
White Papers
In-depth analysis of technology and business challenges.
Guides
Practical guidance organizations can apply.
Checklists
Simple tools for evaluating technology, cybersecurity and governance.
Reports
Research and executive perspectives.
Webinars
Expert discussions and educational sessions.
Assessments
Interactive tools for understanding organizational maturity.
Explore →Start with your readiness score
Ten minutes. Result shown immediately.
Assessments
Assess how ready is your organization?
Eight assessments spanning cybersecurity, governance, AI, transformation, network, cloud, application security and identity. Each scores you against defined domains and produces a downloadable report.
Readiness Assessment Platform
CISOG Readiness Assessment Platform
A full multi-domain readiness assessment with scoring, an executive dashboard and a downloadable PDF report.
Cybersecurity Readiness Assessment
Evaluate your organization’s cybersecurity governance, risk, controls and preparedness.
GRC Maturity Assessment
Understand the maturity of your governance, risk and compliance capabilities.
AI Governance Readiness Assessment
Evaluate your organization’s readiness to govern AI responsibly.
Digital Transformation Readiness Assessment
Assess your organization’s strategic, technological and organizational readiness for transformation.
Network Security Assessment
Assesses your organization’s network infrastructure, configurations, security controls, vulnerabilities and operational practices to determine how effectively the environment can prevent, detect, contain and recover from cyber threats.
Cloud Security Assessment
Evaluates the security, configuration, architecture, identity controls, data protection, workloads and operational practices of an organization’s cloud environment.
Application Security Assessment
Evaluates whether your applications are securely designed, developed, deployed, configured and maintained.
Identity & Access Management Assessment
Evaluates how effectively your organization controls who can access systems, applications, data, cloud resources and privileged functions; what they can access; and whether that access remains appropriate throughout the identity lifecycle.
CISOG Academy
Build the capabilities your organization needs.
Academy programmes are being prepared
Training tracks across cybersecurity, GRC, AI governance and executive leadership. Content is being supplied by CISOG.
Register interestInsights
CISOG Insights
Cisog provides practical perspectives for leaders navigating cybersecurity, technology risk, artificial intelligence and digital transformation.
Why your organization needs an AI inventory before it needs an AI policy
Most organizations write the policy first. It is the wrong order, and it produces a document that governs systems nobody has identified.
Article · 3 min read · August 2026
What every CEO should know about cyber risk
Does your organization need a vCISO?
The five most common cybersecurity governance gaps
Building a cybersecurity risk register that gets used
AI security and AI governance are not the same problem
Why digital transformation programs fail
Cybersecurity versus cyber resilience
Building a board-level cybersecurity dashboard
Explore by theme
Cybersecurity
Threats, resilience, governance and security strategy.
GRC
Governance, risk, controls, compliance and technology assurance.
AI Governance
Responsible AI, AI risk, AI security, policy and governance.
Digital Transformation
Technology modernization, enterprise architecture, cloud and operating models.
Executive Technology Strategy
Insights for CEOs, boards, CIOs, CTOs, CISOs and other technology decision-makers.
Showing all 8 articles.
Subscribe to CISOG Insights
Executive analysis on cybersecurity, governance and AI. Monthly, not weekly.
AI Governance
Why your organization needs an AI inventory before it needs an AI policy
Most organizations write the policy first. It is the wrong order, and it produces a document that governs systems nobody has identified.
Ask a governance team where their AI policy stands and most will tell you it is drafted, circulating, or approved last quarter. Ask the same team how many AI systems are running in the organization and the answer is usually a pause.
That sequence — policy first, inventory later — is the single most common structural error in early AI governance programs. It feels like progress because a policy is a visible artifact. It produces a document that governs an unknown population.
A policy without an inventory is unenforceable
Every meaningful clause in an AI policy is conditional on knowing what exists. A rule requiring human review of consequential decisions only binds systems you have identified as making consequential decisions. A vendor clause only reaches contracts you know contain AI functionality.
The gap is rarely the sanctioned, obvious systems. It is the AI that arrived through a feature release in software the organization already licensed — a summarization tool in the service desk, scoring in a recruitment platform, a copilot switched on by default in the productivity suite. None of that went through a procurement decision anyone would characterize as an AI adoption.
What an inventory needs to capture
A useful inventory is not a list of tools. It is a record of decisions and exposure. For each system: the business process it touches, whether output influences a decision about a person, what data it consumes, whether that data leaves your tenancy, who owns it internally, and whether a human can meaningfully override it.
That last field is where most inventories become useful and uncomfortable at the same time. "Human in the loop" is frequently claimed and rarely tested. If the reviewer sees a hundred recommendations an hour with no realistic capacity to disagree, the oversight is nominal.
Where to look
- Procurement and finance records — subscriptions and renewals, particularly where the line item changed without a corresponding contract review.
- Existing vendor contracts — feature additions in software already deployed rarely trigger a new assessment.
- Network and identity telemetry — outbound connections to model providers reveal shadow adoption faster than any survey.
- Business units directly — asked as "what have you automated recently?" rather than "are you using AI?", which people answer inaccurately.
- Your own development pipeline — internally built models and any use of external APIs inside your products.
Then the policy writes itself
Once the inventory exists, policy stops being a drafting exercise and becomes a set of decisions about specific, known risks. The document gets shorter, more specific and considerably easier to get approved — because you are no longer asking executives to endorse abstract principles. You are asking them to make calls about systems they can see.
Organizations that sequence this correctly typically find the inventory takes four to six weeks and surfaces between two and four times the number of AI systems leadership expected. That number is the most persuasive governance artifact you will produce all year.
Key takeaways
- An AI policy written before an inventory governs a population you have not identified and cannot enforce against.
- The material exposure is usually AI that arrived as a feature in existing software, not AI that was deliberately procured.
- Inventory fields should capture decision impact and data flow, not tool names.
- Test claimed human oversight against realistic reviewer capacity before recording it as a control.
- Expect to find two to four times more AI systems than leadership anticipates — and use that number to drive the governance mandate.
Contact
Let's talk about your technology challenge.
Tell us what you are trying to solve. A first conversation is a scoping conversation — no obligation, no pitch deck.
What do you need help with?
Thank you. Your request has been received.
A CISOG advisor will review your requirements and contact you regarding next steps.
Schedule a consultation
Book a 30-minute conversation.
No preparation needed. We will ask what prompted the enquiry and tell you honestly whether we are the right firm for it.
- Service
- Meeting type
- Date & time
- Your details
What would you like to discuss?
How would you like to meet?
Choose a time
Times shown in Eastern Time (ET).
Tuesday 11 August
Wednesday 12 August
Thursday 13 August
Confirm your booking
Your meeting is confirmed
—
A calendar invitation and joining details are on the way. In production this writes to the CRM, scores the lead at 30 (sales-qualified), assigns an owner and exits any active nurture sequence — see §10.4.



